746,022open jobs
44,798companies
108,231added this week
Browse all
Salary
≈ $141k – $281k per year (Estimated)
Location
In office (New York)
Seniority
Senior · 5+ years exp
Employment
Full-Time

Confirmed on the employer's own hiring board on Sep 24, 2026. First seen by Alion on Jul 7, 2026. Nscale scores A on the Alion truth index.

Overview
Company
Impact
Profile match
Nscale is a London-based AI infrastructure company that builds and operates GPU data centres and runs a full-stack AI cloud offering managed inference, Kubernetes and Slurm clusters, bare-metal instances and dedicated GPU capacity. Founded in 2024 by Josh Payne and Nathan Townsend, it develops sites in Norway, the UK, South Korea and North America, works with Microsoft and NVIDIA, and acquired Anyscale in July 2026 to extend its cloud platform. Its hiring spans data centre design and construction, electrical and infrastructure operations, HPC and storage engineering, networking, solutions architecture, legal, finance and marketing.

About Nscale

Nscale is building the infrastructure platform for the AI era. We provide cost-effective, high-performance infrastructure for AI start-ups and large enterprise customers, reducing the complexity of AI development and helping customers manage cost, innovate rapidly, and operate responsibly.

We thrive on a culture of relentless innovation, ownership, and accountability, where every team member takes pride in their work and drives it with excellence and urgency. As an Nscaler, you’ll build trust through openness and transparency, where everyone is inspired to do their best work. If you join our team, you’ll be contributing to building the technology that powers the future.

About the Role

We are hiring Security Response Engineers to own what happens after an alert becomes real, across enterprise, cloud, production, data centre, and operational technology environments.

Agents and a managed security service provider (MSP) hold the level 1 queue. You take escalations, decide fast, act, and then make sure the same class of problem does not come back. Half the job is response. The other half is turning what you learned into engineering work that permanently retires the issue.

If you have spent years closing the same ticket every Tuesday-and knowing exactly how to fix it for good, but never having the mandate-this is the job where that is the mandate.

How this function works

Read this section carefully. It is not a standard SOC, and the difference is the whole point.

  • You do not watch a queue. An in-house security agent and a contracted managed provider hold level 0 and level 1 around the clock. Work reaches you as an escalation with context already attached.
  • Every escalation forks three ways: act, solve, or both. Act is the immediate containment. Solve is the engineering artifact you hand to the build teams so that alert class does not fire again. Most escalations are both.
  • Your primary metric is the share of escalations permanently solved. Not tickets closed, and not mean time to close. If the same alert fires twice, we got it wrong the first time.
  • Two classes, not five. We sort everything into risk indicator or actionable, using the SSVC model. If you have drowned in a five-tier severity scheme nobody trusted, you will like this.
  • Follow-the-sun across hubs. Nobody works permanent nights.

What you'll be doing

Escalation response

  • Take escalations from the agent and managed provider, scope them against real asset and business context, decide, and act.
  • Execute approved containment, including isolating devices, revoking sessions, restricting access, blocking activity, and preserving evidence.
  • Know what you can do immediately, what requires authority, and what could disrupt production if handled incorrectly.

The solve

  • Ensure every escalation exits with an engineering artifact where one is warranted: a detection requirement, telemetry gap with a business case, control change, automation, or regression test.
  • Specify the artifact clearly enough that the team building it can act without a second conversation. You do not build it; you make the required outcome unambiguous.

Investigation and evidence

  • Build timelines from primary evidence across identity, endpoint, email, SaaS, cloud, network, production, and increasingly operational technology and building management systems, which are currently dark to us.
  • Close every case with a security disposition, an owner, the evidence, actions taken, and any required follow-up.

Detection judgement

  • Review candidate detections auto-authored by our research loop as shadow rules and assess their inside-out coverage.
  • Make the human judgement on whether shadow detections should be promoted to live. You do not write the detection logic, but nothing goes live without your call.

Provider quality

  • Reconcile the managed provider’s case work, which lives in their platform rather than ours, against our standards.
  • Hold the provider accountable for evidence, analysis, routing, and closure quality.

Readiness

  • Contribute to threat hunts, incident reviews, tabletop exercises, recovery tests, the on-call rotation, and keeping runbooks honest.

First 90 days

  • Independently own escalations across common classes, with defensible dispositions and evidence that stands up.
  • Ship your first solve: an engineering artifact that permanently retires a recurring alert class.
  • Learn the incident command, escalation, evidence, and handover model, and take a rotation slot.
  • Review the managed provider’s case quality against our standard and raise the first reconciliation findings.
  • Judge and promote your first shadow detections to live.
  • Take part in a threat hunt, tabletop, or recovery exercise.
  • Name one telemetry gap with a business case behind it. Extra credit if it is in operational technology or building management systems, both of which we currently cannot see.

KPIs

  • Share of escalations permanently solved
  • Quality and defensibility of security dispositions and evidence
  • Containment judgement and response effectiveness
  • Quality and actionability of engineering artifacts
  • Managed provider quality and reconciliation

About You

  • 5+ years in security operations, incident response, threat detection, threat hunting, security engineering, or related roles.
  • Hands-on investigation experience across endpoint, identity, cloud, SaaS, network, or production telemetry, with the ability to build a timeline from primary evidence rather than a vendor summary.
  • Fluency in modern attacker tradecraft, including credential theft, session abuse, phishing, malware execution, persistence, privilege escalation, lateral movement, command and control, and exfiltration.
  • You automate what you repeat, using query languages, scripting, APIs, or workflow automation. When you hit the same problem a third time, your instinct is to build-not add another step to a runbook.
  • Sound judgement on containment under time pressure, including knowing where your authority ends.
  • You write investigations another engineer can follow, escalations a leader can act on in thirty seconds, and case notes that still make sense to someone reading them two years later in an audit.
  • Calm and methodical when facts are incomplete or contradict each other.
  • Willingness to challenge automated conclusions. AI-generated analysis is an input, not an authority; we expect you to validate it and notice when it is confidently wrong.
  • Ability to work effectively with engineering, infrastructure, and service owners who do not report to you.

Strong pluses

  • Operational technology, industrial control systems, building management systems, or critical facilities experience. We have a known gap here and will weight it heavily.
  • Cloud infrastructure, AI infrastructure, data centres, HPC, or other availability-sensitive environments.
  • Response experience involving ransomware, identity compromise, destructive attacks, cloud intrusion, insider threats, or supply-chain incidents.
  • Experience holding a managed monitoring or response provider to a standard while keeping decisions in-house.
  • Detection testing, shadow-rule validation, threat hunting, or forensic readiness.
  • Follow-the-sun, shift-based, or on-call operations.
  • Certifications are useful, but not required.

How we will assess

  • An investigation, end to end. Signal to evidence to scope to containment to disposition. We are listening for what you decided independently, what you escalated, and why.
  • The solve. This is the most important answer in the process. Describe a recurring problem you permanently retired: the artifact, who built it, and how you proved it worked.
  • Automation instinct. Tell us about recurring toil you inherited and whether you reached for a tool, a person, or a build.
  • Judging a machine. Describe a time an alert, vendor, or model was confidently wrong and how you caught it.
  • Writing. We may ask for a redacted investigation write-up or escalation note.

Where this leads

Response Engineers here develop the sharpest picture in the company of where the estate actually breaks. They are strong internal candidates for detection engineering, platform security, and identity roles as those pillars grow. We would rather grow our next engineers here than hire them all in.

This role may not be a fit if you:

  • Want a queue to work through. There is not one.
  • Measure success in tickets closed.
  • Close cases without a security disposition or evidence.
  • Forward vendor alerts without validating them.
  • Want to write detections full time. That role is real and well funded here, but it sits in another pillar; we would rather point you towards it than mis-hire you into this one.

What we can offer you

At Nscale, you'll find a collaborative, supportive, and innovative environment where your contributions spark real impact. We're building something extraordinary, and we want you at the core.

Highly competitive US compensation package (base + bonus + equity), with performance reviews every 12 months.

Join one of the fastest-growing AI infrastructure companies-your chance to directly shape how global AI capacity is planned and deployed.

Expect a dynamic progression plan tailored to your ambitions. Grow by leading critical cross-functional initiatives and shaping capital strategy-always with our full support.

Human-First Flexibility: We treat you as humans first. Our flexible workplace trusts Nscalers to deliver, giving you the autonomy to shape your day around life's moments.

Equal Opportunities Statement

We strongly encourage applications from people of colour, the LGBTQ+ community, people with disabilities, neurodivergent people, parents, carers, and people from lower socio-economic backgrounds.

If there’s anything we can do to accommodate your specific situation, please let us know.

The responsibilities outlined in this job description are not exhaustive and are intended to provide a general overview of the position. The employee may be required to perform additional duties, tasks, and responsibilities as assigned by management, consistent with the skills and qualifications required for the role.

For information on how Nscale handles candidate personal data, please see our Employee & Candidate Privacy Notice: Here.

Salary Range

The range below reflects the base salary for the position. Actual compensation may vary based on job-related factors such as skill set, experience, education, and location. In addition to base salary, this role may be eligible for bonus, equity, and/or commission programs. Nscale may offer a competitive benefits package including medical, dental, vision, flexible paid time off, parental leave, and retirement plan participation.

The range below reflects the base salary for the position. Actual compensation may vary based on job-related factors such as skill set, experience, education, and location. In addition to base salary, this role may be eligible for bonus, equity, and/or commission programs. Nscale may offer a competitive benefits package including medical, dental, vision, flexible paid time off, parental leave, and retirement plan participation.

Salary Range

$100,000—$130,000 USD

For information on how Nscale handles candidate personal data, please see our Employee & Candidate Privacy Notice:  Here.

Nscale does not accept unsolicited candidate submissions from recruitment agencies.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
746,022 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Security
Similar stack
Same company
New York
$117k – $181k per year • In office • Full-Time • 5+ years exp • Bachelor's Degree • Austin
Python
JavaScript
TypeScript
SQL
Python
Django
AI/ML
LangChain
Claude
Claude Code
Model Context Protocol
Function Calling
AI Agents
CrewAI
Anthropic
OpenAI Codex
A2A
Agentic Workflows
Tool Use
Frontend
Angular
DevOps
Rest API
CI/CD
Linux
Cybersecurity
SIEM
Apply
$91k – $196k per year • Hybrid • Full-Time • 3+ years exp • PhD • United States
Python
JavaScript
DevOps
Azure
CI/CD
AWS
Cybersecurity
Least Privilege
SIEM
DLP
Apply
≈ $107k – $214k per year (Estimated) • In office • 5+ years exp • Atlanta
Python
PowerShell
DevOps
Rest API
Terraform
Ansible
GCP
Azure
AWS
Configuration Management
GitHub
TCP/IP
DNS
DHCP
VPN
Cybersecurity
Okta
Zscaler
Zero Trust
Microsoft Entra ID
Ping Identity
SIEM
DLP
Management
Agile
Apply
≈ $107k – $214k per year (Estimated) • In office • 5+ years exp • Atlanta
Python
PowerShell
DevOps
Rest API
Terraform
Ansible
GCP
Azure
AWS
Configuration Management
GitHub
TCP/IP
DNS
DHCP
VPN
Cybersecurity
Okta
Zscaler
Zero Trust
Microsoft Entra ID
Ping Identity
SIEM
DLP
Management
Agile
Apply
Cybersecurity Analyst 6 hours ago
$75k – $90k per year • In office • Secret • 3+ years exp • Bachelor's Degree • Portland
DevOps
Splunk
Cybersecurity
SIEM
Apply
$148k – $179k per year • In office • TS/SCI • 5+ years exp • Bachelor's Degree
Python
Bash
AI/ML
InfiniBand
DevOps
Red Hat
OpenShift
SLURM
Kubernetes
HPC
Linux
Apply
$86k – $135k per year • In office • Full-Time • 4+ years exp • Bachelor's Degree • Lemont
Python
Bash
AI/ML
InfiniBand
Machine Learning
DevOps
Grafana
HPC
Linux
Unix
Apply
$245k – $279k per year • In office • Full-Time • 10+ years exp • Bachelor's Degree • San Francisco • New York • San Jose
Python
Go
JavaScript
Rust
TypeScript
C#
Scala
AI/ML
AI Agents
Machine Learning
DevOps
GCP
Azure
AWS
HPC
Apply
$69k – $131k per year • In office • Top Secret • Full-Time • 2+ years exp • Bachelor's Degree • Tucson
Python
Java
C++
MATLAB
AI/ML
Machine Learning
DevOps
SLURM
HPC
Linux
Unix
Apply
≈ $43k – $122k per year (Estimated) • In office • New Taipei
Python
C++
AI/ML
CUDA Toolkit
CUDA
Machine Learning
DevOps
SLURM
Docker
Kubernetes
HPC
Linux
Quantum
Qiskit
Cirq
Apply
$190k – $230k per year • In office • 8+ years exp • Houston
Databases
Apache Kafka
Google BigQuery
BigQuery
Apply
$230k – $400k per year • In office • New York
Databases
NATS
RabbitMQ
Apache Kafka
DevOps
Terraform
GCP
Pulumi
Azure
AWS
Kubernetes
Apply
≈ $145k – $303k per year (Estimated) • In office • 10+ years exp • Houston
JavaScript
Node JS
Node JS
Commander.js
AI/ML
AI Agents
DevOps
Windows
Apply
$190k – $240k per year • In office • 10+ years exp • Houston
DevOps
GCP
Azure
AWS
Kubernetes
HPC
Cybersecurity
CVSS
Threat Modeling
Apply
$210k – $270k per year • In office • 12+ years exp • Houston
DevOps
SLURM
Kubernetes
HPC
Apply
$183k – $240k per year • Equity • Hybrid • Full-Time • 4+ years exp • New York • Seattle • San Francisco
Python
Go
JavaScript
TypeScript
AI/ML
AI Agents
LLM
DevOps
CI/CD
Cybersecurity
Threat Modeling
Apply
$81k – $92k per year • In office • Full-Time • 5+ years exp • High School Diploma • McLean • New York
Management
Outlook
Microsoft Office
Apply
$215k – $246k per year • In office • Full-Time • 7+ years exp • Bachelor's Degree • New York
Python
Java
SQL
Scala
Databases
Snowflake
Databricks
Cassandra
DynamoDB
Amazon Redshift
AI/ML
Spark
Dagster
Machine Learning
DevOps
Splunk
GCP
Azure
AWS
Management
Agile
Apply
$245k – $279k per year • In office • Full-Time • 10+ years exp • Bachelor's Degree • San Francisco • New York • San Jose
Python
Go
JavaScript
Rust
TypeScript
C#
Scala
AI/ML
AI Agents
Machine Learning
DevOps
GCP
Azure
AWS
HPC
Apply
$201k – $229k per year • In office • Full-Time • 4+ years exp • Bachelor's Degree • New York • McLean
Apply
See all jobs
This is one of many
746,022 more open roles from verified company boards, updated every day.