
Staff Security Engineer, Product & Platform Security
Nscale
Job description
About Nscale
Nscale is the GPU cloud engineered for AI. We provide cost-effective, high-performance infrastructure for AI start-ups and large enterprise customers. Nscale enables AI-focused companies to achieve superior results by reducing the complexity of AI development. Our GPU cloud bolsters technical capabilities and directly supports strategic business outcomes, including cost management, rapid innovation, and environmental responsibility.
We thrive on a culture of relentless innovation, ownership, and accountability, where every team member takes pride in their work and drives it with excellence and urgency. As an Nscaler, you’ll build trust through openness and transparency, where everyone is inspired to do their best work. If you join our team, you’ll be contributing to building the technology that powers the future.
About the Role
We are seeking a Staff Security Engineer, Product and Platform Security to lead security initiatives across Nscale’s products, cloud platforms, hyperscale GPU clusters, and critical infrastructure.
You’ll partner closely with engineering, platform, infrastructure, and security teams to identify and reduce risk throughout the product and technology lifecycle. You’ll provide hands-on security expertise across architecture and design reviews, threat modeling, vulnerability management, secure development, and incident response.
This role will help build and scale product and platform security practices while turning technical findings, researcher insights, and emerging threats into stronger engineering controls, clearer priorities, and measurable improvements to Nscale’s security posture.
What you'll be doing
Product and Platform Security
-
Lead security reviews across Nscale’s products, cloud platforms, APIs, hyperscale GPU clusters, and supporting infrastructure.
-
Partner with engineering teams throughout the development lifecycle to identify security risks and define practical remediation plans.
-
Conduct threat modeling and architecture reviews for new products, features, services, and platform changes.
-
Provide guidance on secure design, coding practices, authentication, authorization, data protection, and infrastructure security.
-
Help develop reusable security standards, patterns, and guardrails that enable teams to build and deploy securely at scale.
Vulnerability Management and Remediation
-
Receive, analyze, and validate vulnerability findings from internal testing, security tooling, external researchers, and other sources.
-
Assign severity ratings using CVSS and assess technical and business impact to drive prioritization.
-
Coordinate with engineering, platform, and infrastructure teams to reproduce, validate, and remediate findings.
-
Create clear remediation roadmaps and track progress toward resolution.
-
Identify recurring vulnerability patterns and work with engineering teams to address systemic risks and technical debt.
Bug Bounty and Responsible Disclosure
-
Design, launch, and scale Nscale’s bug bounty and vulnerability disclosure programs across platforms such as HackerOne, Bugcrowd, or equivalent.
-
Establish clear scope definitions, reward guidelines, and submission processes that encourage high-quality vulnerability disclosures.
-
Build trusted relationships with security researchers and the broader security community.
-
Manage researcher communications, triage workflows, and resolution timelines with professionalism and transparency.
-
Act as the primary liaison between external researchers and internal security and engineering teams during vulnerability disclosure.
Security Coordination and Incident Response
-
Support incident classification and escalation workflows when vulnerabilities or security issues are discovered in production environments.
-
Coordinate responsible disclosure timelines and remediation activities with affected stakeholders.
-
Contribute to root-cause analysis and process improvements following vulnerability discovery or security incidents.
-
Document findings, remediation steps, and lessons learned to improve product and platform security practices.
-
Maintain detailed records of findings and resolutions for audit and compliance purposes.
Program Measurement and Improvement
-
Track and report on product and platform security KPIs, including vulnerability trends, remediation timelines, recurrence, and researcher engagement.
-
Analyze patterns in vulnerability types to identify systemic risks, control gaps, and technical debt.
-
Provide regular insights to leadership on security risks, emerging threats, researcher feedback, and program effectiveness.
-
Recommend enhancements to security controls, testing coverage, program scope, and remediation processes based on data.
-
Benchmark Nscale’s product and platform security practices against industry peers in cloud infrastructure and AI/GPU platforms.
Threat Intelligence and Security Awareness
-
Monitor emerging vulnerabilities, attack vectors, and security trends relevant to cloud platforms, GPU infrastructure, Kubernetes, containers, and AI systems.
-
Share findings with security, product, platform, and engineering teams to inform prevention and detection strategies.
-
Support security awareness and training initiatives by communicating lessons learned from vulnerabilities and incidents.
-
Promote security ownership across engineering teams through practical guidance, collaboration, and knowledge sharing.
KPIs
-
Reduction in product and platform security risk and recurring vulnerability types
-
Time to validate, prioritize, and resolve reported vulnerabilities
-
Security review and threat-modeling coverage for critical products and platform changes
-
Adoption and effectiveness of secure engineering standards and controls
-
Researcher engagement and responsible disclosure outcomes
About You
-
10+ years of experience in information security, including substantial hands-on experience in product security, application security, platform security, or vulnerability management.
-
Deep technical expertise in threat modeling, security architecture, vulnerability assessment, and secure coding practices.
-
Experience partnering with software, platform, and infrastructure engineering teams to embed security throughout the development lifecycle.
-
Strong understanding of CVSS scoring, vulnerability prioritization, and risk quantification.
-
Proficiency with vulnerability scanners, application security tooling, SIEM platforms, EDR tools, and GRC systems.
-
Experience with responsible disclosure frameworks, bug bounty programs, and coordinating multi-stakeholder vulnerability remediation.
-
Excellent communication skills, with the ability to explain technical findings to researchers, engineers, leaders, and non-technical stakeholders.
-
Comfort working in complex, high-stakes environments where security decisions affect product reliability and customer trust.
-
Experience with GPU/HPC or cloud infrastructure security, including AWS, GCP, or Azure.
-
Knowledge of Kubernetes, container security, APIs, identity and access management, and hybrid cloud architectures.
-
A background in product security, application security, incident response, vulnerability management, penetration testing, or hands-on work with bug bounty platforms.
What we can offer you
At Nscale, you'll find a collaborative, supportive, and innovative environment where your contributions spark real impact. We're building something extraordinary, and we want you at the core.
Highly competitive US compensation package (base + bonus + equity), with performance reviews every 12 months. 🚀
Join one of the fastest-growing AI infrastructure companies — your chance to directly shape how global AI capacity is planned and deployed. ✨
Expect a dynamic progression plan tailored to your ambitions. Grow by leading critical cross-functional initiatives and shaping capital strategy — always with our full support.
Human-First Flexibility: We treat you as humans first. 🫶🏽 Our flexible workplace trusts Nscalers to deliver, giving you the autonomy to shape your day around life's moments.
Equal Opportunities Statement
We strongly encourage applications from people of colour, the LGBTQ+ community, people with disabilities, neurodivergent people, parents, carers, and people from lower socio-economic backgrounds.
If there’s anything we can do to accommodate your specific situation, please let us know.
The responsibilities outlined in this job description are not exhaustive and are intended to provide a general overview of the position. The employee may be required to perform additional duties, tasks, and responsibilities as assigned by management, consistent with the skills and qualifications required for the role.
For information on how Nscale handles candidate personal data, please see our Employee & Candidate Privacy Notice: Here.
The range below reflects the base salary for the position. Actual compensation may vary based on job-related factors such as skill set, experience, education, and location. In addition to base salary, this role may be eligible for bonus, equity, and/or commission programs. Nscale may offer a competitive benefits package including medical, dental, vision, flexible paid time off, parental leave, and retirement plan participation.
Salary Range
$190,000—$230,000 USD
For information on how Nscale handles candidate personal data, please see our Employee & Candidate Privacy Notice: Here.