Security Analyst; Security Operations
Listed on 2026-07-13
-
IT/Tech
Cybersecurity, Security Management & Operations
About Nscale
Nscale is the GPU cloud engineered for AI. We provide cost-effective, high-performance infrastructure for AI start-ups and large enterprise customers. Nscale enables AI-focused companies to achieve superior results by reducing the complexity of AI development. Our GPU cloud bolsters technical capabilities and directly supports strategic business outcomes, including cost management, rapid innovation, and environmental responsibility.
We thrive on a culture of relentless innovation, ownership, and accountability, where every team member takes pride in their work and drives it with excellence and urgency. As an Nscaler, you’ll build trust through openness and transparency, where everyone is inspired to do their best work. If you join our team, you’ll be contributing to building the technology that powers the future.
Aboutthe Role
We are hiring Security Analysts to run the daily security operations work that keeps Nscale protected.
This is a hands‑on analyst role, one level below Staff, working across alert triage, incident investigation, escalation, evidence collection, response coordination, vulnerability follow‑up, and operational reporting. The role connects closely with Incident Response, Cyber Defence, Enterprise Security, IT, Platform Engineering, identity, endpoint, vulnerability management, network security, GRC, and platform teams.
Security operations is where controls become real. This role helps ensure security events are investigated consistently, incidents are escalated quickly, and daily operational risks do not get lost in the noise. The right person will be curious, calm under pressure, technically practical, and comfortable working across endpoint, identity, SaaS, cloud, network, and production access signals.
What you’ll be doing Security alert triage and investigation- Triage daily security alerts across endpoint, identity, SaaS, cloud, network, email, and infrastructure telemetry.
- Investigate suspicious activity, including user behavior, device activity, login events, access changes, exposed assets, and potential data leakage.
- Separate signal from noise and make clear judgments on when to keep investigating, when to escalare, and when to ask for help.
- Escalate confirmed or high‑risk events to Incident Response, Cyber Defence, Enterprise Security, IT, Platform Engineering, or other owners.
- Execute documented response actions such as host isolation requests, account review, access disablement recommendations, malicious domain blocking requests, evidence capture, and case routing.
- Build incident timelines, collect evidence, and write clear handoff notes.
- Support post‑incident reviews, including missed opportunities in prevention, detection, response, and remediation.
- Produce daily and weekly operational reporting covering alert volumes, true positives, escalations, open cases, recurring issues, and response SLAs.
- Improve runbooks, investigation guides, alert tuning feedback, and automation opportunities.
- Identify recurring false positives, missing context, or weak handoff points and propose fixes.
- Follow up on vulnerabilities and exposures where daily operations identifies active risk, missing ownership, or overdue remediation.
- Learn Nscale's security operations workflows, escalation paths, severity model, key systems, and evidence standards.
- Build fluency across the core telemetry sources used for endpoint, identity, SaaS, cloud, and infrastructure investigations.
- Triage and document daily alerts with clear findings, confidence level, and recommended next action.
- Improve at least three runbooks or investigation guides based on real operational friction.
- Support at least one tabletop, incident review, or readiness exercise.
- Contribute to a weekly security operations report that leadership can use to understand risk, workload, and operational quality.
- Alert triage quality and timeliness
- Escalation accuracy and speed
- Investigation documentation quality
- Runbook, alert tuning, and automation improvements
- 3+ years in security operations, incident response, threat monitoring, SOC analysis,…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).