Senior Staff Security Engineer @Nscale
All Others
Salary $210,000 - $250..
Remote Location
πŸ‡ΊπŸ‡Έ USA Only
Employment Type full-time
Posted 1mth ago

[Hiring] Senior Staff Security Engineer @Nscale

1mth ago - Nscale is hiring a remote Senior Staff Security Engineer. πŸ’Έ Salary: $210,000 - $250,000 usd πŸ“Location: USA

Role Description

We are hiring a Senior Staff Security Engineer as a founding member of Nscale's Platform Security program. Your job is to go deep on how our IaaS platform is actually built β€” not how the diagrams say it is built β€” and to perform the security reviews that tell leadership and customers where it holds, where it doesn't, and what it will take to close the gap.

The scope is the infrastructure layer: the GPU compute platform, storage, virtual networking, and Kubernetes. Across each of these you'll map the architecture, define what secure looks like, review designs and implementations against that standard, test isolation boundaries, and produce assurance evidence. The estate spans bare-metal GPU infrastructure, Slurm/HPC scheduling, and Kubernetes.

This is a hands-on assurance role. You will spend most of your time inside the platform β€” reading configuration, tracing data and control paths, breaking isolation assumptions, and working alongside platform, SRE, and infrastructure engineering to land fixes. You will have done this before, at a cloud services provider, where the platform was the product.

What you'll be doing

  • Platform security reviews
    • Perform deep-dive security reviews of Nscale's IaaS services, one service at a time, producing a documented architecture, threat model, findings, and remediation plan for each.
    • Define the security requirements baseline for each service and review designs and implementations against it.
    • Prioritise findings by exploitability in our environment.
    • Advise leadership on what is known, verified, accepted, and required to close platform security gaps.
  • GPU compute platform
    • Review the bare-metal and virtualised GPU compute stack: host provisioning, hypervisor and GPU passthrough or partitioning, firmware and BMC management, and tenant reprovisioning.
    • Verify that a tenant cannot reach, persist on, or learn from hardware after their lease ends.
    • Assess the out-of-band management plane and its separation from tenant-reachable networks.
  • Storage
    • Review block, object, and file storage services for tenant data separation, encryption at rest and in transit, key management, and access-path control.
    • Verify snapshot, backup, and volume lifecycle handling β€” including secure deletion and reuse β€” across tenants.
  • Virtual networking
    • Review the virtual network layer: overlay and underlay design, tenant segmentation, east-west controls, and the boundary between tenant networks and the management plane.
    • Test that segmentation holds under realistic tenant behaviour, not only under the design assumptions.
  • Kubernetes and Slurm
    • Review multi-tenant Kubernetes: admission control, workload identity, runtime and node hardening, network policy, and container escape paths.
    • Review Slurm/HPC scheduling for isolation between jobs and tenants, privilege boundaries, and node reuse.
    • Drive testing of isolation boundaries and gather evidence that demonstrates customer workloads are separated.
  • Engineering partnership
    • Partner with platform, SRE, and infrastructure engineering to land fixes and secure-by-default patterns.
    • Influence teams you don't manage without becoming their ticket queue.
    • Track control coverage and remediation trends so "secure" is a number, not a word.

Qualifications

  • 12+ years in security engineering, platform/infrastructure engineering, or security architecture, with a deep platform security focus.
  • Experience at a cloud services provider β€” you have secured or assessed IaaS services where the platform was the product and tenants were untrusted by default.
  • Deep understanding of multi-tenant isolation across bare metal, hypervisors, container boundaries, and network segmentation β€” including what it takes to prove separation rather than assert it.
  • Hands-on knowledge of GPU or accelerator infrastructure: passthrough and partitioning, firmware and BMC management, and the failure modes of hardware reuse between tenants.
  • Strong grasp of storage security in a multi-tenant setting: encryption and key management, access-path control, and data lifecycle across snapshots, backups, and reuse.
  • Working knowledge of virtual networking: overlay/underlay design, segmentation, and management-plane separation.
  • Deep knowledge of Kubernetes and container internals, including runtimes, namespaces and cgroups, escape paths, admission control, and workload identity.
  • Experience securing or assessing Slurm/HPC environments is a strong plus.
  • Proven ability to influence engineering organisations you don't manage, set standards, win arguments through evidence, and drive remediation without formal authority.
  • Comfortable operating with ambiguity and a founding-team mandate, creating the evidence base as you build the program.

Benefits

  • Highly competitive US compensation package (base + bonus + equity), with performance reviews every 12 months.
  • Join one of the fastest-growing AI infrastructure companies β€” your chance to directly shape how global AI capacity is planned and deployed.
  • Expect a dynamic progression plan tailored to your ambitions. Grow by leading critical cross-functional initiatives and shaping capital strategy β€” always with our full support.
  • Human-First Flexibility: We treat you as humans first. Our flexible workplace trusts Nscalers to deliver, giving you the autonomy to shape your day around life's moments.
Before You Apply
️
πŸ‡ΊπŸ‡Έ Be aware of the location restriction for this remote position: USA Only
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Senior Staff Security Engineer @Nscale
All Others
Salary $210,000 - $250..
Remote Location
πŸ‡ΊπŸ‡Έ USA Only
Employment Type full-time
Posted 1mth ago
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 125,000+ Remote Jobs
️
πŸ‡ΊπŸ‡Έ Be aware of the location restriction for this remote position: USA Only
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 125,000+ Remote Jobs
Γ—
Apply to the best remote jobs
before everyone else

Access 125,000+ vetted remote jobs and get daily alerts.

4.9 β˜…β˜…β˜…β˜…β˜… from 500+ reviews

⚑ 125,709+ remote jobs, refreshed hourly

πŸ”” Real-time alerts: Apply first, direct to employer

πŸ›‘οΈ Vetted companies, no scams, true remote only

Unlock All Jobs Now

Maybe later