About the role
Nscale is hiring a Director of Identity to lead the engineering function accountable for authentication, authorisation, and identity propagation across the platform - for humans, agents, and workloads . Identity sits on the critical path of every API call and every Console, SDK, or CLI action: when we are slow, the platform is slow; when we are wrong, we create significant security and reputational risk.
This is a high impact role with scope across Product, Platform, Infrastructure, SRE, and Security. You will set direction, hire and grow a high-performing team, and own end-to-end outcomes: a secure sign-in experience, consistent and auditable access control, and a paved road that makes secure patterns the default.
You'll operate as a player-coach: technically deep enough to make high-leverage architectural calls, and organisationally strong enough to align stakeholders and ship iteratively without compromising correctness.
What you'll work on
- Authentication & federation: login/session flows, token issuance and exchange, key management, identity verification, and enterprise federation (SSO, SCIM, group/role sync, outbound federation).
- Authorisation & policy: RBAC/ABAC models, policy definition and enforcement, permission resolution services, and scalable guardrails.
- Propagation & workload identity: standardised identity headers/claims, service-to-service identity, workload identity, and secure delegation patterns.
- Paved roads: shared libraries, SDKs, middleware, docs, and compatibility contracts that make secure patterns the default.
- Operational trust: reliability/latency discipline, safe incremental releases, incident response, observability, and auditability/evidence generation.
Responsibilities
- Mission outcomes. Own the end-to-end identity experience and security posture across the platform, and the feedback loops that drive the roadmap.
- Org leadership & operating model. Set the multi-year Identity strategy, organisational design, and delivery approach; accountable for org-wide delivery, budget, and headcount. Hire and develop engineers and managers, build a leadership bench, and create the structure that enables the function to scale.
- Platform coherency. Establish standards and patterns for identity usage across all services and product surfaces, reducing bespoke integrations and inconsistent permission models - with proactive detection to ensure adherence.
- Security-by-default. Make the secure path the easy path: opinionated primitives, strong defaults, and guardrails that prevent classes of mistakes.
- Reliability & performance. Hold a high bar for correctness, availability, and latency on the systems that gate every request. Ensure rollout safety and fast recovery.
- Cross-functional alignment. Represent Identity in architectural and roadmap conversations with Product, Platform, Infrastructure, SRE, and Security - resolving trade-offs and ensuring decisions stick when you are not in the room.
- Industry awareness. Stay abreast of identity, security, and cloud industry direction - and translate relevant shifts (standards, vendor roadmaps, regulatory changes, and threats) into pragmatic platform improvements.
- Metrics & accountability. Define and track the KPIs that matter: authentication success rate, authz decision latency, incident rate/MTTR, adoption of shared libraries, policy coverage, and access review hygiene.
- Sovereignty & key custody. Ensure our identity and key-management posture supports sovereignty requirements (where needed), with clear controls and evidence for where keys and trust roots are held and operated.
Requirements
- Senior technical leadership. Staff+ / Principal engineering background (or equivalent), with the ability to challenge designs across distributed systems, security boundaries, and the full stack.
- Track record leading teams. Experience hiring, leading, and developing engineering teams with strong delivery and operational standards.
- Identity domain expertise. Deep experience with authentication and authorisation systems (e.g., OAuth 2.0/OIDC, RBAC/ABAC, token exchange, JWT/JWKS, policy engines such as OPA/Cedar, Zanzibar-style patterns).
- Distributed systems & cloud fluency. Hands-on experience designing, building, and operating scalable production systems for or on a major cloud provider (AWS/GCP/Azure), including day-2 operations.
- Critical-path discipline. Comfort working on systems with large blast radius - rollback plans, incremental delivery, and correctness guarantees - while preserving release momentum and navigating one-way-door decisions when they arise.
- Communication and influence. Ability to work with Security, Product, and Engineering leadership, extract signal from design partner conversations, and translate it into measurable de