Nscale logo
Nscale

Nscale is the Hyperscaler engineered for AI.

Staff Security Engineer, Privileged Access

Security EngineerSecurity EngineerFull TimeRemoteLeadTeam 201-500Since 2024H1B No SponsorCompany SiteLinkedIn

Location

Netherlands

Posted

4 days ago

Salary

$175K - $225K / year

Seniority

Lead

Job Description

Staff Security Engineer, Privileged Access

Nscale

Role Description We’re hiring a Staff Security Engineer focused on Privileged Access and Access Automation to build Nscale’s privileged access operating model across enterprise systems, SaaS administration, infrastructure, production environments, source control, data platforms, and emergency access paths. This role sits inside the identity control plane and is intentionally execution-focused. You’ll work across Identity, Endpoint, Security Data, Network Security, Platform Engineering, IT, and service owners to turn privileged access into a practical engineering mechanism with: - Request, approval, justification - Time-bound elevation - Session or event evidence - Automated revocation - Break-glass - Clean audit trails This role is critical because standing privilege is one of the highest-risk patterns in a fast-growing infrastructure company. Your work will help make privileged access secure, fast, measurable, and recoverable so engineers can move quickly without relying on manual reviews, tribal knowledge, or permanent admin rights. Qualifications - 7+ years in identity security, privileged access, security engineering, infrastructure security, or related engineering roles - Hands-on experience designing or operating privileged access, JIT, break-glass, access request, approval, or access review workflows - Strong understanding of authentication, authorization, RBAC, SSO, MFA, access governance, admin tiering, and least privilege - Experience automating access workflows, entitlement cleanup, evidence collection, or revocation processes - Strong scripting, workflow automation, API integration, or platform engineering skills - Ability to translate access risk into practical controls that engineering and operations teams will adopt - Ability to work across enterprise systems, production environments, SaaS platforms, IT, infrastructure, and compliance stakeholders - Experience with service accounts, non-human identities, workload identities, API tokens, automation accounts, or secrets governance - Experience securing production access, source control administration, data platforms, cloud administration, or endpoint admin workflows - Experience designing access evidence for audit, customer assurance, or incident response Requirements - Build privileged access workflows across enterprise SaaS admin roles, production systems, cloud consoles, infrastructure management systems, source control, data platforms, endpoint admin, and emergency access paths - Design access patterns that support request, approval, justification, time-bound elevation, and automated revocation - Define practical controls that reduce reliance on permanent admin rights across high-risk environments - Establish clean audit trails for privileged access activity across critical systems - Implement JIT access patterns with approval, justification, expiry, revocation, and evidence collection - Create a privileged access baseline that defines who can approve access, what justification is required, how long access lasts, what evidence is captured, and how revocation works - Own exception governance for access paths that cannot yet meet the standard - Drive entitlement cleanup and stale privilege reduction through automation - Design break-glass access standards, ownership models, monitoring, and recovery procedures - Test emergency access workflows and validate break-glass readiness - Develop a tiering model for privileged access covering Tier 0 and Tier 1 systems, admin paths, sensitive groups, service-owner roles, and high-risk workflows - Identify the top 10 highest-risk standing privileges and create remediation paths - Define privileged access telemetry requirements for detection, investigations, audit, compliance, and executive reporting - Partner with Security Data to establish privileged access detections and source-health requirements - Track metrics including standing privilege reduction, JIT adoption, stale admin cleanup, break-glass test success, approval SLA, and access review closure - Build an inventory of top admin paths, owners, approvers, access methods, logging, expiry, and current risk Benefits - Highly competitive US compensation package (base + bonus + equity), with performance reviews every 12 months. - Join one of the fastest-growing AI infrastructure companies — your chance to directly shape how global AI capacity is planned and deployed. - Expect a dynamic progression plan tailored to your ambitions. - Human-First Flexibility: We treat you as humans first. Our flexible workplace trusts Nscalers to deliver, giving you the autonomy to shape your day around life's moments. Equal Opportunities Statement We strongly encourage applications from people of colour, the LGBTQ+ community, people with disabilities, neurodivergent people, parents, carers, and people from lower socio-economic backgrounds. If there’s anything we can do to accommodate your specific situation, please let us know.

Related Categories

Related Job Pages

More Security Engineer Jobs

Nscale logo

Senior Staff Security Engineer, Identity

Nscale

Nscale is the Hyperscaler engineered for AI.

Full TimeRemoteTeam 201-500Since 2024H1B No Sponsor

Role Description We’re hiring a Senior Staff Security Engineer, Identity to define and lead Nscale’s identity and access architecture at scale. This is a high-impact role focused on shaping how identity, authentication, and authorization operate across infrastructure, platform, and internal systems. You’ll set long-term technical direction, design foundational systems, and partner closely with engineering leadership as well as infrastructure, platform, and security teams to embed identity into every layer of the stack. Your work will directly influence how Nscale secures highly distributed systems, supports safe multi-tenant workloads, and builds scalable identity primitives for both humans and services. This role matters because identity is a foundational part of secure, scalable infrastructure—and you’ll help define how it evolves across the company. This role will be part of the global CISO organization. What you'll be doing - Identity strategy and architecture - Define Nscale’s identity vision and multi-year roadmap in line with platform and infrastructure strategy. - Set the long-term technical direction for identity, authentication, and authorization across core systems. - Design foundational identity architecture that can scale across distributed infrastructure environments. - Authentication and federation - Architect and standardize authentication systems, including SSO and federation patterns. - Implement identity integrations using protocols such as SAML and OIDC. - Establish scalable approaches for working with identity providers across internal and platform systems. - Authorization and access control - Design and evolve authorization frameworks using models such as RBAC, ABAC, and policy-based access control. - Drive consistent access patterns for complex, distributed systems where security and usability must both scale. - Standardize policy-as-code and automation approaches for identity and access control enforcement. - Workload identity and zero trust - Build and scale service-to-service authentication and workload identity patterns, including short-lived credentials and identity-based access. - Establish zero trust architecture principles and ensure they are enforced consistently across infrastructure. - Define identity patterns for cloud, Kubernetes, and GPU-based infrastructure environments. - Lead the design of privileged access management, secrets management, and secure access workflows. - Cross-functional technical leadership - Partner with infrastructure, platform, and security teams to integrate identity into core systems and services. - Influence large-scale initiatives across organizational boundaries as a senior technical leader. - Mentor senior engineers and raise the bar for security engineering across teams. KPIs - Multi-year identity roadmap delivery - Standardization of authentication and federation systems - Adoption of authorization and policy-as-code frameworks - Consistent zero trust and workload identity enforcement Qualifications - 10–15+ years of experience in security engineering or distributed systems, with deep expertise in identity and access management. - Proven experience designing and operating large-scale identity systems in cloud-native or infrastructure-heavy environments. - Strong expertise in authentication and federation protocols, including SAML, OIDC, and OAuth2. - Deep understanding of authorization models and policy systems such as RBAC, ABAC, and Rego/OPA. - Experience with cloud IAM and Kubernetes-native identity patterns, including workload identity and service accounts. - Experience designing service identity systems, mTLS, or identity-based networking in distributed systems. - Strong architectural judgment with the ability to balance security, usability, and performance. - Demonstrated ability to operate at a Senior Staff level by setting direction, influencing across org boundaries, and leading large-scale initiatives. - Nice to have: experience in AI infrastructure, high-performance computing, or GPU-based environments. - Nice to have: familiarity with multi-tenant system design, zero trust implementations, developer-facing security systems, or identity support for compliance frameworks such as SOC2 and ISO. Benefits - Highly competitive US compensation package (base + bonus + equity), with performance reviews every 12 months. - Join one of the fastest-growing AI infrastructure companies — your chance to directly shape how global AI capacity is planned and deployed. - Expect a dynamic progression plan tailored to your ambitions. Grow by leading critical cross-functional initiatives and shaping capital strategy — always with our full support. - Human-First Flexibility: We treat you as humans first. Our flexible workplace trusts Nscalers to deliver, giving you the autonomy to shape your day around life's moments.

United Kingdom
$175K - $225K / year
Nscale logo

Staff Security Engineer, Enterprise / SaaS Security

Nscale

Nscale is the Hyperscaler engineered for AI.

Full TimeRemoteTeam 201-500Since 2024H1B No Sponsor

Role Description We’re hiring a Staff Security Engineer, Enterprise / SaaS Security to lead the security strategy and architecture for Nscale’s SaaS and enterprise application ecosystem. In this role, you’ll sit at the intersection of security, IT, and engineering , owning how SaaS applications are secured, managed, and governed across the company. You’ll work closely with Identity, Legal, IT, and Compliance partners to strengthen access controls, improve application governance, and support secure adoption of the tools teams rely on every day. This is a high-impact Staff-level role focused on reducing risk from shadow IT, building scalable security controls, and enabling the business to move quickly without compromising security. Your work will help shape how enterprise tools are adopted and used across Nscale while balancing strong risk reduction with user productivity. This role will be part of the global CISO organization. What you'll be doing - SaaS Security Strategy & Architecture - Define and drive Nscale’s SaaS security strategy and roadmap - Own the security architecture for the company’s SaaS and enterprise application ecosystem - Build scalable security solutions that support rapid, secure tool adoption across the organization - Drive user-friendly security approaches that balance protection with productivity - Application Discovery, Governance & Risk Reduction - Discover and assess SaaS application inventory across the company - Identify and reduce risks associated with shadow IT - Establish governance for application onboarding, risk reviews, and vendor security assessments - Manage how SaaS applications are secured and governed throughout their lifecycle - Access Controls & Identity Integration - Design and enforce secure configurations and access controls across SaaS platforms - Partner with Identity teams to implement SSO, SCIM provisioning, and lifecycle management - Implement and automate least-privilege access and role-based controls across enterprise tools - Strengthen enterprise access models in alignment with identity systems and governance standards - Security Controls, Monitoring & Cross-Functional Enablement - Build and scale SaaS security controls, including CASB/SSPM, posture management, and monitoring - Integrate SaaS platforms into logging, monitoring, and detection systems - Partner with Legal, IT, and Compliance teams to align with security policies and regulatory requirements - Influence stakeholders across functions on secure adoption and use of enterprise tooling KPIs - Shadow IT identification and reduction - SSO, SCIM, and lifecycle management implementation - Least-privilege and role-based access control adoption - SaaS platform logging, monitoring, and detection coverage Qualifications - 8+ years of experience in security engineering, with a strong focus on enterprise and SaaS security - Deep experience securing major SaaS platforms such as Google Workspace, Microsoft 365, Okta, Slack, and Salesforce - Strong understanding of identity integration, including SSO, SCIM, and lifecycle management - Experience with SaaS security tools such as SSPM, CASB, or equivalent platforms - Experience identifying and mitigating shadow IT risks - Familiarity with access control models and enterprise identity systems - Ability to operate at a Staff level, owning systems and driving cross-functional initiatives - Confidence influencing stakeholders across security, IT, engineering, Legal, and Compliance - Nice to have: familiarity with API security and SaaS integrations - Nice to have: experience with automation, SaaS governance tooling, compliance frameworks, or integrating SaaS telemetry into SIEM or detection pipelines Benefits - Highly competitive US compensation package (base + bonus + equity), with performance reviews every 12 months. - Join one of the fastest-growing AI infrastructure companies — your chance to directly shape how global AI capacity is planned and deployed. - Expect a dynamic progression plan tailored to your ambitions. - Human-First Flexibility: We treat you as humans first. Our flexible workplace trusts Nscalers to deliver, giving you the autonomy to shape your day around life's moments.

Netherlands
$175K - $225K / year
Nscale logo

Staff Security Engineer, Threat Intelligence

Nscale

Nscale is the Hyperscaler engineered for AI.

Full TimeRemoteTeam 201-500Since 2024H1B No Sponsor

Role Description We’re hiring a Staff Security Engineer, Threat Intelligence to build and scale Nscale’s threat intelligence capability and turn adversary insight into actionable security outcomes. This is a high-impact, engineering-driven role focused on connecting external threat intelligence with internal telemetry so that what Nscale knows about attackers directly improves how the company detects and responds. The role works closely with Detection & Response and supports security efforts across infrastructure, cloud, and enterprise systems . You’ll help strengthen Nscale’s security posture by: - Tracking relevant threat actors, campaigns, and emerging techniques. - Translating intelligence into practical detections, defenses, and response improvements. - Ensuring intelligence is operationalized in the systems and workflows that protect the business. This role will be part of the global CISO organization. Qualifications - 8+ years of experience in threat intelligence, security engineering, or detection engineering. - Strong understanding of threat actors, tactics, techniques, and procedures (TTPs). - Experience translating intelligence into detections, rules, or security controls. - Familiarity with SIEM platforms and detection pipelines. - Experience with threat intelligence platforms (TIPs) and data formats such as STIX/TAXII. - Understanding of cloud environments and modern infrastructure. - Experience leveraging automation or AI/ML techniques for intelligence analysis or enrichment. - Ability to operate at a Staff level, driving strategy, influencing detection programs, and owning systems. - Clear communication skills with the ability to share insights and risks with technical teams and leadership. - Nice to have: experience in AI infrastructure, threat hunting, incident response, SOAR integrations, malware analysis, or advanced threat actor tracking. Requirements - Track relevant threat actors, campaigns, and emerging attack techniques tied to Nscale’s environment. - Analyze adversary tactics, techniques, and procedures to identify meaningful security implications. - Produce actionable threat intelligence tailored to infrastructure, cloud, and enterprise systems. - Evaluate external intelligence sources, feeds, and tooling for relevance and quality. - Translate intelligence into detection logic, SIEM rules, and security controls. - Partner with Detection & Response to improve coverage against known adversary behaviors. - Maintain mappings to frameworks such as MITRE ATT&CK and identify coverage gaps. - Improve defensive visibility by aligning detections to current and emerging threats. - Integrate threat intelligence into SIEM pipelines, enrichment systems, and automation workflows. - Leverage AI and automation to process large volumes of threat data and surface patterns. - Support the use of intelligence data within operational security systems and workflows. - Support incident response and threat hunting with contextual intelligence and hypothesis generation. - Communicate insights, risks, and adversary activity clearly to technical teams and leadership. - Enable more effective response playbooks by embedding intelligence into response workflows. Benefits - Highly competitive US compensation package (base + bonus + equity), with performance reviews every 12 months. - Opportunity to join one of the fastest-growing AI infrastructure companies. - Dynamic progression plan tailored to your ambitions. - Human-First Flexibility: A flexible workplace that trusts Nscalers to deliver.

Netherlands
$175K - $225K / year
GoDaddy logo

Senior Cloud Network Security Engineer

GoDaddy

GoDaddy is a web services platform that helps individuals and businesses worldwide start, grow, and manage their online presence. GoDaddy employs team members a

Role Description The Senior Cloud Network Security Engineer will play a crucial role in designing, building, and securing large-scale, distributed cloud environments that support GoDaddy Services. This role operates at the intersection of cloud infrastructure, security architecture, and engineering execution. The successful candidate will collaborate closely with service teams, security leaders, and compliance partners to embed security-by-design principles into cloud services and internal platforms. This position requires advanced technical expertise in cloud-native security controls and a strong understanding of threat models in hyperscale environments. Additionally, it involves influencing architecture decisions across multiple teams. The role demands hands-on engineering, good judgment in ambiguous situations, and proficiency at translating security requirements into scalable, automated solutions. - Build and maintain secure, scalable cloud architectures aligned with AWS security standards, including defining guardrails for multi-account and multi-region setups. - Establish and manage security controls across compute, storage, networking, and identity layers, leveraging infrastructure-as-code, policy-as-code, and continuous compliance automation. - Perform threat modeling, architecture reviews, and risk assessments for new and existing cloud services. - Collaborate with platform teams to integrate security into CI/CD pipelines and deployment workflows. - Contribute to security strategy, standards, and reference architectures; mentor junior engineers; and engage with audit, compliance, and risk teams to meet regulatory requirements. Qualifications - 8+ years of experience in security engineering, cloud engineering, or infrastructure engineering roles, with significant exposure to large-scale distributed systems. - Deep hands-on experience securing AWS environments, including services such as IAM, VPC, EC2, EKS, S3, Lambda, and CloudTrail. - Solid knowledge of cloud security domains, including identity and access management, network security, encryption and key management, logging and monitoring, and secrets management. - Proficiency with threat modeling methodologies (e.g., STRIDE), security architecture design, and risk-based decision making. - Proficiency in infrastructure-as-code and automation frameworks (e.g., AWS CDK, CloudFormation, Terraform) and scripting or programming languages (e.g., Python, Go, Java). - Experience building security automation and integrating automated security controls directly into platform CI/CD pipelines and deployment workflows. Requirements - Bachelor’s degree in Computer Science, Engineering, or a related field, or equivalent hands-on experience. - Familiarity with security standards and compliance frameworks (e.g., ISO 27001, SOC 2, NIST, PCI DSS) in cloud environments. Benefits - Paid time off. - Retirement savings (e.g., 401k, pension schemes). - Bonus/incentive eligibility. - Equity grants. - Participation in our employee stock purchase plan. - Competitive health benefits. - Other family-friendly benefits including parental leave.

India