Staff Security Engineer, Product & Platform Security

Nscale

$190K — $230K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 10+ years experience in information security involving product, application, and platform security.
  • Deep technical expertise in threat modeling, security architecture, and secure coding practices.
  • Experience collaborating with engineering teams to integrate security throughout development.
  • Strong knowledge of CVSS scoring and vulnerability prioritization.
  • Proficiency with security tools including vulnerability scanners, SIEM, and GRC systems.
  • Experience with bug bounty programs and multi-stakeholder vulnerability coordination.
  • Excellent communication skills for conveying technical issues to diverse audiences.

Responsibilities

  • Lead security reviews for products, cloud platforms, APIs, and critical infrastructure.
  • Collaborate with engineering teams to identify security risks and create remediation strategies.
  • Conduct threat modeling and architecture reviews for new projects and platform changes.
  • Guide secure design and coding practices, focusing on security across the development lifecycle.
  • Develop reusable security standards that facilitate secure deployment at scale.
  • Manage vulnerability findings: analyze, validate, and create remediation plans.
  • Coordinate bug bounty programs, enhancing ethical vulnerability reporting processes.

Benefits

  • Collaborative and innovative work environment with a focus on impactful contributions.
  • Competitive compensation package with performance reviews annually.
  • Dynamic progression plans tailored to individual ambitions and career growth.
  • Flexibility in the workplace, allowing autonomy in work-life management.
Full Job Description
About the Role

We are seeking a Staff Security Engineer, Product and Platform Security to lead security initiatives across Nscale's products, cloud platforms, hyperscale GPU clusters, and critical infrastructure.

You'll partner closely with engineering, platform, infrastructure, and security teams to identify and reduce risk throughout the product and technology lifecycle. You'll provide hands-on security expertise across architecture and design reviews, threat modeling, vulnerability management, secure development, and incident response.

This role will help build and scale product and platform security practices while turning technical findings, researcher insights, and emerging threats into stronger engineering controls, clearer priorities, and measurable improvements to Nscale's security posture.
What you'll be doing

Product and Platform Security
  • Lead security reviews across Nscale's products, cloud platforms, APIs, hyperscale GPU clusters, and supporting infrastructure.
  • Partner with engineering teams throughout the development lifecycle to identify security risks and define practical remediation plans.
  • Conduct threat modeling and architecture reviews for new products, features, services, and platform changes.
  • Provide guidance on secure design, coding practices, authentication, authorization, data protection, and infrastructure security.
  • Help develop reusable security standards, patterns, and guardrails that enable teams to build and deploy securely at scale.

Vulnerability Management and Remediation
  • Receive, analyze, and validate vulnerability findings from internal testing, security tooling, external researchers, and other sources.
  • Assign severity ratings using CVSS and assess technical and business impact to drive prioritization.
  • Coordinate with engineering, platform, and infrastructure teams to reproduce, validate, and remediate findings.
  • Create clear remediation roadmaps and track progress toward resolution.
  • Identify recurring vulnerability patterns and work with engineering teams to address systemic risks and technical debt.

Bug Bounty and Responsible Disclosure
  • Design, launch, and scale Nscale's bug bounty and vulnerability disclosure programs across platforms such as HackerOne, Bugcrowd, or equivalent.
  • Establish clear scope definitions, reward guidelines, and submission processes that encourage high-quality vulnerability disclosures.
  • Build trusted relationships with security researchers and the broader security community.
  • Manage researcher communications, triage workflows, and resolution timelines with professionalism and transparency.
  • Act as the primary liaison between external researchers and internal security and engineering teams during vulnerability disclosure.

Security Coordination and Incident Response
  • Support incident classification and escalation workflows when vulnerabilities or security issues are discovered in production environments.
  • Coordinate responsible disclosure timelines and remediation activities with affected stakeholders.
  • Contribute to root-cause analysis and process improvements following vulnerability discovery or security incidents.
  • Document findings, remediation steps, and lessons learned to improve product and platform security practices.
  • Maintain detailed records of findings and resolutions for audit and compliance purposes.

Program Measurement and Improvement
  • Track and report on product and platform security KPIs, including vulnerability trends, remediation timelines, recurrence, and researcher engagement.
  • Analyze patterns in vulnerability types to identify systemic risks, control gaps, and technical debt.
  • Provide regular insights to leadership on security risks, emerging threats, researcher feedback, and program effectiveness.
  • Recommend enhancements to security controls, testing coverage, program scope, and remediation processes based on data.
  • Benchmark Nscale's product and platform security practices against industry peers in cloud infrastructure and AI/GPU platforms.

Threat Intelligence and Security Awareness
  • Monitor emerging vulnerabilities, attack vectors, and security trends relevant to cloud platforms, GPU infrastructure, Kubernetes, containers, and AI systems.
  • Share findings with security, product, platform, and engineering teams to inform prevention and detection strategies.
  • Support security awareness and training initiatives by communicating lessons learned from vulnerabilities and incidents.
  • Promote security ownership across engineering teams through practical guidance, collaboration, and knowledge sharing.
KPIs
  • Reduction in product and platform security risk and recurring vulnerability types
  • Time to validate, prioritize, and resolve reported vulnerabilities
  • Security review and threat-modeling coverage for critical products and platform changes
  • Adoption and effectiveness of secure engineering standards and controls
  • Researcher engagement and responsible disclosure outcomes
About You
  • 10+ years of experience in information security, including substantial hands-on experience in product security, application security, platform security, or vulnerability management.
  • Deep technical expertise in threat modeling, security architecture, vulnerability assessment, and secure coding practices.
  • Experience partnering with software, platform, and infrastructure engineering teams to embed security throughout the development lifecycle.
  • Strong understanding of CVSS scoring, vulnerability prioritization, and risk quantification.
  • Proficiency with vulnerability scanners, application security tooling, SIEM platforms, EDR tools, and GRC systems.
  • Experience with responsible disclosure frameworks, bug bounty programs, and coordinating multi-stakeholder vulnerability remediation.
  • Excellent communication skills, with the ability to explain technical findings to researchers, engineers, leaders, and non-technical stakeholders.
  • Comfort working in complex, high-stakes environments where security decisions affect product reliability and customer trust.
  • Experience with GPU/HPC or cloud infrastructure security, including AWS, GCP, or Azure.
  • Knowledge of Kubernetes, container security, APIs, identity and access management, and hybrid cloud architectures.
  • A background in product security, application security, incident response, vulnerability management, penetration testing, or hands-on work with bug bounty platforms.
What we can offer you

At Nscale, you'll find a collaborative, supportive, and innovative environment where your contributions spark real impact. We're building something extraordinary, and we want you at the core.

Highly competitive US compensation package (base + bonus + equity), with performance reviews every 12 months.

Join one of the fastest-growing AI infrastructure companies - your chance to directly shape how global AI capacity is planned and deployed.
• Expect a dynamic progression plan tailored to your ambitions. Grow by leading critical cross-functional initiatives and shaping capital strategy - always with our full support.

Human-First Flexibility: We treat you as humans first. Our flexible workplace trusts Nscalers to deliver, giving you the autonomy to shape your day around life's moments.

Similar Jobs

More Jobs at Nscale

More Information Technology Jobs

Find similar Staff Security Engineer, Product & Platform Security jobs: