Nscale logo
Nscale

Nscale is the Hyperscaler engineered for AI.

Senior Staff Security Engineer, Identity

Security EngineerSecurity EngineerFull TimeRemoteLeadTeam 201-500Since 2024H1B No SponsorCompany SiteLinkedIn

Location

United Kingdom

Posted

4 days ago

Salary

$175K - $225K / year

Seniority

Lead

Job Description

Senior Staff Security Engineer, Identity

Nscale

Role Description We’re hiring a Senior Staff Security Engineer, Identity to define and lead Nscale’s identity and access architecture at scale. This is a high-impact role focused on shaping how identity, authentication, and authorization operate across infrastructure, platform, and internal systems. You’ll set long-term technical direction, design foundational systems, and partner closely with engineering leadership as well as infrastructure, platform, and security teams to embed identity into every layer of the stack. Your work will directly influence how Nscale secures highly distributed systems, supports safe multi-tenant workloads, and builds scalable identity primitives for both humans and services. This role matters because identity is a foundational part of secure, scalable infrastructure—and you’ll help define how it evolves across the company. This role will be part of the global CISO organization. What you'll be doing - Identity strategy and architecture - Define Nscale’s identity vision and multi-year roadmap in line with platform and infrastructure strategy. - Set the long-term technical direction for identity, authentication, and authorization across core systems. - Design foundational identity architecture that can scale across distributed infrastructure environments. - Authentication and federation - Architect and standardize authentication systems, including SSO and federation patterns. - Implement identity integrations using protocols such as SAML and OIDC. - Establish scalable approaches for working with identity providers across internal and platform systems. - Authorization and access control - Design and evolve authorization frameworks using models such as RBAC, ABAC, and policy-based access control. - Drive consistent access patterns for complex, distributed systems where security and usability must both scale. - Standardize policy-as-code and automation approaches for identity and access control enforcement. - Workload identity and zero trust - Build and scale service-to-service authentication and workload identity patterns, including short-lived credentials and identity-based access. - Establish zero trust architecture principles and ensure they are enforced consistently across infrastructure. - Define identity patterns for cloud, Kubernetes, and GPU-based infrastructure environments. - Lead the design of privileged access management, secrets management, and secure access workflows. - Cross-functional technical leadership - Partner with infrastructure, platform, and security teams to integrate identity into core systems and services. - Influence large-scale initiatives across organizational boundaries as a senior technical leader. - Mentor senior engineers and raise the bar for security engineering across teams. KPIs - Multi-year identity roadmap delivery - Standardization of authentication and federation systems - Adoption of authorization and policy-as-code frameworks - Consistent zero trust and workload identity enforcement Qualifications - 10–15+ years of experience in security engineering or distributed systems, with deep expertise in identity and access management. - Proven experience designing and operating large-scale identity systems in cloud-native or infrastructure-heavy environments. - Strong expertise in authentication and federation protocols, including SAML, OIDC, and OAuth2. - Deep understanding of authorization models and policy systems such as RBAC, ABAC, and Rego/OPA. - Experience with cloud IAM and Kubernetes-native identity patterns, including workload identity and service accounts. - Experience designing service identity systems, mTLS, or identity-based networking in distributed systems. - Strong architectural judgment with the ability to balance security, usability, and performance. - Demonstrated ability to operate at a Senior Staff level by setting direction, influencing across org boundaries, and leading large-scale initiatives. - Nice to have: experience in AI infrastructure, high-performance computing, or GPU-based environments. - Nice to have: familiarity with multi-tenant system design, zero trust implementations, developer-facing security systems, or identity support for compliance frameworks such as SOC2 and ISO. Benefits - Highly competitive US compensation package (base + bonus + equity), with performance reviews every 12 months. - Join one of the fastest-growing AI infrastructure companies — your chance to directly shape how global AI capacity is planned and deployed. - Expect a dynamic progression plan tailored to your ambitions. Grow by leading critical cross-functional initiatives and shaping capital strategy — always with our full support. - Human-First Flexibility: We treat you as humans first. Our flexible workplace trusts Nscalers to deliver, giving you the autonomy to shape your day around life's moments.

Related Categories

Related Job Pages

More Security Engineer Jobs

GoDaddy logo

Senior Cloud Network Security Engineer

GoDaddy

GoDaddy is a web services platform that helps individuals and businesses worldwide start, grow, and manage their online presence. GoDaddy employs team members a

Role Description The Senior Cloud Network Security Engineer will play a crucial role in designing, building, and securing large-scale, distributed cloud environments that support GoDaddy Services. This role operates at the intersection of cloud infrastructure, security architecture, and engineering execution. The successful candidate will collaborate closely with service teams, security leaders, and compliance partners to embed security-by-design principles into cloud services and internal platforms. This position requires advanced technical expertise in cloud-native security controls and a strong understanding of threat models in hyperscale environments. Additionally, it involves influencing architecture decisions across multiple teams. The role demands hands-on engineering, good judgment in ambiguous situations, and proficiency at translating security requirements into scalable, automated solutions. - Build and maintain secure, scalable cloud architectures aligned with AWS security standards, including defining guardrails for multi-account and multi-region setups. - Establish and manage security controls across compute, storage, networking, and identity layers, leveraging infrastructure-as-code, policy-as-code, and continuous compliance automation. - Perform threat modeling, architecture reviews, and risk assessments for new and existing cloud services. - Collaborate with platform teams to integrate security into CI/CD pipelines and deployment workflows. - Contribute to security strategy, standards, and reference architectures; mentor junior engineers; and engage with audit, compliance, and risk teams to meet regulatory requirements. Qualifications - 8+ years of experience in security engineering, cloud engineering, or infrastructure engineering roles, with significant exposure to large-scale distributed systems. - Deep hands-on experience securing AWS environments, including services such as IAM, VPC, EC2, EKS, S3, Lambda, and CloudTrail. - Solid knowledge of cloud security domains, including identity and access management, network security, encryption and key management, logging and monitoring, and secrets management. - Proficiency with threat modeling methodologies (e.g., STRIDE), security architecture design, and risk-based decision making. - Proficiency in infrastructure-as-code and automation frameworks (e.g., AWS CDK, CloudFormation, Terraform) and scripting or programming languages (e.g., Python, Go, Java). - Experience building security automation and integrating automated security controls directly into platform CI/CD pipelines and deployment workflows. Requirements - Bachelor’s degree in Computer Science, Engineering, or a related field, or equivalent hands-on experience. - Familiarity with security standards and compliance frameworks (e.g., ISO 27001, SOC 2, NIST, PCI DSS) in cloud environments. Benefits - Paid time off. - Retirement savings (e.g., 401k, pension schemes). - Bonus/incentive eligibility. - Equity grants. - Participation in our employee stock purchase plan. - Competitive health benefits. - Other family-friendly benefits including parental leave.

India
GoDaddy logo

Principal Cloud Network Security Engineer

GoDaddy

GoDaddy is a web services platform that helps individuals and businesses worldwide start, grow, and manage their online presence. GoDaddy employs team members a

Role Description The Principal Cloud Network Security Engineer is a senior technical leadership role responsible for defining, evolving, and driving GoDaddy's security architecture at scale. This role operates with broad organizational influence, crafting long-term security strategy, architectural direction, and engineering standards across multiple services and platforms. As a recognized subject-matter expert, you'll address the most complex and ambiguous security challenges in hyperscale cloud environments. The role requires deep technical depth, strong architectural judgment, and the ability to influence senior engineering leaders and executives. Success is measured not only by individual technical contributions but by the security outcomes delivered across organizations through vision, mentorship, and cross-team alignment. - Lead the development of long-term AWS and hybrid cloud security architecture and strategy, ensuring alignment with organizational goals, risk posture, and expert-level enterprise networking standards (CCIE/JNCIE Security). - Architect hyperscale security solutions that balance security, availability, performance, and customer experience, supported by reference architectures, network automation frameworks, guardrails, and design patterns. - Conduct security architecture reviews and threat modeling for high-risk services, identify systemic security risks, and drive cross-organizational remediation initiatives. - Influence service roadmaps to integrate security early in the design lifecycle, champion advanced network automation frameworks, infrastructure-as-code, policy-as-code, and continuous assurance mechanisms, and lead complex incident response efforts. - Mentor engineers at all levels to raise the security bar, partner with senior leadership on priorities, and represent AWS security architecture in executive reviews and technical forums. Qualifications - 12+ years in security engineering, cloud infrastructure, or distributed systems with proven leadership of large-scale security initiatives and experience designing/securing hyperscale cloud platforms. - Deep AWS security expertise across IAM, VPC, KMS, EC2, EKS, serverless architectures, logging, monitoring, and core security domains (identity management, network segmentation, cryptography, secrets management, detection engineering). - Strong technical engineering skills including threat modeling, security architecture design, infrastructure-as-code/policy-as-code (AWS CDK, CloudFormation, Terraform), and proficiency in Python, Go, or Java. - Expert-level network security knowledge equivalent to active CCIE Security or JNCIE-SEC credentials to effectively bridge cloud-native controls with enterprise network infrastructure. - Proven ability to influence and lead across organizational boundaries without direct authority in complex, distributed environments. Requirements - This role requires overlap with US business hours for collaboration with US-based teams. You might also have... - Bachelor’s degree in Computer Science, Engineering, or a related field. - Familiarity with global security and compliance frameworks (e.g., NIST, ISO 27001, SOC, PCI) and their application at scale. Benefits - Paid time off. - Retirement savings (e.g., 401k, pension schemes). - Bonus/incentive eligibility. - Equity grants. - Participation in our employee stock purchase plan. - Competitive health benefits. - Family-friendly benefits including parental leave.

India
NTT Group logo

Cybersecurity - IAM Engineer

NTT Group

A global IT innovator founded in 1965, NTT DATA specializes in system integration and networking system services for more than a dozen industries. As an employe

Title: Cybersecurity / IAM Engineer Location: US-MD, United States Job Description: Category Other NTT DATA strives to hire exceptional, innovative and passionate individuals who want to grow with us. If you want to be part of an inclusive, adaptable, and forward-thinking organization, apply now. We are currently seeking a Cybersecurity / IAM Engineer to join our team in Bethesda (REMOTE), Maryland (US-MD), United States (US). Job Summary: The Cybersecurity / IAM Engineer is responsible for architecting, implementing, and maintaining advanced cybersecurity and identity and access management (IAM) solutions across all client environments, including cloud, IoT, edge, and data systems. This role is critical to ensuring that client meets and sustains compliance with cybersecurity, privacy, and risk management requirements, including RMF, IL4/IL5, and FedRAMP controls. The engineer leads the design and enforcement of secure authentication, authorization, and RBAC frameworks, supporting multi-factor authentication, single sign-on, and integration with providers. The Cybersecurity / IAM Engineer works closely with DevSecOps, software, and infrastructure teams to embed security best practices into all phases of the system lifecycle, including secure configuration baselines, continuous monitoring, vulnerability management, and incident response. The position requires hands-on experience with IAM platforms, PKI, secure directory services, and the implementation of audit logging and compliance reporting. The engineer maintains comprehensive documentation, supports audit and ATO processes, and ensures that all client solutions are resilient, auditable, and optimized for operational readiness and regulatory compliance. Job Duties: - Architect, implement, and maintain advanced IAM solutions, including RBAC, MFA, SSO, and integration with providers - Develop and enforce secure authentication and authorization frameworks for client's cloud, edge, and data environments - Lead the implementation of secure directory services, PKI, and certificate management for all client components - Support continuous monitoring, vulnerability management, and incident response in compliance with DoD RMF, IL4/IL5, and FedRAMP requirements - Collaborate with DevSecOps, software, and infrastructure teams to embed security best practices throughout the system lifecycle - Maintain comprehensive documentation for IAM architectures, security controls, and compliance artifacts - Support audit, ATO, and risk management processes, including evidence collection and remediation of findings - Implement and monitor audit logging, access reviews, and compliance reporting for all client environments - Provide technical support for user provisioning, deprovisioning, and lifecycle management - Participate in security assessments, code reviews, and compliance audits as required by contract and SOW Basic Qualifications: - Master's degree in Cybersecurity, Computer, Electrical, or Electronics Engineering, or Mathematics with a concentration in computer science or equivalent. - Minimum 10 years of experience with cybersecurity engineering - Must be US Citizen with ability to obtain a Secret Clearance Preferred Qualifications: - Experience designing and managing IAM solutions in regulated or mission-critical DoD environments - Proficiency with RBAC, SSO, MFA, PKI, and secure directory services - Experience with DoD RMF, IL4/IL5, and FedRAMP cybersecurity and compliance requirements - Familiarity with AWS GovCloud, cloud security, and secure integration of edge/IoT devices - Strong documentation and communication skills, including the ability to produce compliance artifacts and technical guides - Experience supporting audit, ATO, and risk management processes for federal systems - Information Assurance Management (IAM) or Information Assurance Technical (IAT) or Information Assurance System Architect and Engineer (IASAE) Level I (position-based) per DoD 8570.1M About NTT DATA</u> NTT DATA is a $30 billion business and technology services leader, serving 75% of the Fortune Global 100. We are committed to accelerating client success and positively impacting society through responsible innovation. We are one of the world's leading AI and digital infrastructure providers, with unmatched capabilities in enterprise-scale AI, cloud, security, connectivity, data centers and application services. our consulting and Industry solutions help organizations and society move confidently and sustainably into the digital future. As a Global Top Employer, we have experts in more than 50 countries. We also offer clients access to a robust ecosystem of innovation centers as well as established and start-up partners. NTT DATA is a part of NTT Group, which invests over $3 billion each year in R&D. Whenever possible, we hire locally to NTT DATA offices or client sites. This ensures we can provide timely and effective support tailored to each client&rsquo;s needs. While many positions offer remote or hybrid work options, these arrangements are subject to change based on client requirements. For employees near an NTT DATA office or client site, in-office attendance may be required for meetings or events, depending on business needs. At NTT DATA, we are committed to staying flexible and meeting the evolving needs of both our clients and employees. NTT DATA recruiters will never ask for payment or banking information and will only use @nttdata.com, @nttdatafed.com and @talent.nttdataservices.com email addresses. If you are requested to provide payment or disclose banking information, please submit a contact us form, https://us.nttdata.com/en/contact-us. NTT DATA endeavors to make https://us.nttdata.com accessible to any and all users. If you would like to contact us regarding the accessibility of our website or need assistance completing the application process, please contact us at https://us.nttdata.com/en/contact-us. This contact information is for accommodation requests only and cannot be used to inquire about the status of applications. NTT DATA is an equal opportunity employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or protected veteran status. For our EEO Policy Statement, please click here. If you'd like more information on your EEO rights under the law, please click here. For Pay Transparency information, please click here. NTT DATA provides a reasonable range of compensation for specific roles. The starting pay range for this remote role is $90,146 - $208,672. This range reflects the minimum and maximum target compensation for the position across all US locations. Actual compensation will depend on a number of factors, including the candidate&rsquo;s actual work location, relevant experience, technical skills, and other qualifications. This position may also be eligible for incentive compensation based on individual and/or company performance. If the position offered in temporary, the position will not be eligible for incentive compensation. This position is eligible for company benefits including medical, dental, and vision insurance with an employer contribution, flexible spending or health savings account, life and AD&D insurance, short and long term disability coverage, paid time off, employee assistance, participation in a 401k program with company match, and additional voluntary or legally-required benefits.

Maryland
$90.1K - $208.7K / year
Mastercard logo

Lead Program Security Engineer

Mastercard

Founded in 1966, Mastercard is a worldwide transaction, payment-processing, and consulting company best known for its line of personal and business credit cards. As an employer, Ma

Full TimeRemoteTeam 38,800Since 1966

Our Purpose Mastercard powers economies and empowers people in 200+ countries and territories worldwide. Together with our customers, we're helping build a sustainable economy where everyone can prosper. We support a wide range of digital payments choices, making transactions secure, simple, smart and accessible. Our technology and innovation, partnerships and networks combine to deliver a unique set of products and services that help people, businesses and governments realize their greatest potential. Title and Summary Lead Program Security Engineer Overview Mastercard's Business Security Enablement (BSE) team is seeking a seasoned Lead Security Engineer (L6) - Data & AI to serve as the primary security advocate and advisor for our Data Commercialization and Artificial Intelligence initiatives. The BSE team is a worldwide group of information security experts focused on helping Mastercard achieve its goals by ensuring that security is at the heart of everything we do. In this role, you will collaborate with technology, engineering, and business teams to integrate strong security practices into Mastercard's data-driven products and AI solutions. The ideal candidate possesses a high level of expertise in information security and secure engineering disciplines, enabling them to advise product and development teams on designing secure applications and services following industry best practices. You will apply deep knowledge of security principles, theories, and concepts throughout the business and development lifecycles. As an L6 Security Engineer, you are expected to take a lead security role in large, complex, global, cross-functional initiatives. You will work closely with developers and architects to evaluate business needs, determine feasibility, and recommend optimal security solutions that meet both security and regulatory requirements. Furthermore, you will champion a strong security risk culture across the organization, proactively managing risks in alignment with Mastercard's risk appetite and ensuring data and AI innovations are secure by design. Role As the L6 Data & AI Security Engineer, you will be responsible for a variety of critical security engineering and business enablement activities:• Security Partnership & Advocacy: Serve as the primary security partner for Data Commercialization and AI programs. Provide security risk guidance from discovery through deployment, and advise product, engineering, and operations teams on secure design and delivery of data-driven and AI-powered solutions.• Security Engineering Enablement: Translate Corporate Security policies, standards, and controls into actionable guidance for Data & AI teams. Partner with security champions and deliver targeted training. Maintain security dashboards/documentation and ensure requirements (secure coding, data protection, IAM controls) are embedded in the SDLC. Ensure adherence to security policy, regulatory requirements, and industry standards (e.g., PCI-DSS, privacy). • Collaboration & Leadership: Partner with Business Security Officers (BSOs) and act as a bridge between Corporate Security and Data/AI product teams. Work with engineering and architecture to improve security of code, data pipelines, cloud services, and AI solutions. Promote a security-first culture across the domain.• Security Reviews & Oversight: Lead key security governance for Data & AI work, including design/code reviews, Solution Architecture approvals, Threat Model reviews, Third-Party technology reviews, Technical Architecture Diagram approvals, Network as a Service approval, and vulnerability management support. Drive security user stories in PI Planning and ensure requirements are tracked to closure.• Innovation & Continuous Improvement: Monitor emerging threats and best practices across data analytics and AI. Partner with cross-functional teams to strengthen protection for sensitive data and ML models. Improve architectures and processes through standardization and automation of security controls and tooling. All About You The ideal candidate for the L6 Data & AI Security Engineer position will demonstrate a blend of deep technical expertise, leadership, and collaborative skills, including:• Extensive Security and Engineering Experience: Typically, 7-10 years in information security, with hands-on secure software development and secure architecture/design, including reviewing code/systems for vulnerabilities. Experience with cloud platforms, APIs, and distributed systems preferred.• Leadership and Collaboration: Proven ability to work effectively in a global environment, build strong relationships, and influence cross-functional and executive stakeholders across varying technical depth.• Security Knowledge and Technical Skills: Advanced knowledge of security principles, domains, protocols, and standards, with familiarity with ISO 27001, PCI-DSS, NIST SP 800-53, and COBIT. Strong grounding in risk management and data privacy for data analytics, digital commerce, and AI solutions, and experience designing secure, multi-domain architectures.• Cryptography Security: Strong experience with cryptography and network security, including encryption, hashing, key management, PKI/certificates, TLS/SSL, VPN, IPsec, and related protocols.• DevSecOps: Experience with DevOps/DevSecOps, including CI/CD and automated deployments, with security controls embedded throughout the SDLC.• Technical Domain Expertise: Proficiency with data technologies, analytics platforms, and AI/ML frameworks; experience securing data platforms and/or AI/ML models.• Business & Industry Acumen: Knowledge of the payments and e-commerce landscape and security considerations for data-centric and AI-powered products, including best practices for protecting data assets and algorithms and awareness of emerging threats.• Mindset and Soft Skills: Professional, proactive, and solutions-oriented, with strong problem-solving and continuous-learning mindset. Excellent communication skills to articulate security risks and mitigations to technical and business audiences, and comfort operating in a fast-paced, global environment. NICE Framework References The National Initiative for Cybersecurity Education (NICE) provides a framework of cybersecurity work roles and competencies. This Mastercard role shares knowledge, skills, and abilities (KSAs) with several NICE Framework work roles, including:• SP-DEV-002 (OPM622) - Secure Software Assessor• SP-ARC-002 (OPM652) - Security Architect• OV-SPP-002 (OPM751) - Cyber Policy and Strategy Planner Corporate Security Responsibility At Mastercard, every person working for or on behalf of the company is responsible for information security. All activities involving access to Mastercard assets, information, and networks come with an inherent risk to the organization. Therefore, it is expected that the successful candidate for this position will:• Abide by Mastercard's security policies and practices.• Ensure the confidentiality and integrity of the information being accessed.• Report any suspected information security violation or breach in a timely manner.• Complete all periodic mandatory security training courses in accordance with Mastercard's guidelines. Corporate Security Responsibility All activities involving access to Mastercard assets, information, and networks comes with an inherent risk to the organization and, therefore, it is expected that every person working for, or on behalf of, Mastercard is responsible for information security and must: - Abide by Mastercard's security policies and practices; - Ensure the confidentiality and integrity of the information being accessed; - Report any suspected information security violation or breach, and - Complete all periodic mandatory security trainings in accordance with Mastercard's guidelines.

Ireland