About the Role
Scale AI is seeking an International Head of Security to own and unify the company's security strategy across its non-US affairs, focusing on Global Public Sector and non-US Enterprise deals. This role involves driving execution, customer engagements, and compliance with international frameworks while aligning with global security architecture. The ideal candidate is a builder who views security as a product feature and can enhance both defensive maturity and ambition in frontier AI security.
Responsibilities
- Execute the Global Security Strategy Across International Markets
- Drive execution of Scale's multi-year secure-by-default roadmap across non-US markets, surfacing regional needs into global architecture decisions.
- Translate regional regulatory requirements (GDPR, ISO 27001/27018, SOC 2, UK Cyber Essentials Plus, EU AI Act, NIS2, and country-specific data residency / sovereign-cloud rules) into concrete engineering controls.
- Track regional security metrics and accountability, and represent the international perspective in global prioritisation, audits, and roadmap reviews.
- Lead Regional Security Engineering & Threat Detection
- Own the regional execution of identity, fine-grained RBAC, secrets management, CI/CD hardening, encryption, logging, and infrastructure protection with a particular focus on cross-border data flows and in-region telemetry.
- Stand up high-fidelity detection and response capabilities that meet local time zone coverage, breach-notification timelines, and regulator expectations.
- Drive systemic risk reduction through platform-level controls, partnering with the global security engineering team rather than building parallel stacks.
- Secure Products, Data, and AI Systems for International Customers
- Ensure enterprise-grade protection of customer data, proprietary datasets, and AI assets across regional deployments, including support for in-region processing, encryption with customer-managed keys, and data-localisation commitments.
- Design and enforce robust multi-tenant isolation, fine-grained RBAC, and privilege lifecycle management across customer environments serving international enterprises and public sector buyers.
- Address AI-specific attack surfaces; prompt injection, tool abuse in agentic workflows, data exfiltration, and model/data integrity risks.
- Champion secure SDLC practices, threat modeling, and code review standards within FDE teams.
- Lead Insider Risk & Contributor Integrity Across International Populations
- Partner with Product and Operations to reduce fraud, account compromise, collusion, and identity-based abuse without degrading platform usability, particularly in higher-risk regions.
- Implement strong auditability, privilege governance, and behavioural anomaly detection across sensitive workflows in a way that is defensible to international regulators.
- Be the Lead Security Partner for International Customers & Governments
- Serve as the lead security partner in international enterprise and public sector engagements; running customer security reviews, supporting regulator interactions, and shaping trust narratives across the UK, EU, MENA, and beyond.
- Drive execution of the international clearable-infrastructure plan without fragmenting the core platform.
- Partner with Sales, Legal, and Compliance to streamline security reviews and build durable customer confidence.
Requirements
- 8+ years in cybersecurity (security engineering, product security, detection/response, or cloud security), with at least 4 years leading or formally mentoring engineers in high-growth or enterprise environments.
- Demonstrated experience building and scaling security programs that materially improved risk posture.
- Strong technical depth in cloud-native security (AWS / GCP / Azure), IAM / Zero Trust, infrastructure security, logging and monitoring, and secure SDLC practices.
- Hands-on familiarity with GDPR, ISO 27001, SOC 2, UK Cyber Essentials Plus, NIS2, and the EU AI Act.
- Experience managing insider risk or securing environments with significant third-party, contractor, or marketplace-style user populations.
- Ability to operate cross-functionally with Engineering, Product, Legal, Compliance, Sales, and Public Sector stakeholders.
- Right to work in the UK.
- Comfortable traveling regularly.
- Willing to be vetted for country-specific clearances where customer engagements require it.
Skills
- Cloud-native security (AWS / GCP / Azure)
- IAM / Zero Trust
- Infrastructure security
- Logging and monitoring
- Secure SDLC practices
- GDPR
- ISO 27001
- SOC 2
- UK Cyber Essentials Plus
- NIS2
- EU AI Act
- Insider risk management
- AI / ML platforms security
- LLM-based systems security
- Agentic applications security
- AI-specific threat vectors (training data poisoning, prompt injection, tool/plugin abuse, model IP protection)
- Enterprise SaaS security
- Government or national security customer environments
- GCC sovereign compliance and privacy regulations
- Multi-tenant systems security
- Red-teaming
- Adversarial testing
- Offense-informed defense programs
Location
- UK
Work Type
- Full-time
Experience Level
- 8+ years in cybersecurity
- 4+ years leading or formally mentoring engineers
About the Company
- Scale AI develops reliable AI systems for the world's most important decisions, providing high-quality data and full-stack technologies for leading AI models and enterprise/government AI applications.
- The company works with industry leaders like Meta, Ernst & Young, Mayo Clinic, Time Inc., the Government of Qatar, and U.S. government agencies.
- Scale is expanding its team to accelerate AI application development.
Equal Opportunity
- Scale believes everyone should be able to bring their whole selves to work and is a proud inclusive and equal opportunity workplace.
- Committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability status, gender identity or Veteran status.
- Committed to working with and providing reasonable accommodations to applicants with physical and mental disabilities.
- Complies with the United States Department of Labor's Pay Transparency provision.
