About the Role
We are hiring Security Analysts to run the daily security operations work that keeps Nscale protected. This is a hands-on analyst role, one level below Staff, working across alert triage, incident investigation, escalation, evidence collection, response coordination, vulnerability follow-up, and operational reporting. The role connects closely with Incident Response, Cyber Defence, Enterprise Security, IT, Platform Engineering, identity, endpoint, vulnerability management, network security, GRC, and platform teams. Security operations is where controls become real. This role helps ensure security events are investigated consistently, incidents are escalated quickly, and daily operational risks do not get lost in the noise. The right person will be curious, calm under pressure, technically practical, and comfortable working across endpoint, identity, SaaS, cloud, network, and production access signals.
Responsibilities
- Triage daily security alerts across endpoint, identity, SaaS, cloud, network, email, and infrastructure telemetry.
- Investigate suspicious activity, including user behavior, device activity, login events, access changes, exposed assets, and potential data leakage.
- Separate signal from noise and make clear judgments on when to keep investigating, when to escalate, and when to ask for help.
- Escalate confirmed or high-risk events to Incident Response, Cyber Defence, Enterprise Security, IT, Platform Engineering, or other owners.
- Execute documented response actions such as host isolation requests, account review, access disablement recommendations, malicious domain blocking requests, evidence capture, and case routing.
- Build incident timelines, collect evidence, and write clear handoff notes.
- Support post-incident reviews, including missed opportunities in prevention, detection, response, and remediation.
- Produce daily and weekly operational reporting covering alert volumes, true positives, escalations, open cases, recurring issues, and response SLAs.
- Improve runbooks, investigation guides, alert tuning feedback, and automation opportunities.
- Identify recurring false positives, missing context, or weak handoff points and propose fixes.
- Follow up on vulnerabilities and exposures where daily operations identifies active risk, missing ownership, or overdue remediation.
Requirements
- 3+ years in security operations, incident response, threat monitoring, SOC analysis, detection triage, cloud security operations, or related roles.
- Experience investigating alerts from endpoint, identity, SaaS, cloud, email, network, or application telemetry.
- Understanding of common attacker techniques such as phishing, credential theft, suspicious login behavior, malware execution, command and control, privilege misuse, data exfiltration, and cloud misconfiguration.
- Ability to write clear investigation notes, timelines, case summaries, and escalation handoffs.
- Familiarity with incident response basics: severity, containment, eradication, recovery, evidence handling, and post-incident review.
- Comfort using query languages, logs, dashboards, case management systems, or security analytics tools.
- Strong judgment on when to keep investigating, when to escalate, and when to ask for help.
- Ability to work calmly during high-pressure security events.
- Experience in a high-growth technology, cloud, infrastructure, AI, regulated, or customer-trust-sensitive environment is a plus.
- Experience improving runbooks, automating repetitive tasks, reducing alert noise, threat hunting, MITRE ATT&CK, detection logic, or incident readiness exercises is a plus.
Skills
- Endpoint telemetry
- Identity telemetry
- SaaS telemetry
- Cloud telemetry
- Network telemetry
- Email telemetry
- Infrastructure telemetry
- Query languages
- Logs
- Dashboards
- Case management systems
- Security analytics tools
- MITRE ATT&CK
Experience Level
- 3+ years
Salary/Compensations
- $100,000—$130,000 USD
Benefits
- Medical
- Dental
- Vision
- Flexible paid time off
- Parental leave
- Retirement plan participation
About the Company
- Nscale is the GPU cloud engineered for AI. We provide cost-effective, high-performance infrastructure for AI start-ups and large enterprise customers. Nscale enables AI-focused companies to achieve superior results by reducing the complexity of AI development. Our GPU cloud bolsters technical capabilities and directly supports strategic business outcomes, including cost management, rapid innovation, and environmental responsibility.
- We thrive on a culture of relentless innovation, ownership, and accountability, where every team member takes pride in their work and drives it with excellence and urgency. As an Nscaler, you’ll build trust through openness and transparency, where everyone is inspired to do their best work. If you join our team, you’ll be contributing to building the technology that powers the future.
Equal Opportunity
- We strongly encourage applications from people of colour, the LGBTQ+ community, people with disabilities, neurodivergent people, parents, carers, and people from lower socio-economic backgrounds.
- If there’s anything we can do to accommodate your specific situation, please let us know.
