Sr. Security Engineer, Platform Security
Listed on 2026-09-07
-
IT/Tech
Systems Engineer, Cybersecurity, Cloud Computing: Infrastructure & Operations
Sr. Staff Security Engineer, Platform Security
Houston;
New York;
San Francisco;
Seattle
Nscale is the GPU cloud engineered for AI. We provide cost-effective, high-performance infrastructure for AI start-ups and large enterprise customers. Nscale enables AI-focused companies to achieve superior results by reducing the complexity of AI development. Our GPU cloud bolsters technical capabilities and directly supports strategic business outcomes, including cost management, rapid innovation, and environmental responsibility.
We thrive on a culture of relentless innovation, ownership, and accountability, where every team member takes pride in their work and drives it with excellence and urgency. As an Nscaler, you'll build trust through openness and transparency, where everyone is inspired to do their best work. If you join our team, you'll be contributing to building the technology that powers the future.
Aboutthe Role
We are hiring a Senior Staff Security Engineer as a founding member of Nscale's Platform Security program. Your job is to go deep on how our IaaS platform is actually built — not how the diagrams say it is built — and to perform the security reviews that tell leadership and customers where it holds, where it doesn't, and what it will take to close the gap.
The scope is the infrastructure layer: the GPU compute platform, storage, virtual networking, and Kubernetes. Across each of these you'll map the architecture, define what secure looks like, review designs and implementations against that standard, test isolation boundaries, and produce assurance evidence. The estate spans bare-metal GPU infrastructure, Slurm/HPC scheduling, and Kubernetes.
This is a hands-on assurance role. You will spend most of your time inside the platform — reading configuration, tracing data and control paths, breaking isolation assumptions, and working alongside platform, SRE, and infrastructure engineering to land fixes. You will have done this before, at a cloud services provider, where the platform was the product.
What You'll Be DoingPlatform Security Reviews
- Perform deep-dive security reviews of Nscale's IaaS services, one service at a time, producing a documented architecture, threat model, findings, and remediation plan for each.
- Define the security requirements baseline for each service and review designs and implementations against it.
- Prioritise findings by exploitability in our environment.
- Advise leadership on what is known, verified, accepted, and required to close platform security gaps.
GPU Compute Platform
- Review the bare-metal and virtualised GPU compute stack: host provisioning, hypervisor and GPU passthrough or partitioning, firmware and BMC management, and tenant reprovisioning.
- Verify that a tenant cannot reach, persist on, or learn from hardware after their lease ends.
- Assess the out-of-band management plane and its separation from tenant-reachable networks.
Storage
- Review block, object, and file storage services for tenant data separation, encryption at rest and in transit, key management, and access-path control.
- Verify snapshot, backup, and volume lifecycle handling — including secure deletion and reuse — across tenants.
Virtual Networking
- Review the virtual network layer: overlay and underlay design, tenant segmentation, east-west controls, and the boundary between tenant networks and the management plane.
- Test that segmentation holds under realistic tenant behaviour, not only under the design assumptions.
Kubernetes and Slurm
- Review multi-tenant Kubernetes: admission control, workload identity, runtime and node hardening, network policy, and container escape paths.
- Review Slurm/HPC scheduling for isolation between jobs and tenants, privilege boundaries, and node reuse.
- Drive testing of isolation boundaries and gather evidence that demonstrates customer workloads are separated.
Engineering Partnership
- Partner with platform, SRE, and infrastructure engineering to land fixes and secure-by-default patterns.
- Influence teams you don't manage without becoming their ticket queue.
- Track control coverage and remediation trends so "secure" is a number, not a word.
- Assurance Reviews Shipped
- Tenant…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).