Senior Staff Security Engineer, Incident Response

Nscale

$190K — $240K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 10+ years of experience in incident response or closely related technical security role
  • Experience leading responses to complex, high-severity incidents in cloud-scale environments
  • Strong understanding of attacker behavior and techniques
  • Proficient in investigating Linux/Windows hosts and cloud environments
  • Experience in developing security automation and tooling
  • Ability to make sound decisions from incomplete or conflicting evidence
  • Capability to lead cross-team remediation efforts effectively

Responsibilities

  • Lead technical response to high-severity incidents across various environments
  • Direct investigation strategy and analysis during cyber incidents
  • Develop containment, eradication, and monitoring options post-incident
  • Automate evidence collection and response recommendations
  • Convert red-team findings into defensive measures and tests
  • Design safe AI-assisted incident response workflows
  • Mentor team members in incident response best practices

Benefits

  • Collaborative and innovative work environment
  • Highly competitive compensation package
  • Opportunity to shape global AI infrastructure
  • Dynamic progression plan tailored to individual ambitions
  • Flexible workplace that promotes a work-life balance
Full Job Description
About the Role

We are hiring a Senior Staff Security Engineer, Incident Response to lead the technical response to Nscale's most serious cyber incidents and build the capabilities that make future responses faster, safer and more decisive.

This hands-on senior individual contributor role sits in Cyber Defence and reports to the Director of Cyber Defence. You will work across Security Operations, Detection and Security Data Engineering, Product, Platform, Identity, Enterprise and Infrastructure teams, and Offensive Security.

During a major incident, you will be the technical incident commander, setting the investigation strategy, directing technical workstreams and providing the evidence leaders need to make decisions. Between incidents, you will turn lessons from incidents and offensive testing into durable defensive capability, including safe AI-assisted and agentic response workflows.
What you'll be doing
Technical incident command
  • Lead the technical response to high-severity incidents across enterprise, identity, endpoint, cloud, product, production, data centre and operational technology environments.
  • Set investigation hypotheses and evidence priorities; direct workstreams; reconstruct attack paths; analyse persistence and root cause; and establish credible scope.
  • Develop technical options and success criteria for containment, eradication, credential and session invalidation, recovery validation and heightened monitoring.
  • Conduct hands-on investigations across Linux and Windows hosts, cloud control planes, identity systems, networks, applications and containers.
  • Lead post-incident technical reviews that result in permanent engineering improvements.
Response engineering
  • Build a response-engineering roadmap that turns recurring manual investigation and containment work into tested, version-controlled and observable capabilities.
  • Automate evidence collection, enrichment, correlation, timeline generation, blast-radius analysis, asset and owner attribution, remediation tracking and response recommendations.
  • Create executable playbooks for identity compromise, cloud control-plane intrusion, destructive attacks and ransomware, insider threat, supply-chain compromise, data exfiltration and production compromise.
Adversary-informed defence
  • Turn red-team findings, incident evidence and threat intelligence into detections, preventive controls, response actions and regression tests.
  • Drive remediation campaigns for vulnerabilities and attack paths that span engineering organisations, with clear ownership, measurable closure and executive visibility where needed.
  • Run technical readiness exercises that test Nscale's ability to detect, investigate, contain and recover from realistic attacks before they reach production.
Agentic response and team development
  • Define safe AI-assisted and agentic response workflows with scoped access, human approval for consequential actions, evidence provenance, output validation, auditability, rollback and emergency-stop controls.
  • Mentor incident responders, SOC analysts, security engineers and service owners in adversary behaviour, investigation methods and technical decision-making.
  • Participate in the incident-response on-call rotation.
KPIs
  • Time to credible scope
  • Time to contain and eradicate
  • Share of investigative and response steps safely automated
  • Closure of post-incident engineering actions
About You
  • You have 10+ years in incident response, security engineering, offensive security, detection engineering, vulnerability management or a closely related technical security role.
  • You have led the technical response to complex, high-severity incidents in cloud-scale, hybrid or globally distributed environments.
  • You understand attacker behavior including credential and session theft, privilege escalation, persistence, lateral movement, command and control, defence evasion, data exfiltration and destructive activity.
  • You have investigated Linux and Windows hosts, cloud environments, identity systems, network activity and related security telemetry.
  • You can establish incident scope and make sound containment decisions from incomplete or conflicting evidence.
  • You have strong software engineering or scripting ability and have built reliable security tooling, integrations or automation.
  • You have turned offensive findings, incidents or vulnerability intelligence into durable detections, controls, remediation mechanisms and validation tests.
  • You can lead urgent remediation across teams without direct reporting lines and communicate technical conclusions, uncertainty and trade-offs to engineers, executives and other stakeholders.
  • You build repeatable mechanisms and develop the wider team rather than becoming a single point of failure.
What we can offer you

At Nscale, you'll find a collaborative, supportive, and innovative environment where your contributions spark real impact. We're building something extraordinary, and we want you at the core.
  • Highly competitive US compensation package (base + bonus + equity), with performance reviews every 12 months.
  • Join one of the fastest-growing AI infrastructure companies - your chance to directly shape how global AI capacity is planned and deployed. •
  • Expect a dynamic progression plan tailored to your ambitions. Grow by leading critical cross-functional initiatives and shaping capital strategy - always with our full support.
  • Human-First Flexibility: We treat you as humans first. Our flexible workplace trusts Nscalers to deliver, giving you the autonomy to shape your day around life's moments.


Salary Range

$190,000-$240,000 USD

Similar Jobs

More Jobs at Nscale

More Information Technology Jobs

Find similar Senior Staff Security Engineer, Incident Response jobs: