Human Risk Lead
Listed on 2026-07-27
-
Security
Cybersecurity, Information Security & Data Protection
Houston;
New York;
San Francisco;
Seattle
Nscale is the GPU cloud engineered for AI. We provide cost-effective, high-performance infrastructure for AI start-ups and large enterprise customers. Nscale enables AI-focused companies to achieve superior results by reducing the complexity of AI development. Our GPU cloud bolsters technical capabilities and directly supports strategic business outcomes, including cost management, rapid innovation, and environmental responsibility.
We thrive on a culture of relentless innovation, ownership, and accountability, where every team member takes pride in their work and drives it with excellence and urgency. As an Nscaler, you’ll build trust through openness and transparency, where everyone is inspired to do their best work. If you join our team, you’ll be contributing to building the technology that powers the future.
About the RoleWe’re hiring a Human Risk Lead to own the human layer of security at Nscale: awareness, behavior, and policy adoption across our global AI infrastructure.
This is a senior individual contributor role at the intersection of people, security, data, and program management. You’ll build the function from the ground up, working closely with every control tower and partnering with Insider Risk, Detection Engineering, HR, Legal, policy owners, and compliance engineering.
You’ll create a program that treats human risk as an engineering and data problem- combining behavioral analytics, security telemetry, insider risk, and organizational insights to make risk visible, drive measurable behavior change, and build a culture where security is a shared instinct.
What you'll be doingSecurity Awareness and Behavior Change
- Build and operate Nscale’s Security Awareness and Training program, delivering engaging, role-based learning for engineering, operations, corporate functions, executives, and privileged users.
- Update training using threat intelligence, incident learnings, emerging attacker techniques, regulatory changes, and AI-specific risks.
- Evaluate awareness initiatives through behavioral outcomes rather than relying only on completion metrics.
- Create targeted interventions that reduce risky behavior and improve phishing and social-engineering resilience.
- Build and own a data pipeline that combines learning outcomes, phishing exercises, identity signals, endpoint telemetry, policy adoption, collaboration patterns, and security events.
- Develop behavioral risk metrics that show where risk is concentrated across populations, functions, and business units.
- Make human risk queryable by creating a live picture of behavioral risk rather than relying on quarterly reporting.
- Define executive dashboards that communicate program maturity, behavioral trends, and opportunities for improvement.
- Partner with Insider Risk, Detection Engineering, HR, and Legal to understand behavioral indicators, trusted insider risks, and realistic abuse scenarios.
- Use behavioral analytics and incident trends to identify preventative education and risk-reduction opportunities while respecting privacy and governance boundaries.
- Differentiate accidental, negligent, and malicious behaviors so interventions are appropriately targeted.
- Translate relevant incident learnings into practical guidance and program improvements.
- Build and scale a Security Champions program that empowers advocates across engineering and business teams.
- Create repeatable communications, workshops, office hours, and community events that make security approachable and relevant.
- Foster a blame-free culture where employees confidently report suspicious activity, ask questions, and treat security as a shared responsibility.
- Partner with leaders to embed secure behaviors into day-to-day workflows.
- Partner with policy owners to translate security policies and standards into clear, actionable employee guidance.
- Manage policy communication, attestation, and adoption in a way that supports audit requirements.
- Own the human risk roadmap, communications calendar, and awareness initiatives, balancing…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).