Senior Staff Security Engineer, Incident Response

nscaleoperationsukltd

Houston (TX)

On-site

USD 150,000 - 210,000

Full time

5 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Nscale is seeking a Senior Staff Security Engineer, Incident Response to lead the technical response to our most serious cyber incidents and build capabilities that make future responses faster, safer and more decisive. This hands-on role sits in Cyber Defence and reports to the Director of Cyber Defence.

You will coordinate investigations across Linux and Windows hosts, cloud control planes, identity systems and networks, craft containment strategies, and translate lessons from incidents into

Qualifications

  • 10+ years in incident response or related security roles.
  • Led technical response to complex, high-severity incidents.
  • Experience across cloud, on-prem, and hybrid environments.
  • Deep knowledge of attacker behavior and security telemetry.

Responsibilities

  • Lead the technical response to high-severity incidents across enterprise, identity, endpoint, cloud, and infrastructure.
  • Develop a response engineering roadmap with automation and version-controlled playbooks.
  • Create executable playbooks for cloud control-plane, ransomware and data exfiltration scenarios.
  • Mentor incident responders and coordinate cross-functional teams.
  • Drive post-incident reviews and permanent engineering improvements.

Skills

Incident response
Security engineering
Offensive security
Detection engineering
Vulnerability management

Job description

About Nscale

Nscale is the GPU cloud engineered for AI. We provide cost-effective, high-performance infrastructure for AI start-ups and large enterprise customers. Nscale enables AI-focused companies to achieve superior results by reducing the complexity of AI development. Our GPU cloud bolsters technical capabilities and directly supports strategic business outcomes, including cost management, rapid innovation, and environmental responsibility.

We thrive on a culture of relentless innovation, ownership, and accountability, where every team member takes pride in their work and drives it with excellence and urgency. As an Nscaler, you'll build trust through openness and transparency, where everyone is inspired to do their best work. If you join our team, you'll be contributing to building the technology that powers the future.

About the Role

We are hiring a Senior Staff Security Engineer, Incident Response to lead the technical response to Nscale's most serious cyber incidents and build the capabilities that make future responses faster, safer and more decisive.

This hands‑on senior individual contributor role sits in Cyber Defence and reports to the Director of Cyber Defence. You will work across Security Operations, Detection and Security Data Engineering, Product, Platform, Identity, Enterprise and Infrastructure teams, and Offensive Security.

During a major incident, you will be the technical incident commander, setting the investigation strategy, directing technical workstreams and providing the evidence leaders need to make decisions. Between incidents, you will turn lessons from incidents and offensive testing into durable defensive capability, including safe AI‑assisted and agentic response workflows.

What you'll be doing
Technical incident command

Lead the technical response to high‑severity incidents across enterprise, identity, endpoint, cloud, product, production, data centre and operational technology environments.

Set investigation hypotheses and evidence priorities; direct workstreams; reconstructattackpaths; analysepersistenceandrootcause;andestablishcredible scope.

Develop technical options and success criteria for containment, eradication, credential and session invalidation, recovery validation and heightened monitoring.

Conduct hands‑on investigations across Linux and Windows hosts, cloud control planes, identity systems, networks, applications and containers.

Leadpost‑incident technical reviews that result in permanent engineering improvements.

Response engineering

Build a response‑engineering roadmap that turns recurring manual investigation and containment work into tested, version‑controlled and observable capabilities.

Automate evidence collection, enrichment, correlation, timeline generation, blast‑radius analysis, asset and owner attribution, remediation tracking and response recommendations.

Create executable playbooks for identity compromise, cloud control‑plane intrusion, destructive attacks and ransomware, insider threat, supply‑chain compromise, data exfiltration and production compromise.

Adversary‑informed defence

Turn red‑team findings, incident evidence and threat intelligence into detections, preventive controls, response actions and regression tests.

Drive remediation campaigns for vulnerabilities and attack paths that span engineering organisations, with clear ownership, measurable closure and executive visibility where needed.

Run technical readiness exercises that test Nscale's ability to detect, investigate, contain and recover from realistic attacks before they reach production.

Agentic response and team development

Define safe AI‑assisted and agentic response workflows with scoped access, human approval for consequential actions, evidence provenance, output validation, auditability, rollback and emergency‑stop controls.

Mentor incident responders, SOC analysts, security engineers and service owners in adversary behaviour, investigation methods and technical decision‑making.

Participate in the incident‑response on‑call rotation.

KPIs

Time to credible scope

Time to contain and eradicate

Share of investigative and response steps safely automated

Closure of post‑incident engineering actions

About You

You have 10+ years in incident response, security engineering, offensive security, detection engineering, vulnerability management or a closely related technical security role.

You have led the technical response to complex, high‑severity incidents in cloud‑scale, hybrid or globally distributed environments.

You understand attacker behavior including credential and session theft, privilege escalation, persistence, lateral movement, command and control, defence evasion, data exfiltration and destructive activity.

You have investigated Linux and Windows hosts, cloud environments, identity systems, network activity and related security telemetry.

You can establish incident scope and make sound containment decisions from incomplete

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Incident Response Engineer — Technical Incident Commander
Senior Incident Response Engineer — Technical Incident Commander

nscaleoperationsukltd • Houston (TX)

On-site
USD 150,000 - 210,000
Security Response Engineer, Cyber Defense
Security Response Engineer, Cyber Defense

Nscale • Seattle (WA)

On-site
USD 100,000 - 130,000
Base + bonus + equity
Equity
Flexible paid time off
+2
Security Analyst (Security Operations)
Security Analyst (Security Operations)

Socket.dev • Houston (TX)

On-site
USD 100,000 - 130,000
Staff Security Engineer, Product & Platform Security
Staff Security Engineer, Product & Platform Security

Socket.dev • Houston (TX), Northern (KY)

Hybrid
USD 190,000 - 230,000
Equity
Flexible work
Staff Security Engineer, Product & Platform Security
Staff Security Engineer, Product & Platform Security

Nscale • New York (NY), San Francisco (CA), Seattle (WA)

On-site
USD 190,000 - 230,000
Equity
Flexible work policy
Comprehensive benefits
Data Center Physical Security Manager (NC)
Data Center Physical Security Manager (NC)

Nscale • Greensboro (NC)

On-site
USD 90,000 - 130,000
Sr. Staff Security Engineer, Platform Security
Sr. Staff Security Engineer, Platform Security

Socket.dev • Houston (TX)

On-site
USD 210,000 - 250,000
Competitive salary + equity
Bonus + equity programs
Flexible workplace
Data Center Physical Security Engineer (US)
Data Center Physical Security Engineer (US)

Nscale • Houston (TX)

On-site
USD 110,000 - 150,000
Staff Security Engineer, Product & Platform Security New Houston; New York; San Francisco; Seattle
Staff Security Engineer, Product & Platform Security New Houston; New York; San Francisco; Seattle

Nscale • New York (NY), Northern (KY)

Hybrid
USD 190,000 - 240,000
Equity
Bonus
Medical benefits
+2
Incident Response Lead - AI-Driven Detection & Containment
Incident Response Lead - AI-Driven Detection & Containment

Career Techniques • Dallas (TX)

Hybrid
USD 130,000 - 170,000