Senior Staff Security Engineer — Product & Platform Security

Nscale

New York, San Francisco, Seattle (NY, CA, WA)

On-site

USD 190,000 - 230,000

Full time

13 days ago
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Equity
Flexible work policy
Comprehensive benefits

Job summary

Nscale is seeking a Staff Security Engineer for Product & Platform Security in the US. You will lead security reviews across products, cloud platforms, and infrastructure, partner with engineering to identify risks, and drive remediation. Responsibilities include threat modeling, secure design guidance, and scaling bug bounty programs.

Strong collaboration with cross‑functional teams is essential. The role emphasizes vulnerability management, incident response, and program measurement, with a

Qualifications

  • 10+ years of information security experience in product or cloud security.
  • Strong threat modeling and security design review skills.
  • Experience with vulnerability management and incident response.
  • Experience with bug bounty programs and coordinated disclosure.
  • Excellent communication and cross-functional collaboration.

Responsibilities

  • Lead security reviews across products, cloud platforms, APIs, hyperscale GPU clusters, and supporting infrastructure.
  • Partner with engineering teams throughout the development lifecycle to identify security risks and define practical remediation plans.
  • Conduct threat modeling and architecture reviews for new products, features, services, and platform changes.
  • Provide guidance on secure design, coding practices, authentication, data protection, and infrastructure security.
  • Help develop reusable security standards, patterns, and guardrails that enable teams to build and deploy securely at scale.
  • Receive, analyze, and validate vulnerability findings from internal testing, security tooling, external researchers, and other sources.
  • Coordinate with engineering, platform, and infrastructure teams to reproduce, validate, and remediate findings.
  • Create clear remediation roadmaps and track progress toward resolution.
  • Identify recurring vulnerability patterns and work with engineering teams to address systemic risks and technical debt.
  • Design, launch, and scale Nscale’s bug bounty and vulnerability disclosure programs across platforms such as HackerOne, Bugcrowd, or equivalent.
  • Establish clear scope definitions, reward guidelines, and submission processes that encourage high-quality vulnerability disclosures.
  • Build trusted relationships with security researchers and the broader security community.
  • Manage researcher communications, triage workflows, and resolution timelines with professionalism and transparency.
  • Act as the primary liaison between external researchers and internal security and engineering teams during vulnerability disclosure.
  • Support incident classification and escalation workflows when vulnerabilities or security issues are discovered in production environments.
  • Coordinate responsible disclosure timelines and remediation activities with affected stakeholders.
  • Contribute to root‑cause analysis and process improvements following vulnerability discovery or security incidents.
  • Document findings, remediation steps, and lessons learned to improve product and platform security practices.
  • Maintain detailed records of findings and resolutions for audit and compliance purposes.
  • Track and report on product and platform security KPIs, including vulnerability trends, remediation timelines, recurrence, and researcher engagement.
  • Analyze patterns in vulnerability types to identify systemic risks, control gaps, and technical debt.
  • Provide regular insights to leadership on security risks, emerging threats, researcher feedback, and program effectiveness.
  • Recommend enhancements to security controls, testing coverage, program scope, and remediation processes based on data.
  • Benchmark Nscale’s product and platform security practices against industry peers in cloud infrastructure and AI/GPU platforms.
  • Monitor emerging vulnerabilities, attack vectors, and security trends relevant to cloud platforms, GPU infrastructure, Kubernetes, containers, and AI systems.
  • Share findings with security, product, platform, and engineering teams to inform prevention and detection strategies.
  • Support security awareness and training initiatives by communicating lessons learned from vulnerabilities and incidents.
  • Promote security ownership across engineering teams through practical guidance, collaboration, and knowledge sharing.

Skills

Threat modeling
Security architecture
Vulnerability assessment
Secure coding practices
Incident response
Bug bounty programs
Kubernetes security
Cloud security (AWS/GCP/Azure)
Risk quantification

Tools

Vulnerability scanners
SIEM
EDR
GRC systems

Job description

Nscale is seeking a Staff Security Engineer for Product & Platform Security in the US. You will lead security reviews across products, cloud platforms, and infrastructure, partner with engineering to identify risks, and drive remediation. Responsibilities include threat modeling, secure design guidance, and scaling bug bounty programs.

Strong collaboration with cross‑functional teams is essential. The role emphasizes vulnerability management, incident response, and program measurement, with a

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Engineer — Product & Platform Defense
Senior Security Engineer — Product & Platform Defense

Socket.dev • Houston (TX), Northern (KY)

Hybrid
USD 190,000 - 230,000
Equity
Flexible work
Staff Security Engineer — Secure Platform & Cloud
Staff Security Engineer — Secure Platform & Cloud

Beyond Finance • United States

On-site
USD 160,000 - 195,000
Health, dental, and vision program
Generous PTO and paid holidays
401(k) matching program
+2
Staff Security Engineer, Product & Platform Security
Staff Security Engineer, Product & Platform Security

Socket.dev • Houston (TX), Northern (KY)

Hybrid
USD 190,000 - 230,000
Equity
Flexible work
Senior Staff Security Engineer - Product Platform
Senior Staff Security Engineer - Product Platform

Peregrine Technologies • San Francisco (CA)

Hybrid
USD 200,000 - 275,000
Staff Security Engineer, Product & Platform Security
Staff Security Engineer, Product & Platform Security

Nscale • New York (NY), San Francisco (CA), Seattle (WA)

On-site
USD 190,000 - 230,000
Equity
Flexible work policy
Comprehensive benefits
Staff Security Engineer, Product & Platform Security New Houston; New York; San Francisco; Seattle
Staff Security Engineer, Product & Platform Security New Houston; New York; San Francisco; Seattle

Nscale • New York (NY), Northern (KY)

Hybrid
USD 190,000 - 240,000
Equity
Bonus
Medical benefits
+2
Product Security Engineer Remote - US
Product Security Engineer Remote - US

Secure State.IQ • United States

Remote
USD 120,000 - 180,000
Senior Platform Security Engineer - Cloud & AWS
Senior Platform Security Engineer - Cloud & AWS

Early Warning • San Francisco (CA)

Hybrid
USD 158,000 - 198,000
Healthcare Coverage
401(k) Retirement Plan
Paid Time Off
+2
Founding Platform Security Engineer, GPUs & IaaS
Founding Platform Security Engineer, GPUs & IaaS

Socket.dev • Houston (TX)

On-site
USD 210,000 - 250,000
Competitive salary + equity
Bonus + equity programs
Flexible workplace
Senior Platform Security Engineer
Senior Platform Security Engineer

NMC2 • Dallas (TX), Northern (KY)

Hybrid
USD 150,000 - 230,000