Job Opportunities API

The Public Ledger of Openings

← Back to the ledger

Staff Security Engineer, Privileged Access (PAM)

Nscale
CompanyNscale
CategoryEngineering
LocationAMER
RemoteOn-site (inferred)
EmploymentNot stated
LevelNot stated
SalaryNot stated by the employer
Posted27 May 2026
Last verified5 Aug 2026
SourceEmployer ATS (greenhouse)
Applications are handled by the employer, not by us.Apply on the employer's site →
Description
About Nscale Nscale is the GPU cloud engineered for AI. We provide cost-effective, high-performance infrastructure for AI start-ups and large enterprise customers. Nscale enables AI-focused companies to achieve superior results by reducing the complexity of AI development. Our GPU cloud bolsters technical capabilities and directly supports strategic business outcomes, including cost management, rapid innovation, and environmental responsibility. We thrive on a culture of relentless innovation, ownership, and accountability, where every team member takes pride in their work and drives it with excellence and urgency. As an Nscaler, you’ll build trust through openness and transparency, where everyone is inspired to do their best work. If you join our team, you’ll be contributing to building the technology that powers the future. About the Role We’re hiring a Staff Security Engineer focused on Privileged Access and Access Automation to build Nscale’s privileged access operating model across enterprise systems, SaaS administration, infrastructure, production environments, source control, data platforms, and emergency access paths. This role sits inside the identity control plane and is intentionally execution-focused. You’ll work across Identity, Endpoint, Security Data, Network Security, Platform Engineering, IT, and service owners to turn privileged access into a practical engineering mechanism with request, approval, justification, time-bound elevation, session or event evidence, automated revocation, break-glass, and clean audit trails. This role is critical because standing privilege is one of the highest-risk patterns in a fast-growing infrastructure company. Your work will help make privileged access secure, fast, measurable, and recoverable so engineers can move quickly without relying on manual reviews, tribal knowledge, or permanent admin rights. What you'll be doing Privileged Access Workflows Build privileged access workflows across enterprise SaaS admin roles, production systems, cloud consoles, infrastructure management systems, source control, data platforms, endpoint admin, and emergency access paths Design access patterns that support request, approval, justification, time-bound elevation, and automated revocation Define practical controls that reduce reliance on permanent admin rights across high-risk environments Establish clean audit trails for privileged access activity across critical systems JIT Access and Governance Controls Implement JIT access patterns with approval, justification, expiry, revocation, and evidence collection Create a privileged access baseline that defines who can approve access, what justification is required, how long access lasts, what evidence is captured, and how revocation works Own exception governance for access paths that cannot yet meet the standard Drive entitlement cleanup and stale privilege reduction through automation Break-Glass and Tiering Model Design break-glass access standards, ownership models, monitoring, and recovery procedures Test emergency access workflows and validate break-glass readiness Develop a tiering model for privileged access covering Tier 0 and Tier 1 systems, admin paths, sensitive groups, service-owner roles, and high-risk workflows Identify the top 10 highest-risk standing privileges and create remediation paths Telemetry, Detection, and Measurement Define privileged access telemetry requirements for detection, investigations, audit, compliance, and executive reporting Partner with Security Data to establish privileged access detections and source-health requirements Track metrics including standing privilege reduction, JIT adoption, stale admin cleanup, break-glass test success, approval SLA, and access review closure Build an inventory of top admin paths, owners, approvers, access methods, logging, expiry, and current risk