Director of Cyber Defense & Operations

Nscale

$275K — $315K *
Information Technology
11 - 15 years of experience
Job Overview by Ladders

Qualifications

  • 12+ years in security operations or incident response leadership.
  • 5+ years of team leadership experience.
  • Proven experience commanding serious incidents with significant consequences.
  • Exceptional communication skills for briefing executives and external stakeholders.
  • Depth in business continuity and disaster recovery practices.

Responsibilities

  • Lead 24/7 cyber defense operations across global hubs.
  • Establish and enforce incident command and escalation standards.
  • Manage relationships and expectations with managed service providers.
  • Develop cyber resilience standards and ensure recovery processes.
  • Turn escalation outcomes into permanent operational improvements.

Benefits

  • Collaborative and innovative work environment with real impact.
  • Dynamic progression plans tailored to individual ambitions.
  • Flexible workplace allowing for work-life balance.
  • Performance reviews every 12 months to assess growth and advancement.
Full Job Description
About the Role

We are hiring a Director, Cyber Defense and Operations to own how Nscale detects, responds to, and recovers from serious cyber events across enterprise, cloud, production, data centre, and operational technology environments.

This is an operator's role, not an engineering role. You will lead incident command, escalation discipline, on-call health, case quality, resilience, and the operating relationship with our managed provider. You will work directly with the CISO, executive team, service owners, and the Enterprise Security, Platform and Product Security, Identity and PAM, and CISO office pillars. When you identify a capability gap, you will specify the operational requirement and our engineering pillars will build it.

This is one of the most externally visible roles in the security organisation. You will brief the CISO weekly, the executive team and board quarterly, and customers, auditors, and insurers on demand. Your operational judgement and communication under pressure will shape how Nscale manages material incidents, demonstrates recovery readiness, and permanently removes recurring security problems.
What you'll be doing

Lead 24x7 cyber defense operations
  • Establish follow-the-sun coverage, with North America first and a second hub in Singapore or India scoped and hiring within your first 60 days.
  • Lead response operations across two hubs, setting escalation standards and maintaining on-call health, handover quality, and case quality.
  • Manage the operating relationship with our contracted managed provider, including measurable service expectations, evidence standards, and a plan to bring the work in-house over time.
  • Maintain an operating model in which the in-house security agent and managed provider hold level 0 and level 1 around the clock, while your team handles escalations rather than watching a queue.

Command incidents and crises
  • Publish and operate a repeatable severity and incident command model covering authority, roles, escalation, containment, evidence, recovery, and post-incident learning.
  • Establish a named command rotation and test escalation paths.
  • Serve as one of the incident commanders and lead alongside the executive team while material incidents remain unresolved.
  • Brief the CISO weekly, the executive team and board quarterly, and customers, auditors, insurers, and regulators as required.

Strengthen resilience and recovery
  • Set cyber resilience standards for recovery priorities, critical dependencies, recovery objectives, and evidence that plans survive contact.
  • Challenge service-owner assumptions while keeping accountability for system recovery with the relevant service owners.
  • Ensure continuity of the security function during identity outages, communications failure, destructive attack, or compromise of primary security tooling.
  • Run a standing programme of tabletops, technical simulations, and recovery tests that produces prioritised, funded remediation work.
  • Close the operational technology and building management coverage gap, neither of which is currently visible to the detection stack.

Turn escalations into permanent improvements
  • Ensure every escalation exits as an engineering artifact and measure success through the share of escalations permanently solved rather than tickets closed.
  • Set priority intelligence requirements that connect real threat actors, campaigns, and exposure to decisions.
  • Convert incidents, investigations, intelligence, and exercise findings into prioritised engineering demand, tested detections, and regression tests.
  • Define operational requirements, validate that delivered capabilities work, and measure whether they reduce risk without owning the engineering build.

Build and run the function
  • Hire, level, coach, and develop a team across time zones, including succession planning and performance management.
  • Own budget and vendor decisions for the function.
  • Lead the cyber defense section of the monthly operations review and make it the place the CISO steers from.
  • Name Nscale's most critical services, their recovery objectives and dependencies, and the highest-risk readiness gaps within your first 90 days.
KPIs
  • Share of escalations permanently solved
  • On-call health, handover quality, and escalation-standard adherence
  • Demonstrated recovery readiness for critical services and security operations
  • Managed-provider service and evidence-quality performance
About You
  • 12+ years in security operations, incident response, cyber defense, or resilience leadership, including 5+ years leading teams.
  • You have personally commanded serious incidents with material customer, legal, regulatory, or reputational consequences.
  • You communicate with exceptional clarity to executives, boards, customers, legal teams, auditors, insurers, and regulators while facts are still evolving.
  • You have built and scaled teams through hiring, levelling, coaching, succession planning, and handling underperformance; experience leading across time zones is a strong plus.
  • You bring real depth in business continuity and disaster recovery, with the technical credibility to challenge recovery plans that will not survive contact.
  • You have run tabletops, technical simulations, and recovery tests that produced funded change rather than reports alone.
  • You demonstrate operational rigour through runbooks, handovers, on-call health, case quality, escalation standards, and audit-ready evidence.
  • You have an automation-first instinct and respond to recurring toil by building or automating it away rather than defaulting to a tool purchase or additional headcount.
  • You understand modern attacker behaviour across identity, endpoint, cloud, SaaS, production, and third parties, and have held third-party monitoring or response providers to clear standards.
  • Experience with operational technology, industrial control systems, building management systems, converged IT and OT response, data centres, HPC, sovereign cloud, destructive-event recovery, outsourced-to-insourced transitions, or multi-region, regulated, or pre-IPO environments is strongly valued; certifications are useful but not required.
How We Will Assess

Incident command.

Walk us through an incident you led. We are listening for the decisions you made with incomplete information, what you told executives and when, and what you would do differently.

Communication.

We will ask for a written artifact: a real incident note, board summary, or customer update, redacted as needed. We assess structure, clarity, and how you handled what you did not yet know.

Scaling.

Tell us how you hired, levelled, and developed a team, and what you did when someone was not working out.

Automation instinct.

Describe recurring toil you inherited. We are listening for whether you reached for a tool, a person, or a build.

Recovery.

Explain how you would prove this company can recover from a destructive event across identity, communications, infrastructure, data, and the security tooling itself. We are looking for the difference between a documented plan and a demonstrated one.
This Role Is Not a Fit If You
  • Have run a tiered, alert-processing SOC and would rebuild one here.
  • Treat incident response, business continuity, and disaster recovery as three separate compliance exercises.
  • Solve capacity problems primarily with headcount or vendor spend.
  • Want to build detection tooling. That work is real and well funded here; it sits in another pillar.
  • Are a strong operator but a weak communicator. This role is too externally facing for that trade.
What we can offer you

At Nscale, you'll find a collaborative, supportive, and innovative environment where your contributions spark real impact. We're building something extraordinary, and we want you at the core.
  • Highly competitive US compensation package (base + bonus + equity), with performance reviews every 12 months.
  • Join one of the fastest-growing AI infrastructure companies - your chance to directly shape how global AI capacity is planned and deployed. •
  • Expect a dynamic progression plan tailored to your ambitions. Grow by leading critical cross-functional initiatives and shaping capital strategy - always with our full support.
  • Human-First Flexibility: We treat you as humans first. Our flexible workplace trusts Nscalers to deliver, giving you the autonomy to shape your day around life's moments.
Salary Range

The range below reflects the base salary for the position. Actual compensation may vary based on job-related factors such as skill set, experience, education, and location. In addition to base salary, this role may be eligible for bonus, equity, and/or commission programs. Nscale may offer a competitive benefits package including medical, dental, vision, flexible paid time off, parental leave, and retirement plan participation.

The range below reflects the base salary for the position. Actual compensation may vary based on job-related factors such as skill set, experience, education, and location. In addition to base salary, this role may be eligible for bonus, equity, and/or commission programs. Nscale may offer a competitive benefits package including medical, dental, vision, flexible paid time off, parental leave, and retirement plan participation.

Salary Range

$275,000-$315,000 USD

Similar Jobs

More Jobs at Nscale

More Information Technology Jobs

Find similar Director of Cyber Defense & Operations jobs: