Security Response Engineer Cyber Defense
Nscale is a London-based, full-stack AI cloud and infrastructure company that provides GPU compute, managed AI services, orchestration software, data centers, and power infrastructure for AI training, fine-tuning, and inference.
Funding history
About Nscale
Nscale builds and operates vertically integrated AI infrastructure spanning software, GPU compute, networking, storage, purpose-built data centers, and power. Its active cloud platform offers self-service inference endpoints, fine-tuning, managed Kubernetes and Slurm, virtual machines, and GPU clusters.
Skills
About the Role
You will investigate escalated security incidents, make containment decisions, preserve evidence, and document defensible dispositions. You will turn recurring incident classes into actionable engineering artifacts, assess shadow detections, evaluate provider quality, and contribute to readiness activities.
Requirements
- 5+ years in security operations, incident response, threat detection, threat hunting, security engineering, or related roles
- Hands-on investigation experience across endpoint, identity, cloud, SaaS, network, or production telemetry
- Knowledge of credential theft, session abuse, phishing, malware, persistence, privilege escalation, lateral movement, command and control, and exfiltration
- Experience using query languages, scripting, APIs, or workflow automation
- Sound containment judgement under time pressure
- Ability to write clear investigations, escalations, and case notes
- Ability to validate automated analysis and challenge incorrect conclusions
- Ability to work with engineering, infrastructure, and service owners
- Operational technology, industrial control systems, building management systems, cloud infrastructure, AI infrastructure, data centers, or HPC experience is preferred
- Experience with ransomware, cloud intrusion, insider threats, supply-chain incidents, detection testing, threat hunting, forensic readiness, or managed response providers is preferred
Responsibilities
- Investigate escalations using asset and business context
- Execute approved containment actions and preserve evidence
- Produce detection requirements, telemetry gap cases, control changes, automation, or regression tests for recurring issues
- Build timelines from identity, endpoint, email, SaaS, cloud, network, production, operational technology, and building-management evidence
- Close cases with security dispositions, owners, evidence, actions, and follow-up
- Assess shadow detections and approve promotion to live detections
- Reconcile managed-provider case work against response standards
- Contribute to threat hunts, incident reviews, tabletop exercises, recovery tests, on-call rotations, and runbook updates
Benefits
- Bonus
- Equity
- Medical insurance
- Dental insurance
- Vision insurance
- Flexible paid time off
- Parental leave
- Retirement plan participation
- Flexible work arrangements
Hiring Process
Investigation assessment; recurring-problem solution discussion; automation discussion; machine-judgement discussion; possible redacted investigation write-up or escalation note.
