Security Engineer, Product & Platform Security
Listed on 2026-09-06
-
IT/Tech
Cybersecurity
Staff Security Engineer, Product & Platform Security
Houston;
New York;
San Francisco;
Seattle
Nscale is the GPU cloud engineered for AI. We provide cost-effective, high-performance infrastructure for AI start-ups and large enterprise customers. Nscale enables AI-focused companies to achieve superior results by reducing the complexity of AI development. Our GPU cloud bolsters technical capabilities and directly supports strategic business outcomes, including cost management, rapid innovation, and environmental responsibility.
We thrive on a culture of relentless innovation, ownership, and accountability, where every team member takes pride in their work and drives it with excellence and urgency. As an Nscaler, you'll build trust through openness and transparency, where everyone is inspired to do their best work. If you join our team, you'll be contributing to building the technology that powers the future.
Aboutthe Role
We are seeking a Staff Security Engineer, Product and Platform Security to lead security initiatives across Nscale's products, cloud platforms, hyperscale GPU clusters, and critical infrastructure.
You'll partner closely with engineering, platform, infrastructure, and security teams to identify and reduce risk throughout the product and technology lifecycle. You'll provide hands-on security expertise across architecture and design reviews, threat modeling, vulnerability management, secure development, and incident response.
This role will help build and scale product and platform security practices while turning technical findings, researcher insights, and emerging threats into stronger engineering controls, clearer priorities, and measurable improvements to Nscale's security posture.
What You'll Be DoingProduct and Platform Security
- Lead security reviews across Nscale's products, cloud platforms, APIs, hyperscale GPU clusters, and supporting infrastructure.
- Partner with engineering teams throughout the development lifecycle to identify security risks and define practical remediation plans.
- Conduct threat modeling and architecture reviews for new products, features, services, and platform changes.
- Provide guidance on secure design, coding practices, authentication, authorization, data protection, and infrastructure security.
- Help develop reusable security standards, patterns, and guardrails that enable teams to build and deploy securely at scale.
Vulnerability Management and Remediation
- Receive, analyze, and validate vulnerability findings from internal testing, security tooling, external researchers, and other sources.
- Assign severity ratings using CVSS and assess technical and business impact to drive prioritization.
- Coordinate with engineering, platform, and infrastructure teams to reproduce, validate, and remediate findings.
- Create clear remediation roadmaps and track progress toward resolution.
- Identify recurring vulnerability patterns and work with engineering teams to address systemic risks and technical debt.
Bug Bounty and Responsible Disclosure
- Design, launch, and scale Nscale's bug bounty and vulnerability disclosure programs across platforms such as Hacker One, Bugcrowd, or equivalent.
- Establish clear scope definitions, reward guidelines, and submission processes that encourage high-quality vulnerability disclosures.
- Build trusted relationships with security researchers and the broader security community.
- Manage researcher communications, triage workflows, and resolution timelines with professionalism and transparency.
- Act as the primary liaison between external researchers and internal security and engineering teams during vulnerability disclosure.
Security Coordination and Incident Response
- Support incident classification and escalation workflows when vulnerabilities or security issues are discovered in production environments.
- Coordinate responsible disclosure timelines and remediation activities with affected stakeholders.
- Contribute to root-cause analysis and process improvements following vulnerability discovery or security incidents.
- Document findings, remediation steps, and lessons learned to improve product and platform security practices.
- Maintain detailed records of…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).