Staff Engineer, Endpoint Security

Nscale

New York (NY)

On-site

USD 175,000 - 225,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Competitive compensation package
Flexible paid time off
Parental leave
Retirement plan participation

Job summary

Nscale, based in New York, is hiring a Staff Security Engineer to focus on Endpoint and Device Security. You'll build the security foundation for employees, ensuring secure, reliable configurations across various devices.

The ideal candidate will have over 7 years in endpoint security, with experience on multiple operating systems and a knack for balancing security with user experience. Nscale offers a competitive compensation package and values employee flexibility.

Qualifications

  • 7+ years in endpoint security or related roles.
  • Hands-on experience securing Windows, macOS, and Linux endpoints.
  • Ability to balance strong endpoint controls with user experience.

Responsibilities

  • Own endpoint and device security architecture.
  • Establish device posture requirements for enterprise access.
  • Drive local admin reduction and controlled elevation patterns.

Skills

Endpoint security
Device management
Scripting
OS hardening
Browser security
Endpoint telemetry
Security engineering

Job description

About Nscale

Nscale is the GPU cloud engineered for AI. We provide cost‑effective, high‑performance infrastructure for AI start‑ups and large enterprise customers. Nscale enables AI‑focused companies to achieve superior results by reducing the complexity of AI development. Our GPU cloud bolsters technical capabilities and directly supports strategic business outcomes, including cost management, rapid innovation, and environmental responsibility.

We thrive on a culture of relentless innovation, ownership, and accountability, where every team member takes pride in their work and drives it with excellence and urgency. As an Nscaler, you'll build trust through openness and transparency, where everyone is inspired to do their best work. If you join our team, you'll be contributing to building the technology that powers the future.

About the Role

We're hiring a Staff Security Engineer focused on Endpoint and Device Security to build and operate the endpoint and device security foundation for Nscale employees, engineers, data center staff, and privileged operators.

This is a hands‑on engineering role centered on turning endpoint security from a collection of tools and policies into a measurable operating model. You'll work across employee laptops and workstations, engineering endpoints, privileged admin devices, and site‑support devices, partnering closely with IT, Identity, Infrastructure, Security Operations, Legal, Privacy, and business stakeholders to design controls that are secure, reliable, and workable in practice.

This role is critical because endpoint and device security is one of the fastest ways to reduce enterprise risk without slowing the business down. Your work will drive stronger managed‑device coverage, hardened baselines, local admin reduction, healthier telemetry, and clearer evidence that device risk is going down across the organization.

What you'll be doing
Architecture & Standards
  • Own endpoint and device security architecture across employee devices, engineering workstations, privileged admin devices, and site‑support endpoints.
  • Define secure baseline standards for operating systems, browsers, disk encryption, host firewalls, endpoint telemetry, and configuration hardening.
  • Develop practical device standards for remote workers, office users, data center staff, contractors, and high‑risk user populations.
Access & Security Integration
  • Establish device posture requirements for access to enterprise applications, production systems, privileged workflows, and sensitive data.
  • Integrate endpoint posture with identity, privileged access, vulnerability management, and detection workflows.
  • Partner with Identity and Privileged Access teams to support high‑risk application and production access decisions.
Privilege Reduction & Endpoint Operations
  • Drive local admin reduction and controlled elevation patterns that reduce risk without creating operational dead ends.
  • Lead endpoint rollout readiness, including deployment sequencing, exception handling, user communication, rollback planning, and adoption metrics.
  • Create an exception model with clear ownership, risk documentation, compensating controls, expiry, and review cadence.
Telemetry, Evidence & Reporting
  • Define endpoint telemetry requirements to support investigations, detection engineering, audit evidence, and executive reporting.
  • Build visibility into device security posture through dashboards covering coverage, stale devices, unmanaged endpoints, local admin status, and telemetry health.
  • Measure progress through metrics such as coverage, unmanaged devices, local admin reduction, hardening compliance, and endpoint detection health.
KPIs
  • Managed device coverage
  • Reduction in stale and unmanaged endpoints
  • Local admin reduction
  • Hardening compliance and endpoint detection health
About You
  • 7+ years in endpoint security, device management, enterprise security engineering, infrastructure security, or related engineering roles
  • Hands‑on experience securing Windows, macOS, and/or Linux endpoints in enterprise environments
  • Experience with device management, endpoint detection, OS hardening, disk encryption, browser security, host firewalls, and endpoint telemetry
  • Experience reducing standing local admin privileges or implementing controlled elevation models
  • Strong scripting, automation, packaging, configuration, or endpoint workflow engineering skills
  • Ability to balance strong endpoint controls with user experience, operational reliability, and business velocity
  • Experience partnering with IT, identity, infrastructure, security operations, legal, privacy, and business stakeholders
  • Experience securing high‑risk engineering populations, data center support teams, privileged administrators, or remote‑first workforces
  • Experience using device posture in conditional access, privileged access, or production access decisions
  • Experience producing audit‑ready evidence for device controls and endpoint security posture
What we can offer you
  • Highly competitive US compensation package (base + bonus + equity), with performance reviews every 12 months.
  • Join one of the fastest‑growing AI infrastructure companies — your chance to directly shape how global AI capacity is planned and deployed.
  • Expect a dynamic progression plan tailored to your ambitions. Grow by leading critical cross‑functional initiatives and shaping capital strategy — always with our full support.
  • Human‑First Flexibility: We treat you as humans first. Our flexible workplace trusts Nscalers to deliver, giving you the autonomy to shape your day around life's moments.
Equal Opportunities Statement

We strongly encourage applications from people of colour, the LGBTQ+ community, people with disabilities, neurodivergent people, parents, carers, and people from lower socio-economic backgrounds.

If there's anything we can do to accommodate your specific situation, please let us know.

Employee & Candidate Privacy Notice

For information on how Nscale handles candidate personal data, please see our Employee & Candidate Privacy Notice: Here.

Salary Range

$175,000—$225,000 USD

Nscale may offer a competitive benefits package including medical, dental, vision, flexible paid time off, parental leave, and retirement plan participation.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Endpoint Engineer
Endpoint Engineer

Nscale • Houston (TX)

Hybrid
USD 160,000 - 190,000
Endpoint Engineer
Endpoint Engineer

Nscale • Seattle (WA)

On-site
USD 160,000 - 190,000
Equity
Bonus
Medical benefits
Security Response Engineer, Cyber Defense
Security Response Engineer, Cyber Defense

Nscale • Seattle (WA)

On-site
USD 100,000 - 130,000
Base + bonus + equity
Equity
Flexible paid time off
+2
Staff Security Engineer, Privileged Access (PAM)
Staff Security Engineer, Privileged Access (PAM)

Nscale • New York (NY)

On-site
USD 175,000 - 225,000
Highly competitive compensation package
Flexible paid time off
Parental leave
+1
Staff Software Engineer - Enterprise Security and Identity Tooling
Staff Software Engineer - Enterprise Security and Identity Tooling

Nscale • Seattle (WA)

On-site
USD 200,000 - 250,000
Competitive US compensation package
Human-First Flexibility
Medical, dental, vision benefits
Staff Security Engineer, Threat Intelligence
Staff Security Engineer, Threat Intelligence

Nscale • Seattle (WA)

On-site
Highly competitive compensation package
Flexible workplace
Medical, dental, and vision benefits
+2
Manager, Security Operations
Manager, Security Operations

Nscale • Seattle (WA)

On-site
USD 120,000 - 160,000
Competitive salary
Performance reviews every 12 months
Flexible workplace
Infrastructure Operations Engineer Greensboro, NC
Infrastructure Operations Engineer Greensboro, NC

Nscale • Winston-Salem (NC)

Hybrid
USD 100,000 - 160,000
Competitive package (base + equity)
Flexible workplace and support for personal growth
Medical, dental, and vision benefits
Security Construction Manager
Security Construction Manager

Nscale • Barstow (TX)

On-site
USD 160,000 - 200,000
Base + equity
Flexible workplace
Career growth
Data Center Construction Security Program Manager
Data Center Construction Security Program Manager

Nscale • Seattle (WA)

On-site
USD 175,000 - 225,000
Highly competitive compensation package
Performance reviews every 12 months
Flexible workplace