Senior Staff Security Engineer, Incident Response

Nscale is a London-based, full-stack AI cloud and infrastructure company that provides GPU compute, managed AI services, orchestration software, data centers, and power infrastructure for AI training, fine-tuning, and inference.

Series CRecently funded0 current maintainers0 active leadsTeam intelligence

Maintainer signals as of 9/23/2026

London, United Kingdom
About Nscale

Nscale builds and operates vertically integrated AI infrastructure spanning software, GPU compute, networking, storage, purpose-built data centers, and power. Its active cloud platform offers self-service inference endpoints, fine-tuning, managed Kubernetes and Slurm, virtual machines, and GPU clusters.

View jobs by Nscale

Skills

Candidate Availability

Required and preferred rules are kept separate and reflect the wording in the original posting.

About the Role

You will serve as the technical incident commander for high-severity cyber incidents. You will lead investigations, containment, eradication, recovery validation, and post-incident improvements. You will also build tested response automation and playbooks, translate adversary findings into durable controls, mentor responders, and participate in the on-call rotation.

Requirements

  • 10+ years of experience in incident response, security engineering, offensive security, detection engineering, vulnerability management, or a related technical security role
  • Experience leading technical responses to complex high-severity incidents in cloud-scale, hybrid, or globally distributed environments
  • Knowledge of attacker behaviour, including credential theft, privilege escalation, persistence, lateral movement, command and control, defence evasion, data exfiltration, and destructive activity
  • Experience investigating Linux and Windows hosts, cloud environments, identity systems, network activity, and security telemetry
  • Ability to establish incident scope and make containment decisions from incomplete or conflicting evidence
  • Strong software engineering or scripting ability and experience building security tooling, integrations, or automation
  • Experience translating offensive findings, incidents, or vulnerability intelligence into detections, controls, remediation mechanisms, and validation tests
  • Ability to lead cross-functional remediation and communicate technical conclusions, uncertainty, and trade-offs

Responsibilities

  • Lead technical responses to high-severity incidents across enterprise, cloud, product, production, data centre, and operational technology environments
  • Set investigation hypotheses, direct workstreams, reconstruct attack paths, and establish incident scope
  • Develop and validate containment, eradication, credential invalidation, recovery, and heightened-monitoring actions
  • Conduct investigations across Linux and Windows hosts, cloud control planes, identity systems, networks, applications, and containers
  • Lead post-incident technical reviews and drive permanent engineering improvements
  • Build version-controlled and observable response-engineering capabilities
  • Automate evidence collection, correlation, timeline generation, blast-radius analysis, remediation tracking, and response recommendations
  • Create executable playbooks for identity compromise, ransomware, data exfiltration, supply-chain compromise, and production compromise
  • Turn offensive findings and threat intelligence into detections, controls, response actions, and regression tests
  • Lead remediation campaigns and technical readiness exercises
  • Define safe AI-assisted response workflows with approval, auditability, rollback, and emergency-stop controls
  • Mentor responders and participate in the incident-response on-call rotation

Benefits

  • Medical insurance
  • Dental insurance
  • Vision insurance
  • Flexible paid time off
  • Parental leave
  • Retirement plan participation