About the RoleWe are seeking a Staff Security Engineer, Product and Platform Security to lead security initiatives across Nscale's products, cloud platforms, hyperscale GPU clusters, and critical infrastructure.
You'll partner closely with engineering, platform, infrastructure, and security teams to identify and reduce risk throughout the product and technology lifecycle. You'll provide hands-on security expertise across architecture and design reviews, threat modeling, vulnerability assessment, secure development, and incident response.
This role will help build and scale product and platform security practices while turning technical findings, researcher insights, and emerging threats into stronger engineering controls, clearer priorities, and measurable improvements to Nscale's security posture.
What you'll be doingProduct and Platform Security- Perform vulnerability assessments, application security reviews, and testing of Nscale's core services, including the Identity service, billing service, external APIs, and the Nscale Console.
- Conduct threat modeling and architecture reviews for new products, features, services, and platform changes.
- Provide guidance on secure design, coding practices, authentication, authorization, data protection, and infrastructure security.
- Develop reusable security standards, patterns, and guardrails that enable teams to build and deploy securely at scale.
Vulnerability Management and Remediation- Receive, analyze, and validate vulnerability findings from internal testing, security tooling, external researchers, and other sources.
- Assign severity ratings using CVSS and assess technical and business impact to drive prioritization.
- Coordinate with engineering, platform, and infrastructure teams to reproduce, validate, and remediate findings.
- Create clear remediation roadmaps and track progress toward resolution.
- Identify recurring vulnerability patterns and work with engineering teams to address systemic risks and technical debt.
Security Coordination and Incident Response- Support incident classification and escalation workflows when vulnerabilities or security issues are discovered in production environments.
- Coordinate responsible disclosure timelines and remediation activities with affected stakeholders.
- Contribute to root-cause analysis and process improvements following vulnerability discovery or security incidents.
- Document findings, remediation steps, and lessons learned to improve product and platform security practices.
- Maintain detailed records of findings and resolutions for audit and compliance purposes.
Program Measurement and Improvement- Track and report on product and platform security KPIs, including vulnerability trends, remediation timelines, recurrence, and researcher engagement.
- Analyze patterns in vulnerability types to identify systemic risks, control gaps, and technical debt.
- Provide regular insights to leadership on security risks, emerging threats, researcher feedback, and program effectiveness.
- Recommend enhancements to security controls, testing coverage, program scope, and remediation processes based on data.
- Benchmark Nscale's product and platform security practices against industry peers in cloud infrastructure and AI/GPU platforms.
KPIs- Reduction in product and platform security risk and recurring vulnerability types
- Time to validate, prioritize, and resolve reported vulnerabilities
- Security review and threat-modeling coverage for critical products and platform changes
- Adoption and effectiveness of secure engineering standards and controls
About You- 10+ years of experience in information security, including substantial hands-on experience in product security, application security, platform security, or vulnerability management.
- A background in product security, application security, and penetration testing.
- Deep technical expertise in threat modeling, security architecture, vulnerability assessment, and secure coding practices.
- Experience partnering with software, platform, and infrastructure engineering teams to embed security throughout the development lifecycle.
- Strong understanding of CVSS scoring, vulnerability prioritization, and risk quantification.
- Experience with responsible disclosure frameworks, bug bounty programs, and coordinating multi-stakeholder vulnerability remediation.
- Excellent communication skills, with the ability to explain technical findings to researchers, engineers, leaders, and non-technical stakeholders.
- Comfort working in complex, high-stakes environments where security decisions affect product reliability and customer trust.
- Experience with GPU/HPC or cloud infrastructure security, including AWS, GCP, or Azure.
- Knowledge of Kubernetes, container security, APIs, identity and access management, and hybrid cloud architectures.
What we can offer youAt Nscale, you'll find a collaborative, supportive, and innovative environment where your contributions spark real impact. We're building something extraordinary, and we want you at the core.
- Highly competitive US compensation package (base + bonus + equity), with performance reviews every 12 months.
- Join one of the fastest-growing AI infrastructure companies - your chance to directly shape how global AI capacity is planned and deployed. •
- Expect a dynamic progression plan tailored to your ambitions. Grow by leading critical cross-functional initiatives and shaping capital strategy - always with our full support.
- Human-First Flexibility: We treat you as humans first. Our flexible workplace trusts Nscalers to deliver, giving you the autonomy to shape your day around life's moments.
Salary Range$190,000-$240,000 USD