Job Opportunities API

The Public Ledger of Openings

← Back to the ledger

Security Incident Response Lead

Nscale
CompanyNscale
CategoryUncategorised
LocationUS
RemoteOn-site (inferred)
EmploymentNot stated
LevelNot stated
SalaryNot stated by the employer
Posted27 Mar 2026
Last verified6 Aug 2026
SourceEmployer ATS (greenhouse)
Applications are handled by the employer, not by us.Apply on the employer's site →
Description
About Nscale Nscale is the GPU cloud engineered for AI. We provide cost-effective, high-performance infrastructure for AI start-ups and large enterprise customers. Nscale enables AI-focused companies to achieve superior results by reducing the complexity of AI development. Our GPU cloud bolsters technical capabilities and directly supports strategic business outcomes, including cost management, rapid innovation, and environmental responsibility. We thrive on a culture of relentless innovation, ownership, and accountability, where every team member takes pride in their work and drives it with excellence and urgency. As an Nscaler, you’ll build trust through openness and transparency, where everyone is inspired to do their best work. If you join our team, you’ll be contributing to building the technology that powers the future. About the Role We’re hiring a Security Incident Response Lead to own and evolve Nscale’s incident response capability in a high-scale, AI-native environment . This is a hands-on leadership role focused on leading investigations across infrastructure, enterprise systems, and security events, while driving effective containment, eradication, and recovery. The role operates at the center of incident coordination and partners closely with Detection & Response as well as cross-functional stakeholders including Infrastructure, IT, Legal, and Compliance . You will help shape how Nscale detects and responds to threats by building the processes, tooling, and operational rigor behind the incident response function. This role is critical to strengthening the organization’s security posture and ensuring high-severity events are managed with speed, clarity, and technical depth. This role will be part of the global CISO organization. What you'll be doing Incident Leadership & Coordination Lead end-to-end security incident response across the organization Act as the incident commander for high-severity events Coordinate cross-functional response efforts with Infrastructure, IT, Legal, and Compliance Participate in and help design on-call and escalation rotations Investigations & Forensics Conduct and oversee investigations across endpoints, cloud, and infrastructure systems Apply digital forensics techniques across logs, endpoints, and cloud environments Drive containment, eradication, and recovery efforts for active security incidents Contribute to threat hunting and proactive investigations Process, Playbooks & Operational Rigor Develop and maintain incident response playbooks and runbooks Establish escalation frameworks to support effective incident handling Lead post-incident reviews and root cause analysis efforts Drive long-term remediation actions following incidents Tooling & Response Improvement Partner with Detection & Response teams to improve alerting, triage, and response workflows Build and scale incident response tooling and automation Enhance case management systems that support investigation and response operations KPIs End-to-end security incident response effectiveness High-severity incident coordination and command Post-incident review and remediation completion Incident response tooling, automation, and workflow maturity About You 8–12+ years of experience in incident response, security operations, or digital forensics Proven experience leading complex, high-severity incident investigations in cloud or distributed environments Strong expertise in forensics and investigation techniques across endpoints, cloud, and logs Hands-on experience with SIEM , EDR/XDR , and detection tooling Familiarity with cloud infrastructure and modern production environments Deep understanding of attack techniques, threat actors, and incident lifecycles Ability to oper