Empleo
Mis anuncios
Mis alertas
Conectarse
Encontrar un trabajo Consejos empleo Fichas empresas
Buscar

Staff security engineer, privileged access (pam)

Amer (Provincia de La Rioja)
Nscale
Publicada el 7 junio
Descripción

Staff Security Engineer, Privileged Access (PAM)
AMER

About Nscale
Nscale is the GPU cloud engineered for AI. We provide cost‐effective, high‐performance infrastructure for AI start‐ups and large enterprise customers. Nscale enables AI‐focused companies to achieve superior results by reducing the complexity of AI development. Our GPU cloud bolsters technical capabilities and directly supports strategic business outcomes, including cost management, rapid innovation, and environmental responsibility.

We thrive on a culture of relentless innovation, ownership, and accountability, where every team member takes pride in their work and drives it with excellence and urgency. As an Nscaler, you'll build trust through openness and transparency, where everyone is inspired to do their best work. If you join our team, you'll be contributing to building the technology that powers the future.

About the Role
We're hiring a Staff Security Engineer focused on Privileged Access and Access Automation to build Nscale's privileged access operating model across enterprise systems, SaaS administration, infrastructure, production environments, source control, data platforms, and emergency access paths.

This role sits inside the identity control plane and is intentionally execution‐focused. You'll work across Identity, Endpoint, Security Data, Network Security, Platform Engineering, IT, and service owners to turn privileged access into a practical engineering mechanism with request, approval, justification, time‐bound elevation, session or event evidence, automated revocation, break‐glass, and clean audit trails.

This role is critical because standing privilege is one of the highest‐risk patterns in a fast‐growing infrastructure company. Your work will help make privileged access secure, fast, measurable, and recoverable so engineers can move quickly without relying on manual reviews, tribal knowledge, or permanent admin rights.

What you'll be doing
Privileged Access Workflows

Build privileged access workflows across enterprise SaaS admin roles, production systems, cloud consoles, infrastructure management systems, source control, data platforms, endpoint admin, and emergency access paths

Design access patterns that support request, approval, justification, time‐bound elevation, and automated revocation

Define practical controls that reduce reliance on permanent admin rights across high‐risk environments

Establish clean audit trails for privileged access activity across critical systems

JIT Access and Governance Controls

Implement JIT access patterns with approval, justification, expiry, revocation, and evidence collection

Create a privileged access baseline that defines who can approve access, what justification is required, how long access lasts, what evidence is captured, and how revocation works

Own exception governance for access paths that cannot yet meet the standard

Drive entitlement cleanup and stale privilege reduction through automation

Break‐Glass and Tiering Model

Design break‐glass access standards, ownership models, monitoring, and recovery procedures

Test emergency access workflows and validate break‐glass readiness

Develop a tiering model for privileged access covering Tier 0 and Tier 1 systems, admin paths, sensitive groups, service‐owner roles, and high‐risk workflows

Identify the top 10 highest‐risk standing privileges and create remediation paths

Telemetry, Detection, and Measurement

Define privileged access telemetry requirements for detection, investigations, audit, compliance, and executive reporting

Partner with Security Data to establish privileged access detections and source‐health requirements

Track metrics including standing privilege reduction, JIT adoption, stale admin cleanup, break‐glass test success, approval SLA, and access review closure

Build an inventory of top admin paths, owners, approvers, access methods, logging, expiry, and current risk

KPIs

Break‐glass test success

About You

7+ years in identity security, privileged access, security engineering, infrastructure security, or related engineering roles

Hands‐on experience designing or operating privileged access, JIT, break‐glass, access request, approval, or access review workflows

Strong understanding of authentication, authorization, RBAC, SSO, MFA, access governance, admin tiering, and least privilege

Experience automating access workflows, entitlement cleanup, evidence collection, or revocation processes

Strong scripting, workflow automation, API integration, or platform engineering skills

Ability to translate access risk into practical controls that engineering and operations teams will adopt

Ability to work across enterprise systems, production environments, SaaS platforms, IT, infrastructure, and compliance stakeholders

Experience with service accounts, non‐human identities, workload identities, API tokens, automation accounts, or secrets governance

Experience securing production access, source control administration, data platforms, cloud administration, or endpoint admin workflows

Experience designing access evidence for audit, customer assurance, or incident response

What we can offer you
At Nscale, you'll find a collaborative, supportive, and innovative environment where your contributions spark real impact. We're building something extraordinary, and we want you at the core.

Highly competitive US compensation package (base + bonus + equity), with performance reviews every 12 months.

Join one of the fastest‐growing AI infrastructure companies — your chance to directly shape how global AI capacity is planned and deployed.

Expect a dynamic progression plan tailored to your ambitions. Grow by leading critical cross‐functional initiatives and shaping capital strategy — always with our full support.

Human‐First Flexibility: We treat you as humans first. Our flexible workplace trusts Nscalers to deliver, giving you the autonomy to shape your day around life's moments.

We strongly encourage applications from people of colour, the LGBTQ+ community, people with disabilities, neurodivergent people, parents, carers, and people from lower socio‐economic backgrounds.

If there's anything we can do to accommodate your specific situation, please let us know.

The responsibilities outlined in this job description are not exhaustive and are intended to provide a general overview of the position. The employee may be required to perform additional duties, tasks, and responsibilities as assigned by management, consistent with the skills and qualifications required for the role.

For information on how Nscale handles candidate personal data, please see our Employee & Candidate Privacy Notice.

Salary Range
The range below reflects the base salary for the position. Actual compensation may vary based on job‐related factors such as skill set, experience, education, and location. In addition to base salary, this role may be eligible for bonus, equity, and/or commission programs. Nscale may offer a competitive benefits package including medical, dental, vision, flexible paid time off, parental leave, and retirement plan participation.

$175,000 - $225,000 USD

#J-18808-Ljbffr

Enviar
Crear una alerta
Alerta activada
Guardada
Guardar
Ofertas cercanas
Empleo Amer (Provincia de La Rioja)
Empleo Provincia de La Rioja
Empleo La Rioja
Inicio > Empleo > Staff Security Engineer, Privileged Access (PAM)

Jobijoba

  • Dosieres empleo
  • Opiniones Empresas

Encuentra empleo

  • Ofertas de empleo por profesiones
  • Búsqueda de empleo por sector
  • Empleos por empresas
  • Empleos para localidad

Contacto/ Colaboraciones

  • Contacto
  • Publiquen sus ofertas en Jobijoba

Menciones legales - Condiciones legales y términos de Uso - Política de Privacidad - Gestionar mis cookies - Accesibilidad: No conforme

© 2026 Jobijoba - Todos los Derechos Reservados

Enviar
Crear una alerta
Alerta activada
Guardada
Guardar