Staff Security Engineer, Data Science Engineering

Nscale

• $190K — $230K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 8+ years in data engineering, data science, detection engineering, or security analytics with a focus on security data.
  • Experience building and operating security data pipelines from APIs and event sources, including backfill and schema evolution.
  • Familiarity with cloud data warehouses and streaming systems, such as BigQuery and Kafka.
  • Understanding of security telemetry across multiple areas including endpoint, identity, and cloud controls.
  • Ability to apply statistical or machine learning methods in security analysis and evaluate their effectiveness.
  • Strong communication skills to collaborate with teams owning source systems and explain technical findings clearly.
  • Hands-on experience with data pipelines, schemas, and analysis while creating scalable solutions.

Responsibilities

  • Inventory and manage security-relevant data sources, ensuring coverage and freshness.
  • Implement and maintain data collection from various sources, making delays and schema changes detectable.
  • Monitor and report on data quality metrics like freshness, completeness, and duplicates.
  • Build behavioral baselines and anomaly detections to enhance threat investigation.
  • Support major incidents through detailed analysis and repeatable detection methods.
  • Create curated datasets for AI-assisted analysis, ensuring secure access and documentation.
  • Collaborate with security teams to turn analytical insights into actionable detections.

Benefits

  • Collaborative and innovative working environment.
  • Competitive compensation which includes base salary, bonuses, and equity.
  • Dynamic career progression plan that supports professional growth.
  • Flexible workplace allowing for a healthy work-life balance.
Full Job Description
About the Role

We're hiring a Staff Security Engineer to make the data behind Cyber Defense's detections and investigations trustworthy and to uncover threats the team might otherwise miss. This is a hands-on individual contributor role reporting to the Director, Cyber Defense.

You'll work across endpoint, identity, cloud, network, vulnerability, SaaS and internal platform telemetry, partnering with the teams that generate the data and with Security Operations, which uses it and provides feedback on alert quality. The work starts with engineering: collecting data completely and making gaps visible. From there, you'll build behavioral baselines and cross-source analyses that become usable detections, not just models or notebooks.

Defenders need to know when a feed is late, partial or unreliable before they make a decision from it. Your work will make that trust measurable and help them find threats that predefined rules alone may miss.
What you'll be doing
Data inventory and collection
  • Own the inventory of security-relevant sources, including their owners, collection methods, freshness, coverage limits and known gaps.
  • Build and operate idempotent batch and streaming collection from APIs, event streams, object stores and internal systems. Make partial drains, late feeds and schema changes detectable; support backfill and replay.
  • Define consistent identity, asset, time and severity conventions while preserving raw payloads. Document lineage, retention and the limits of what each dataset can support, and handle personal data and secrets deliberately.
Data reliability and quality
  • Monitor freshness, volume, completeness, duplicates, schema drift and cross-source consistency. Route quality failures to an owner so analysts know when the data cannot be trusted.
  • Make pipeline failures visible, with routine backfill and replay and measured cost per source.
  • Distinguish exact figures from lower bounds and unknowns wherever the data is used.
Detection and investigation
  • Build and evaluate behavioral baselines, anomaly detection and cross-source correlations against investigation outcomes and real alert volume. Work with Security Operations to tune or retire signals that do not earn their place.
  • Support major incidents with defensible scoping, timelines and pattern analysis, turning useful one-off work into repeatable queries or detections.
  • Partner with Security Operations to turn analytical findings into signals responders can use and assess against labelled outcomes.
AI-assisted analysis and collaboration
  • Prepare curated, documented datasets for AI-assisted analysis, with scoped and audited access, provenance, freshness signals and safe failure when data is missing or stale.
  • Help detection engineers, analysts and security engineers ask better questions of the data and understand the uncertainty in the answers.
  • Negotiate access, schemas and collection cadences with the teams that own source systems, and report coverage gaps back to them.
KPIs
  • Share of security-relevant sources inventoried, collected and documented, with known gaps named
  • Freshness and completeness compliance for critical sources, without silent partial drains
  • Share of sources with quality alerting to a named owner and time to identify a data defect
  • Measured precision of detections retained by Security Operations and analyst time saved on data wrangling
About You
  • You bring 8+ years in data engineering, data science, detection engineering, security analytics or a related technical field, including significant work with security data.
  • You have built and operated security data pipelines, including collection from APIs and event sources, idempotent loads, partitioning, backfill, replay and schema evolution. You can diagnose the difference between a complete dataset and one that only looks complete.
  • You can work with a cloud warehouse and a streaming system, such as BigQuery and Kafka or equivalents, and you have made data quality measurable and actionable for the people who depend on it.
  • You understand security telemetry across areas such as identity, endpoint, cloud control planes, networks, vulnerabilities and SaaS audit logs, including how attackers can appear in that data.
  • You can apply statistical or machine-learning methods to security analysis, evaluate them against real outcomes and translate the result into a detection that analysts can use.
  • You can work with teams that own the source systems to agree access, schemas and collection cadences, and explain coverage gaps and uncertain findings clearly to analysts, engineers and leaders.
  • You stay hands-on with pipelines, schemas and analysis while building repeatable methods that make the wider team less dependent on one person.

Experience with multi-tenant cloud or AI infrastructure, graph-based entity resolution, privacy-sensitive data governance, or building data foundations for AI-assisted analysis would be useful, but is not required.
What we can offer you

At Nscale, you'll find a collaborative, supportive, and innovative environment where your contributions spark real impact. We're building something extraordinary, and we want you at the core.
  • Highly competitive US compensation package (base + bonus + equity), with performance reviews every 12 months.
  • Join one of the fastest-growing AI infrastructure companies - your chance to directly shape how global AI capacity is planned and deployed. •
  • Expect a dynamic progression plan tailored to your ambitions. Grow by leading critical cross-functional initiatives and shaping capital strategy - always with our full support.
  • Human-First Flexibility: We treat you as humans first. Our flexible workplace trusts Nscalers to deliver, giving you the autonomy to shape your day around life's moments.

Similar Jobs

More Jobs at Nscale

More Information Technology Jobs

Find similar Staff Security Engineer, Data Science Engineering jobs: