Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Security Response Engineer, Cyber Defense

$100k - $130k
Full-time

Nscale

About Nscale

Nscale is building the infrastructure platform for the AI era. We provide cost-effective, high-performance infrastructure for AI start-ups and large enterprise customers, reducing the complexity of AI development and helping customers manage cost, innovate rapidly, and operate responsibly.

We thrive on a culture of relentless innovation, ownership, and accountability, where every team member takes pride in their work and drives it with excellence and urgency. As an Nscaler, you’ll build trust through openness and transparency, where everyone is inspired to do their best work. If you join our team, you’ll be contributing to building the technology that powers the future.

About the Role

We are hiring Security Response Engineers to own what happens after an alert becomes real, across enterprise, cloud, production, data centre, and operational technology environments.

Agents and a managed security service provider (MSP) hold the level 1 queue. You take escalations, decide fast, act, and then make sure the same class of problem does not come back. Half the job is response. The other half is turning what you learned into engineering work that permanently retires the issue.

If you have spent years closing the same ticket every Tuesday—and knowing exactly how to fix it for good, but never having the mandate—this is the job where that is the mandate.

How this function works

Read this section carefully. It is not a standard SOC, and the difference is the whole point.

  • You do not watch a queue. An in-house security agent and a contracted managed provider hold level 0 and level 1 around the clock. Work reaches you as an escalation with context already attached.
  • Every escalation forks three ways: act, solve, or both. Act is the immediate containment. Solve is the engineering artifact you hand to the build teams so that alert class does not fire again. Most escalations are both.
  • Your primary metric is the share of escalations permanently solved. Not tickets closed, and not mean time to close. If the same alert fires twice, we got it wrong the first time.
  • Two classes, not five. We sort everything into risk indicator or actionable, using the SSVC model. If you have drowned in a five-tier severity scheme nobody trusted, you will like this.
  • Follow-the-sun across hubs. Nobody works permanent nights.

What you'll be doing

Escalation response

  • Take escalations from the agent and managed provider, scope them against real asset and business context, decide, and act.
  • Execute approved containment, including isolating devices, revoking sessions, restricting access, blocking activity, and preserving evidence.
  • Know what you can do immediately, what requires authority, and what could disrupt production if handled incorrectly.

The solve

  • Ensure every escalation exits with an engineering artifact where one is warranted: a detection requirement, telemetry gap with a business case, control change, automation, or regression test.
  • Specify the artifact clearly enough that the team building it can act without a second conversation. You do not build it; you make the required outcome unambiguous.

Investigation and evidence

  • Build timelines from primary evidence across identity, endpoint, email, SaaS, cloud, network, production, and increasingly operational technology and building management systems, which are currently dark to us.
  • Close every case with a security disposition, an owner, the evidence, actions taken, and any required follow-up.

Detection judgement

  • Review candidate detections auto-authored by our research loop as shadow rules and assess their inside-out coverage.
  • Make the human judgement on whether shadow detections should be promoted to live. You do not write the detection logic, but nothing goes live without your call.

Provider quality

  • Reconcile the managed provider’s case work, which lives in their platform rather than ours, against our standards.
  • Hold the provider accountable for evidence, analysis, routing, and closure quality.

Readiness

  • Contribute to threat hunts, incident reviews, tabletop exercises, recovery tests, the on-call rotation, and keeping runbooks honest.

First 90 days

  • Independently own escalations across common classes, with defensible dispositions and evidence that stands up.
  • Ship your first solve: an engineering artifact that permanently retires a recurring alert class.
  • Learn the incident command, escalation, evidence, and handover model, and take a rotation slot.
  • Review the managed provider’s case quality against our standard and raise the first reconciliation findings.
  • Judge and promote your first shadow detections to live.
  • Take part in a threat hunt, tabletop, or recovery exercise.
  • Name one telemetry gap with a business case behind it. Extra credit if it is in operational technology or building management systems, both of which we currently cannot see.

KPIs

  • Share of escalations permanently solved
  • Quality and defensibility of security dispositions and evidence
  • Containment judgement and response effectiveness
  • Quality and actionability of engineering artifacts
  • Managed provider quality and reconciliation

About You

  • 5+ years in security operations, incident response, threat detection, threat hunting, security engineering, or related roles.
  • Hands-on investigation experience across endpoint, identity, cloud, SaaS, network, or production telemetry, with the ability to build a timeline from primary evidence rather than a vendor summary.
  • Fluency in modern attacker tradecraft, including credential theft, session abuse, phishing, malware execution, persistence, privilege escalation, lateral movement, command and control, and exfiltration.
  • You automate what you repeat, using query languages, scripting, APIs, or workflow automation. When you hit the same problem a third time, your instinct is to build—not add another step to a runbook.
  • Sound judgement on containment under time pressure, including knowing where your authority ends.
  • You write investigations another engineer can follow, escalations a leader can act on in thirty seconds, and case notes that still make sense to someone reading them two years later in an audit.
  • Calm and methodical when facts are incomplete or contradict each other.
  • Willingness to challenge automated conclusions. AI-generated analysis is an input, not an authority; we expect you to validate it and notice when it is confidently wrong.
  • Ability to work effectively with engineering, infrastructure, and service owners who do not report to you.

Strong pluses

  • Operational technology, industrial control systems, building management systems, or critical facilities experience. We have a known gap here and will weight it heavily.
  • Cloud infrastructure, AI infrastructure, data centres, HPC, or other availability-sensitive environments.
  • Response experience involving ransomware, identity compromise, destructive attacks, cloud intrusion, insider threats, or supply-chain incidents.
  • Experience holding a managed monitoring or response provider to a standard while keeping decisions in-house.
  • Detection testing, shadow-rule validation, threat hunting, or forensic readiness.
  • Follow-the-sun, shift-based, or on-call operations.
  • Certifications are useful, but not required.

How we will assess

  • An investigation, end to end. Signal to evidence to scope to containment to disposition. We are listening for what you decided independently, what you escalated, and why.
  • The solve. This is the most important answer in the process. Describe a recurring problem you permanently retired: the artifact, who built it, and how you proved it worked.
  • Automation instinct. Tell us about recurring toil you inherited and whether you reached for a tool, a person, or a build.
  • Judging a machine. Describe a time an alert, vendor, or model was confidently wrong and how you caught it.
  • Writing. We may ask for a redacted investigation write-up or escalation note.

Where this leads

Response Engineers here develop the sharpest picture in the company of where the estate actually breaks. They are strong internal candidates for detection engineering, platform security, and identity roles as those pillars grow. We would rather grow our next engineers here than hire them all in.

This role may not be a fit if you:

  • Want a queue to work through. There is not one.
  • Measure success in tickets closed.
  • Close cases without a security disposition or evidence.
  • Forward vendor alerts without validating them.
  • Want to write detections full time. That role is real and well funded here, but it sits in another pillar; we would rather point you towards it than mis-hire you into this one.

What we can offer you

At Nscale, you'll find a collaborative, supportive, and innovative environment where your contributions spark real impact. We're building something extraordinary, and we want you at the core.

Highly competitive US compensation package (base + bonus + equity), with performance reviews every 12 months.

Join one of the fastest-growing AI infrastructure companies—your chance to directly shape how global AI capacity is planned and deployed. ✨

Expect a dynamic progression plan tailored to your ambitions. Grow by leading critical cross-functional initiatives and shaping capital strategy—always with our full support.

Human-First Flexibility: We treat you as humans first. Our flexible workplace trusts Nscalers to deliver, giving you the autonomy to shape your day around life's moments.

Equal Opportunities Statement

We strongly encourage applications from people of colour, the LGBTQ+ community, people with disabilities, neurodivergent people, parents, carers, and people from lower socio-economic backgrounds.

If there’s anything we can do to accommodate your specific situation, please let us know.

The responsibilities outlined in this job description are not exhaustive and are intended to provide a general overview of the position. The employee may be required to perform additional duties, tasks, and responsibilities as assigned by management, consistent with the skills and qualifications required for the role.

For information on how Nscale handles candidate personal data, please see our Employee & Candidate Privacy Notice: Here.

Salary Range

The range below reflects the base salary for the position. Actual compensation may vary based on job-related factors such as skill set, experience, education, and location. In addition to base salary, this role may be eligible for bonus, equity, and/or commission programs. Nscale may offer a competitive benefits package including medical, dental, vision, flexible paid time off, parental leave, and retirement plan participation.

The range below reflects the base salary for the position. Actual compensation may vary based on job-related factors such as skill set, experience, education, and location. In addition to base salary, this role may be eligible for bonus, equity, and/or commission programs. Nscale may offer a competitive benefits package including medical, dental, vision, flexible paid time off, parental leave, and retirement plan participation.

Salary Range

$100,000—$130,000 USD

For information on how Nscale handles candidate personal data, please see our Employee & Candidate Privacy Notice: Here.

Nscale does not accept unsolicited candidate submissions from recruitment agencies.

Vacancy posted 2 days ago
Similar jobs that could be interesting for youBased on the Security Response Engineer, Cyber Defense in San Francisco, CA vacancy
  • $141.6k - $212.4k

     ...their own destiny.Klaviyo is looking for a Senior Security Engineer to add to our growing Detection and Response (D&R) Team. This is a hands-on technical role that...  ...based detections as codeRespond to security alerts, cyber threats, and security incidents Drive end-to-end... 
    Cyber

    Klaviyo

    San Francisco, CA
    4 days ago
  • $141.6k - $212.4k

     ...their own destiny.Klaviyo is looking for a Senior Security Engineer to add to our growing Detection & Response Team. This is an engineering role that spans the full...  ...-based detections-as-code Detect and respond to cyber threats using security data lake, SIEM, and cloud... 
    Cyber

    Klaviyo

    San Francisco, CA
    1 day ago
  •  ...The RoleWe are looking for a hands-on Senior Detection and Response Security Engineer to be a critical force in driving Rippling's security program...  ...advanced detection rules to protect against emerging cyber threats.Process and Technology Enhancement: Drive continuous... 
    Cyber
    Full time
    Work at office
    Relocation
    3 days per week
    1 day per week

    Rippling

    San Francisco, CA
    18 hours ago
  • $175k - $220k

     ...looking for a highly technical Senior Security Engineer who thrives on building security capabilities...  ..., Detection engineering, Incident response, access governance, and security operations...  ...or Masters in Computer Science, Cyber Security or similar roles.Strong software... 
    Cyber
    Full time
    Work at office

    Sigma Computing

    San Francisco, CA
    3 days ago
  •  ...Solutions, DXC modernises, secures, and operates some of the world...  ...will be doingDXC Managed Cyber Services (MCS) is the specialist...  ...are enhancing the Security Engineering Team who work within the...  ...security improvement programs. Responsibilities: To facilitate the... 
    Cyber
    Full time
    Local area

    DXC Technology

    Brisbane, CA
    4 days ago
  • $168.75k - $200k

     ...DescriptionIt all started when engineer Fred Luddy wrote code...  ...an organization’s cyber risk exposure in real...  ...with ServiceNow’s Security and Risk capabilities,...  ...of its kind autonomous defense platform for the Agentic...  ...sales cycles. Responsibilities Partner with Sales to... 
    Cyber
    Work at office
    Immediate start
    Remote work
    Flexible hours

    Moveworks

    San Francisco, CA
    1 day ago
  • $190k - $225k

    Senior Security Engineer Location: San Francisco,CA (onsite) Full Time Job Description: We are...  ..., detection engineering, incident response, access governance, and security operations...  ...or Masters in Computer Science, Cyber Security or similar roles. Strong software... 
    Cyber
    Full time

    Winmax Systems

    San Francisco, CA
    3 days ago
  •  ...Time, 35 hours/week, fully onsite The Physical Security Systems Engineer is a technical operations role responsible for the day-to-day operation, troubleshooting, deployment...  ...and keep critical systems protected from cyber security risks, backed up and redundant for... 
    Cyber
    Full time
    Remote work
    Flexible hours

    Sfmoma

    San Francisco, CA
    1 day ago
  • $208k - $312k

     ...help builders move from idea to production with speed, security, and exceptional developer experience.Now, software is...  ...comes next.About the Role:We are looking for a Security Engineer to join our Detection Response team. In this role, you will be responsible for managing... 
    Work at office
    Remote work
    Work from home
    Worldwide
    Monday to Friday
    Flexible hours
    Shift work

    Vercel

    San Francisco, CA
    2 days ago
  • $230k - $260k

     ....We’re looking for a hands-on Detection Engineer to build and operate the systems and workflows...  ...powers them, participate in incident response, and help shape how detection and...  ...work closely with Engineering, Corporate Security, and Infrastructure, with broad latitude... 
    Local area

    Notion Labs

    San Francisco, CA
    18 hours ago
  • $230k - $390k

     ...design teams for Google Workspace. Security EngineerSecurity Engineering builds the foundations that let Sierra...  ..., identity, and detection and response. You’ll work across all layers of our...  ...strengthen architectures, and build durable defenses.Own Cross-Cutting Systems.Partner... 
    Full time
    Flexible hours

    Sierra

    San Francisco, CA
    18 hours ago
  • $159.3k - $202.4k

     ...interview process.About the RoleTwitch is looking for a Security Incident Response Engineer to join our SIRT. Reporting to the SIRT Manager, you'll...  ...issues in information security who are ready to level up our defense. If you're passionate about protecting the Twitch... 
    Flexible hours

    Twitch

    San Francisco, CA
    18 hours ago
  • $10 per hour

     ...What you'll doThere is no MSSP and no tier-1 queue here. Detection & Response engineers own their detections end to end: you write them, you tune them, and your team is paged when they fire. The security team is spread across the globe with a follow-the-sun pager... 
    Work at office
    Local area
    Immediate start
    Relocation
    Relocation package
    Flexible hours

    Flexport

    San Francisco, CA
    1 day ago
  • $266k - $385k

     ...artificial general intelligence benefits all of humanity.The Security team protects OpenAI’s technology, people, and products....  ...a robust security culture.About the RoleAs a Security Engineer on Detection & Response, you’ll help protect OpenAI’s most sensitive assets- including... 
    Work at office
    Local area
    Remote work
    Flexible hours

    OpenAI

    San Francisco, CA
    18 hours ago
  •  ...is a next-generation Cloud Security Platform that leverages runtime...  ...to malware defense, Upwind ensures end-to-end,...  ...are looking for a Security Engineer to join our MDR team as the...  ...the U.S. presence scales. Responsibilities Assist in fine-tuning Upwind... 
    Night shift
    Weekend work

    Upwind Security

    San Francisco, CA
    3 days ago
  • $68k - $133.9k

    Position Summary Cyber Oracle Cloud Security - Analyst / Security Engineer I Deloitte’s Cyber team helps organizations address complex cybersecurity challenges...  ...the Cyber Enterprise Security team, you will be responsible for supporting Oracle Cloud security and controls... 
    Cyber
    Local area
    Visa sponsorship

    Deloitte

    San Francisco, CA
    2 days ago
  • $275k - $300k

     ...About the TeamThe Information Security organization at Postman...  ...the adversary to ensure our defenses hold up under real-world pressure...  ...Principal Offensive Security Engineer who is as much a strategist as...  ...measurable improvements in detection, response, and architecture.About... 
    Full time
    Work at office
    Flexible hours
    3 days per week

    Postman

    San Francisco, CA
    1 day ago
  •  ...encouraged and everyone is a stakeholder.What you'll be responsible for:The Circle Security Team works to protect Circle; our customers, clients,...  ...years of experience in detection, response, or security engineering.3+ years of experience commanding security incidents, especially... 
    Contract work
    Work experience placement
    Flexible hours
    Shift work
    Night shift

    Circle

    San Francisco, CA
    4 days ago
  • $132k - $240k

     ...of work with AI. About the role Join WRITER's security team as a staff detection and response engineer and help protect the AI infrastructure that's...  ...Security Engineering, and AI researchers to build a defense-in-depth strategy that protects one of the most valuable... 
    Full time
    Work at office
    Local area
    Flexible hours

    WRITER

    San Francisco, CA
    1 day ago
  • $186.9k - $267.7k

     ...cybersecurity, platform and systems engineering. We are driven by a shared...  ...to shape the future of cyber defense, and eager to work alongside...  ...build systems that combine security-relevant data, detection signals...  ...triage, investigation, and response. Alternatively, former Tier... 
    Cyber
    Full time
    Temporary work
    Local area
    Immediate start
    Flexible hours

    CISCO Systems

    San Francisco, CA
    4 days ago
  • $188.75k - $242.68k

     ...Raleigh, London, and Amsterdam.The Platform Security team (PlatSec) defends Plaid against...  ...cloud security, AI security, detection and response, and red teaming. Right now we're in...  ...the roleYou'll be Plaid's first line of defense on AI security. You'll review new AI technologies... 
    Work experience placement
    Work at office
    Local area

    Plaid Financial

    San Francisco, CA
    2 days ago
  • $155k - $400k

     ...native future. About The Role The Security Team is responsible for securing all things Sentry: our...  ...security problems with creativity and an engineering mindset. We work at a company with a...  ...prioritizes preventative controls, defense in depth, and high signal alerting... 
    Hourly pay

    Sentry

    San Francisco, CA
    3 days ago
  •  ...change that, apply below. About the role We are looking for a Security Engineer to help build and strengthen security foundations from the...  ...startup environment, with a primary focus on detection and response. This is a strong opportunity for someone early in their... 
    Work at office
    Immediate start
    Remote work
    Flexible hours
    Shift work

    Assort Health

    San Francisco, CA
    2 days ago
  • $145k - $210k

    Senior Cyber Security EngineerCooley is seeking a Senior Cyber Security Engineer to join the Security team.Position summary: Cooley Technology embraces a culture...  ...importance to the technical or operational responsibilities outlined later in this document. The Cyber Security... 
    Cyber
    Full time
    Temporary work
    Work at office
    Flexible hours
    Weekend work

    Cooley

    San Francisco, CA
    18 hours ago
  • $134.5k - $265.1k

     ...Summary Our Deloitte Cyber team understands the unique challenges...  ..., and proactively manage to secure success.Recruiting for this...  ...Consulting, you will be responsible for delivering high-quality...  ...deep technical ownership with engineering expertise, governance, and stakeholder... 
    Cyber
    Local area
    Visa sponsorship

    Deloitte

    San Francisco, CA
    4 days ago
  •  ...next-generation Cloud Security Platform that leverages...  ...to malware defense, Upwind ensures end-to...  ...skilled Technical Support Engineer to lead the charge in...  ...with our customers. Responsibilities Provide accurate and...  ...degree in Engineering / Cyber Security, or an equivalent... 
    Cyber

    Upwind Security

    San Francisco, CA
    4 days ago
  • $124k - $280k

     ...Job Description & Summary The Opportunity As a Security Risk & Engineering - Tech and Cyber Risk & Compliance - Senior Manager, you will play a...  ...reinforce professional and technical standards. Responsibilities - Leading the development and implementation of compliance... 
    Cyber
    Full time
    H1b

    PwC

    San Francisco, CA
    1 day ago
  • $140k - $200k

     ...law firm, seeks an attorney to join its Defense Litigation practice group in San Francisco...  ..., personal and advertising injury, cyber liability, and excess liability.Position...  ...join a team that offers a high level of responsibility in an exciting, growing practice. Our firm... 
    Cyber
    Work at office
    Remote work

    Hinshaw & Culbertson

    San Francisco, CA
    18 hours ago
  • $80k - $105k

     ...critical organizations. We build security compliance software...  ...primarily the aerospace and defense industry. At Atomus we are hardworking...  ...Role As a Cybersecurity Engineer will work closely with...  ...experiences for our customers. Responsibilities Manage and guide new... 
    Cyber
    Full time

    Atomus Limited

    San Francisco, CA
    1 day ago
  • $122.7k - $187.8k

     ...accenture.com . You Are As a Security Sales Senior Manager, you...  ...the primary focus and the engine driving regional expansion....  ...Security offerings across Cyber Defense , Cloud Security, Identity...  ...upon sales closure. Key Responsibilities Originate & Close Deals:... 
    Cyber
    Contract work
    Work experience placement
    Live in
    Work at office
    Local area
    Worldwide

    Accenture

    San Francisco, CA
    2 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Security Response Engineer, Cyber Defense. Be the first to apply!