Staff Security Engineer, Privileged Access (PAM)

Nscale

New York (NY)

On-site

USD 175,000 - 225,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Highly competitive compensation package
Flexible paid time off
Parental leave
Retirement plan participation

Job summary

Nscale, based in New York, is looking for a Staff Security Engineer who will focus on optimizing privileged access and access automation across enterprise systems. This role involves building workflows and security patterns to reduce risks associated with standing privileges.

The ideal candidate will have over 7 years of experience in identity security and strong skills in designing automated access solutions. Nscale offers a competitive compensation package and flexible work arrangements.

Qualifications

  • 7+ years in identity security, privileged access, or security engineering roles.
  • Hands-on experience with privileged access workflows.
  • Strong understanding of authentication, authorization, and access governance.
  • Experience automating access workflows and evidence collection.

Responsibilities

  • Build privileged access workflows across various systems.
  • Implement JIT access patterns with approval and evidence collection.
  • Design break-glass access standards and validate workflows.
  • Define privileged access telemetry requirements for compliance.

Skills

Identity security
Privileged access management
Security engineering
Infrastructure security
Automation
Scripting
API integration

Job description

About Nscale

Nscale is the GPU cloud engineered for AI. We provide cost‑effective, high‑performance infrastructure for AI start‑ups and large enterprise customers. Nscale enables AI‑focused companies to achieve superior results by reducing the complexity of AI development. Our GPU cloud bolsters technical capabilities and directly supports strategic business outcomes, including cost management, rapid innovation, and environmental responsibility.

About the Role

We’re hiring a Staff Security Engineer focused on Privileged Access and Access Automation to build Nscale’s privileged access operating model across enterprise systems, SaaS administration, infrastructure, production environments, source control, data platforms, and emergency access paths.

This role sits inside the identity control plane and is intentionally execution‑focused. You’ll work across Identity, Endpoint, Security Data, Network Security, Platform Engineering, IT, and service owners to turn privileged access into a practical engineering mechanism with request, approval, justification, time‑bound elevation, session or event evidence, automated revocation, break‑glass, and clean audit trails.

This role is critical because standing privilege is one of the highest‑risk patterns in a fast‑growing infrastructure company. Your work will help make privileged access secure, fast, measurable, and recoverable so engineers can move quickly without relying on manual reviews, tribal knowledge, or permanent admin rights.

What you’ll be doing
Privileged Access Workflows
  • Build privileged access workflows across enterprise SaaS admin roles, production systems, cloud consoles, infrastructure management systems, source control, data platforms, endpoint admin, and emergency access paths
  • Design access patterns that support request, approval, justification, time‑bound elevation, and automated revocation
  • Define practical controls that reduce reliance on permanent admin rights across high‑risk environments
  • Establish clean audit trails for privileged access activity across critical systems
JIT Access and Governance Controls
  • Implement JIT access patterns with approval, justification, expiry, revocation, and evidence collection
  • Create a privileged access baseline that defines who can approve access, what justification is required, how long access lasts, what evidence is captured, and how revocation works
  • Own exception governance for access paths that cannot yet meet the standard
  • Drive entitlement cleanup and stale privilege reduction through automation
Break‑Glass and Tiering Model
  • Design break‑glass access standards, ownership models, monitoring, and recovery procedures
  • Test emergency access workflows and validate break‑glass readiness
  • Develop a tiering model for privileged access covering Tier 0 and Tier 1 systems, admin paths, sensitive groups, service‑owner roles, and high‑risk workflows
  • Identify the top 10 highest‑risk standing privileges and create remediation paths
Telemetry, Detection, and Measurement
  • Define privileged access telemetry requirements for detection, investigations, audit, compliance, and executive reporting
  • Partner with Security Data to establish privileged access detections and source‑health requirements
  • Track metrics including standing privilege reduction, JIT adoption, stale admin cleanup, break‑glass test success, approval SLA, and access review closure
  • Build an inventory of top admin paths, owners, approvers, access methods, logging, expiry, and current risk
KPIs
  • Standing privilege reduction
  • JIT adoption
  • Stale admin cleanup
  • Break‑glass test success
About You
  • 7+ years in identity security, privileged access, security engineering, infrastructure security, or related engineering roles
  • Hands‑on experience designing or operating privileged access, JIT, break‑glass, access request, approval, or access review workflows
  • Strong understanding of authentication, authorization, RBAC, SSO, MFA, access governance, admin tiering, and least privilege
  • Experience automating access workflows, entitlement cleanup, evidence collection, or revocation processes
  • Strong scripting, workflow automation, API integration, or platform engineering skills
  • Ability to translate access risk into practical controls that engineering and operations teams will adopt
  • Ability to work across enterprise systems, production environments, SaaS platforms, IT, infrastructure, and compliance stakeholders
  • Experience with service accounts, non‑human identities, workload identities, API tokens, automation accounts, or secrets governance
  • Experience securing production access, source control administration, data platforms, cloud administration, or endpoint admin workflows
  • Experience designing access evidence for audit, customer assurance, or incident response
What we can offer you
  • Highly competitive US compensation package (base + bonus + equity), with performance reviews every 12 months.
  • Join one of the fastest‑growing AI infrastructure companies — your chance to directly shape how global AI capacity is planned and deployed.
  • Expect a dynamic progression plan tailored to your ambitions. Grow by leading critical cross‑functional initiatives and shaping capital strategy — always with our full support.
  • Human‑First Flexibility: We treat you as humans first. Our flexible workplace trusts Nscalers to deliver, giving you the autonomy to shape your day around life's moments.
Equal Opportunities Statement

We strongly encourage applications from people of colour, the LGBTQ+ community, people with disabilities, neurodivergent people, parents, carers, and people from lower socio‑economic backgrounds.

If there's anything we can do to accommodate your specific situation, please let us know.

The responsibilities outlined in this job description are not exhaustive and are intended to provide a general overview of the position. The employee may be required to perform additional duties, tasks, and responsibilities as assigned by management, consistent with the skills and qualifications required for the role.

For information on how Nscale handles candidate personal data, please see our Employee & Candidate Privacy Notice: Here.

Salary Range

$175,000–$225,000 USD

Actual compensation may vary based on job‑related factors such as skill set, experience, and education. In addition to base salary, this role may be eligible for bonus, equity, and/or commission programs. Nscale may offer a competitive benefits package including medical, dental, vision, flexible paid time off, parental leave, and retirement plan participation.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Staff Software Engineer - Enterprise Security and Identity Tooling
Staff Software Engineer - Enterprise Security and Identity Tooling

Nscale • Seattle (WA)

On-site
USD 200,000 - 250,000
Competitive US compensation package
Human-First Flexibility
Medical, dental, vision benefits
Security Response Engineer, Cyber Defense
Security Response Engineer, Cyber Defense

Nscale • Seattle (WA)

On-site
USD 100,000 - 130,000
Base + bonus + equity
Equity
Flexible paid time off
+2
Staff Engineer, Endpoint Security
Staff Engineer, Endpoint Security

Nscale • New York (NY)

On-site
USD 175,000 - 225,000
Competitive compensation package
Flexible paid time off
Parental leave
+1
Staff Security Engineer, Threat Intelligence
Staff Security Engineer, Threat Intelligence

Nscale • Seattle (WA)

On-site
USD 180,000 - 260,000
Highly competitive compensation package
Flexible workplace
Medical, dental, and vision benefits
+2
Data Center Construction Security Program Manager
Data Center Construction Security Program Manager

Nscale • Seattle (WA)

On-site
USD 175,000 - 225,000
Highly competitive compensation package
Performance reviews every 12 months
Flexible workplace
Infrastructure Operations Engineer Greensboro, NC
Infrastructure Operations Engineer Greensboro, NC

Nscale • Winston-Salem (NC)

Hybrid
USD 100,000 - 160,000
Competitive package (base + equity)
Flexible workplace and support for personal growth
Medical, dental, and vision benefits
Manager, Security Operations
Manager, Security Operations

Nscale • Seattle (WA)

On-site
USD 120,000 - 160,000
Competitive salary
Performance reviews every 12 months
Flexible workplace
Data Center Physical Security Manager (NC) Greensboro, NC
Data Center Physical Security Manager (NC) Greensboro, NC

Nscale • Greensboro (NC)

On-site
USD 90,000 - 130,000
Medical, dental, vision
Flexible paid time off
Parental leave
+1
Physical Security Engineer (US)
Physical Security Engineer (US)

Socket.dev • Houston (TX)

On-site
USD 150,000 - 175,000
Competitive salary package
Equity and bonus opportunities
Flexible paid time off
+2
Security Incident Response Lead
Security Incident Response Lead

Nscale • Seattle (WA)

On-site
USD 150,000 - 225,000