Staff Security Engineer, Network Security

Nscale

• $160K — $190K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 7+ years of experience in network security or related engineering roles
  • Deep hands-on experience with routing, switching, and firewalls
  • Experience designing secure networks across various environments
  • Strong understanding of zero-trust principles and identity-aware access
  • Ability to translate network diagrams into security requirements
  • Experience building reusable network security standards and processes
  • Preferred exposure to AI infrastructure or hyperscale data centers

Responsibilities

  • Define data center network security reference architecture
  • Establish trust-boundary decisions for network segmentation
  • Translate network diagrams into security controls and risk decisions
  • Design segmentation patterns and access control requirements
  • Review new network designs before implementation
  • Set security standards for third-party network providers
  • Define network telemetry and logging requirements

Benefits

  • Collaborative and innovative work environment
  • Highly competitive compensation package with performance reviews
  • Opportunity to shape global AI infrastructure
  • Dynamic progression plan tailored to individual ambitions
  • Flexible workplace that prioritizes work-life balance
Full Job Description
About the Role

We're hiring a Staff Security Engineer - Network Security to define and implement the network security patterns that keep Nscale's corporate, OT/BMS, production management, customer management, telemetry, and internet access paths separated, observable, and secure.

This role sits at the intersection of security, infrastructure, facilities, IT, platform engineering, security operations, physical security, and third-party providers. You'll work across data centers, colocation sites, office environments, and production management networks, reviewing designs before hardware and implementation decisions are locked and creating repeatable baselines that support fast deployment in real-world conditions.

Your work will help Nscale avoid one-off network security decisions at each new site build. By establishing clear trust boundaries, segmentation patterns, and practical standards, you'll enable the business to move quickly while reducing the risk of corporate networks becoming accidental privileged access zones and ensuring operational networks have the controls they need.
What you'll be doing

Reference architecture and trust boundaries
  • Define data center network security reference architecture across corporate internet access, OT/BMS, production management, customer management, telemetry, and site operations networks.
  • Establish trust-boundary decisions that determine which networks are untrusted, which are privileged, and which flows are explicitly required.
  • Translate network diagrams into trust boundaries, required flows, security controls, monitoring requirements, and risk decisions.
  • Create a clear policy position that corporate site networks provide internet access and do not become privileged access zones by default.

Segmentation, controls, and secure access
  • Design segmentation patterns, firewall policy principles, routing controls, and network access control requirements for high-risk paths.
  • Define when network access control is required, optional, or unnecessary based on trust zone, user population, asset class, and operational risk.
  • Prevent fragile controls such as IP-based trust from replacing strong identity, device posture, application-layer authentication, and explicit authorization.
  • Specify requirements for local safety-critical telemetry paths where latency, availability, or physical operations make remote-only dependencies unacceptable.

Design review and deployment standards
  • Review new data center, colocation, office, and site network designs before implementation choices are finalized.
  • Assess urgent network designs and identify decisions that must be approved, changed, or accepted with compensating controls.
  • Set security standards for third-party network providers, installation partners, managed service providers, and data center specialists.
  • Build reusable design checklists, diagrams, and decision records for future site builds.

Telemetry, monitoring, and cross-functional partnership
  • Define network telemetry, logging, and detection requirements across corporate, OT/BMS, production management, and internet-edge paths.
  • Partner with Identity and Security Data to ensure network access depends on strong authentication and produces usable telemetry.
  • Collaborate with cross-functional teams to balance security, operational safety, availability, and deployment speed.
  • Support practical security decisions in environments with fast hardware timelines, incomplete designs, and third-party dependencies.
KPIs
  • Current-state network trust-boundary map completed
  • Minimum security baseline for new data center deployments defined
  • Urgent network design reviews completed before implementation lock-in
  • Usable network telemetry and logging coverage across key network domains
About You
  • 7+ years of experience in network security, data center networking, infrastructure security, enterprise network engineering, or related engineering roles
  • Deep hands-on experience with routing, switching, segmentation, firewalls, internet edge, WAN, remote access, wireless, and network troubleshooting
  • Experience designing or reviewing secure networks across data centers, colocation sites, offices, production environments, or globally distributed infrastructure
  • Experience securing OT, BMS, industrial, facilities, or other operational networks where safety, availability, and local control matter
  • Strong understanding of zero-trust principles, identity-aware access, least privilege, explicit authorization, and the limits of network location-based trust
  • Ability to translate network diagrams into trust boundaries, required flows, security controls, monitoring requirements, and risk decisions
  • Ability to work effectively with infrastructure, facilities, IT, platform engineering, security operations, physical security, and third-party providers
  • Experience building reusable network security standards, design review processes, and deployment gates
  • Strong judgment in real-world environments with incomplete designs, urgent timelines, and complex trust-boundary decisions
  • Preferred exposure to AI infrastructure, GPU clusters, high-performance computing, sovereign infrastructure, or hyperscale data center environments
What we can offer you

At Nscale, you'll find a collaborative, supportive, and innovative environment where your contributions spark real impact. We're building something extraordinary, and we want you at the core.
  • Highly competitive US compensation package (base + bonus + equity), with performance reviews every 12 months.
  • Join one of the fastest-growing AI infrastructure companies - your chance to directly shape how global AI capacity is planned and deployed. •
  • Expect a dynamic progression plan tailored to your ambitions. Grow by leading critical cross-functional initiatives and shaping capital strategy - always with our full support.
  • Human-First Flexibility: We treat you as humans first. Our flexible workplace trusts Nscalers to deliver, giving you the autonomy to shape your day around life's moments.

Similar Jobs

More Jobs at Nscale

More Information Technology Jobs

Find similar Staff Security Engineer, Network Security jobs: