{"id":649663,"url":"https://alion.io/job/nscale-security-response-engineer-cyber-defense","title":"Security Response Engineer, Cyber Defense","company":{"id":48155,"name":"Nscale","domain":"nscale.com","url":"https://alion.io/company/nscale","size_band":"501-1000","is_staffing_agency":false,"is_intermediary":false,"listed_via":null,"ats_vendor":"Greenhouse","truth_index":{"grade":"A","score":93,"open_postings":45,"ghost_share":0,"stale_share":0.267,"repost_share":0,"time_to_fill_p50_days":56,"computed_at":"2026-09-24T05:45:00Z"}},"role":"Security","role_family":"Security","seniority":"senior","employment_type":"full_time","work_mode":"on_site","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["New York, United States"],"countries":["US"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":141000,"max_usd":281000,"period":"year","method":"role_seniority_country_remote_cell","sample_n":659},"experience_years_min":5,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"HPC","optional":true}],"status":"live","first_seen_at":"2026-07-07T17:42:22Z","employer_posted_date":"2026-09-14","last_verified_at":"2026-09-25T02:08:41Z","board_verified":true,"closed_at":null,"days_open":79,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":79},"description":"About Nscale\nNscale is building the infrastructure platform for the AI era. We provide cost-effective, high-performance infrastructure for AI start-ups and large enterprise customers, reducing the complexity of AI development and helping customers manage cost, innovate rapidly, and operate responsibly.\nWe thrive on a culture of relentless innovation, ownership, and accountability, where every team member takes pride in their work and drives it with excellence and urgency. As an Nscaler, you’ll build trust through openness and transparency, where everyone is inspired to do their best work. If you join our team, you’ll be contributing to building the technology that powers the future.\nAbout the Role\nWe are hiring Security Response Engineers to own what happens after an alert becomes real, across enterprise, cloud, production, data centre, and operational technology environments.\nAgents and a managed security service provider (MSP) hold the level 1 queue. You take escalations, decide fast, act, and then make sure the same class of problem does not come back. Half the job is response. The other half is turning what you learned into engineering work that permanently retires the issue.\nIf you have spent years closing the same ticket every Tuesday-and knowing exactly how to fix it for good, but never having the mandate-this is the job where that is the mandate.\nHow this function works\nRead this section carefully. It is not a standard SOC, and the difference is the whole point.\nYou do not watch a queue. An in-house security agent and a contracted managed provider hold level 0 and level 1 around the clock. Work reaches you as an escalation with context already attached.\nEvery escalation forks three ways: act, solve, or both. Act is the immediate containment. Solve is the engineering artifact you hand to the build teams so that alert class does not fire again. Most escalations are both.\nYour primary metric is the share of escalations permanently solved. Not tickets closed, and not mean time to close. If the same alert fires twice, we got it wrong the first time.\nTwo classes, not five. We sort everything into risk indicator or actionable, using the SSVC model. If you have drowned in a five-tier severity scheme nobody trusted, you will like this.\nFollow-the-sun across hubs. Nobody works permanent nights.\nWhat you'll be doing\nEscalation response\nTake escalations from the agent and managed provider, scope them against real asset and business context, decide, and act.\nExecute approved containment, including isolating devices, revoking sessions, restricting access, blocking activity, and preserving evidence.\nKnow what you can do immediately, what requires authority, and what could disrupt production if handled incorrectly.\nThe solve\nEnsure every escalation exits with an engineering artifact where one is warranted: a detection requirement, telemetry gap with a business case, control change, automation, or regression test.\nSpecify the artifact clearly enough that the team building it can act without a second conversation. You do not build it; you make the required outcome unambiguous.\nInvestigation and evidence\nBuild timelines from primary evidence across identity, endpoint, email, SaaS, cloud, network, production, and increasingly operational technology and building management systems, which are currently dark to us.\nClose every case with a security disposition, an owner, the evidence, actions taken, and any required follow-up.\nDetection judgement\nReview candidate detections auto-authored by our research loop as shadow rules and assess their inside-out coverage.\nMake the human judgement on whether shadow detections should be promoted to live. You do not write the detection logic, but nothing goes live without your call.\nProvider quality\nReconcile the managed provider’s case work, which lives in their platform rather than ours, against our standards.\nHold the provider accountable for evidence, analysis, routing, and closure quality.\nReadiness\nContribute to threat hunts, incident reviews, tabletop exercises, recovery tests, the on-call rotation, and keeping runbooks honest.\nFirst 90 days\nIndependently own escalations across common classes, with defensible dispositions and evidence that stands up.\nShip your first solve: an engineering artifact that permanently retires a recurring alert class.\nLearn the incident command, escalation, evidence, and handover model, and take a rotation slot.\nReview the managed provider’s case quality against our standard and raise the first reconciliation findings.\nJudge and promote your first shadow detections to live.\nTake part in a threat hunt, tabletop, or recovery exercise.\nName one telemetry gap with a business case behind it. Extra credit if it is in operational technology or building management systems, both of which we currently cannot see.\nKPIs\nShare of escalations permanently solved\nQuality and defensibility of security dispositions and evidence\nContainment judgement and response effectiveness\nQuality and actionability of engineering artifacts\nManaged provider quality and reconciliation\nAbout You\n5+ years in security operations, incident response, threat detection, threat hunting, security engineering, or related roles.\nHands-on investigation experience across endpoint, identity, cloud, SaaS, network, or production telemetry, with the ability to build a timeline from primary evidence rather than a vendor summary.\nFluency in modern attacker tradecraft, including credential theft, session abuse, phishing, malware execution, persistence, privilege escalation, lateral movement, command and control, and exfiltration.\nYou automate what you repeat, using query languages, scripting, APIs, or workflow automation. When you hit the same problem a third time, your instinct is to build-not add another step to a runbook.\nSound judgement on containment under time pressure, including knowing where your authority ends.\nYou write investigations another engineer can follow, escalations a leader can act on in thirty seconds, and case notes that still make sense to someone reading them two years later in an audit.\nCalm and methodical when facts are incomplete or contradict each other.\nWillingness to challenge automated conclusions. AI-generated analysis is an input, not an authority; we expect you to validate it and notice when it is confidently wrong.\nAbility to work effectively with engineering, infrastructure, and service owners who do not report to you.\nStrong pluses\nOperational technology, industrial control systems, building management systems, or critical facilities experience. We have a known gap here and will weight it heavily.\nCloud infrastructure, AI infrastructure, data centres, HPC, or other availability-sensitive environments.\nResponse experience involving ransomware, identity compromise, destructive attacks, cloud intrusion, insider threats, or supply-chain incidents.\nExperience holding a managed monitoring or response provider to a standard while keeping decisions in-house.\nDetection testing, shadow-rule validation, threat hunting, or forensic readiness.\nFollow-the-sun, shift-based, or on-call operations.\nCertifications are useful, but not required.\nHow we will assess\nAn investigation, end to end. Signal to evidence to scope to containment to disposition. We are listening for what you decided independently, what you escalated, and why.\nThe solve. This is the most important answer in the process. Describe a recurring problem you permanently retired: the artifact, who built it, and how you proved it worked.\nAutomation instinct. Tell us about recurring toil you inherited and whether you reached for a tool, a person, or a build.\nJudging a machine. Describe a time an alert, vendor, or model was confidently wrong and how you caught it.\nWriting. We may ask for a redacted investigation write-up or escalation note.\nWhere this leads\nResponse Engineers here develop the sharpest picture in the company of where the estate actually breaks. They are strong internal candidates for detection engineering, platform security, and identity roles as those pillars grow. We would rather grow our next engineers here than hire them all in.\nThis role may not be a fit if you:\nWant a queue to work through. There is not one.\nMeasure success in tickets closed.\nClose cases without a security disposition or evidence.\nForward vendor alerts without validating them.\nWant to write detections full time. That role is real and well funded here, but it sits in another pillar; we would rather point you towards it than mis-hire you into this one.\nWhat we can offer you\nAt Nscale, you'll find a collaborative, supportive, and innovative environment where your contributions spark real impact. We're building something extraordinary, and we want you at the core.\nHighly competitive US compensation package (base + bonus + equity), with performance reviews every 12 months.\nJoin one of the fastest-growing AI infrastructure companies-your chance to directly shape how global AI capacity is planned and deployed.\nExpect a dynamic progression plan tailored to your ambitions. Grow by leading critical cross-functional initiatives and shaping capital strategy-always with our full support.\nHuman-First Flexibility: We treat you as humans first. Our flexible workplace trusts Nscalers to deliver, giving you the autonomy to shape your day around life's moments.\nEqual Opportunities Statement\nWe strongly encourage applications from people of colour, the LGBTQ+ community, people with disabilities, neurodivergent people, parents, carers, and people from lower socio-economic backgrounds.\nIf there’s anything we can do to accommodate your specific situation, please let us know.\nThe responsibilities outlined in this job description are not exhaustive and are intended to provide a general overview of the position. The employee may be required to perform additional duties, tasks, and responsibilities as assigned by management, consistent with the skills and qualifications required for the role.\nFor information on how Nscale handles candidate personal data, please see our Employee & Candidate Privacy Notice: Here.\nSalary Range\nThe range below reflects the base salary for the position. Actual compensation may vary based on job-related factors such as skill set, experience, education, and location. In addition to base salary, this role may be eligible for bonus, equity, and/or commission programs. Nscale may offer a competitive benefits package including medical, dental, vision, flexible paid time off, parental leave, and retirement plan participation.\nThe range below reflects the base salary for the position. Actual compensation may vary based on job-related factors such as skill set, experience, education, and location. In addition to base salary, this role may be eligible for bonus, equity, and/or commission programs. Nscale may offer a competitive benefits package including medical, dental, vision, flexible paid time off, parental leave, and retirement plan participation.\nSalary Range\n$100,000—$130,000 USD\nFor information on how Nscale handles candidate personal data, please see our Employee & Candidate Privacy Notice: Here.\nNscale does not accept unsolicited candidate submissions from recruitment agencies.","description_format":"text","description_chars":11264,"description_truncated":false,"requirements":{"experience_years_min":5,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[]},"benefits":["Equity","Flexible schedule","Parental leave","Retirement plans"],"hiring_locations":[],"hiring_excludes":[],"relocation_offered":false,"industries":["Cybersecurity","C4ISR","Data Centers","Cloud Computing"],"lifecycle":[{"event":"open","at":"2026-09-10T20:22:42Z"}],"liveness":{"score":33,"band":"fade","label":"Fading","p_open":1,"p_active":0.749,"p_room":0.44,"age_days":78,"expected_fill_days":56,"reasons":["conf:3","velocity","win:tail","crowd:brand"],"computed_at":"2026-09-24T05:45:00Z"},"pay":null,"html_url":"https://alion.io/job/nscale-security-response-engineer-cyber-defense","json_url":"https://alion.io/job/nscale-security-response-engineer-cyber-defense.json","meta":{"generated_at":"2026-09-25T02:30:35Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":2680,"day_limit":5000,"remaining_today":2320,"minute_limit":60,"resets_at":"2026-09-26T00:00:00Z"}}}