> Markdown version of [/jobs/ext/2730262-security-engineer-product-platform-security](https://www.wearedevelopers.com/jobs/ext/2730262-security-engineer-product-platform-security). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer, Product & Platform Security - **Company:** NuScale Power Corporation - **Location:** New York, United States - **Experience:** Expert - **Salary:** $190,000.0 - $230,000.0 - **Contract:** Permanent contract - **Skills:** Clean Code Principles, Kubernetes Security, Application Programming Interfaces (APIs), Artificial Intelligence, Amazon Web Services, Software System Penetration Testing, User Authentication, Microsoft Azure, Cloud Computing, Cloud Computing Security, Computer Clusters, Code Coverage, Cyber Security, Identity and Access Management, Secure Coding, Security Information and Event Management, Software Vulnerability Management, Cloud Platform System, Software Security, Technical Debt, Cyber Threat Analysis, HybridCloud, Kubernetes, Hardware Infrastructure, Vulnerability Analysis - **Published:** September 5, 2026 - **Apply:** https://startup.jobs/staff-security-engineer-product-platform-security-nscale-9914526 ## About the Role * 10+ years of experience in information security, including substantial hands-on experience in product security, application security, platform security, or vulnerability management. * Deep technical expertise in threat modeling, security architecture, vulnerability assessment, and secure coding practices. * Experience partnering with software, platform, and infrastructure engineering teams to embed security throughout the development lifecycle. * Strong understanding of CVSS scoring, vulnerability prioritization, and risk quantification. * Proficiency with vulnerability scanners, application security tooling, SIEM platforms, EDR tools, and GRC systems. * Experience with responsible disclosure frameworks, bug bounty programs, and coordinating multi-stakeholder vulnerability remediation. * Excellent communication skills, with the ability to explain technical findings to researchers, engineers, leaders, and non-technical stakeholders. * Comfort working in complex, high-stakes environments where security decisions affect product reliability and customer trust. * Experience with GPU/HPC or cloud infrastructure security, including AWS, GCP, or Azure. * Knowledge of Kubernetes, container security, APIs, identity and access management, and hybrid cloud architectures. * A background in product security, application security, incident response, vulnerability management, penetration testing, or hands-on work with bug bounty platforms. ## Description We are seeking a Staff Security Engineer, Product and Platform Security to lead security initiatives across Nscale's products, cloud platforms, hyperscale GPU clusters, and critical infrastructure. You'll partner closely with engineering, platform, infrastructure, and security teams to identify and reduce risk throughout the product and technology lifecycle. You'll provide hands-on security expertise across architecture and design reviews, threat modeling, vulnerability management, secure development, and incident response. This role will help build and scale product and platform security practices while turning technical findings, researcher insights, and emerging threats into stronger engineering controls, clearer priorities, and measurable improvements to Nscale's security posture., * Lead security reviews across Nscale's products, cloud platforms, APIs, hyperscale GPU clusters, and supporting infrastructure. * Partner with engineering teams throughout the development lifecycle to identify security risks and define practical remediation plans. * Conduct threat modeling and architecture reviews for new products, features, services, and platform changes. * Provide guidance on secure design, coding practices, authentication, authorization, data protection, and infrastructure security. * Help develop reusable security standards, patterns, and guardrails that enable teams to build and deploy securely at scale. Vulnerability Management and Remediation * Receive, analyze, and validate vulnerability findings from internal testing, security tooling, external researchers, and other sources. * Assign severity ratings using CVSS and assess technical and business impact to drive prioritization. * Coordinate with engineering, platform, and infrastructure teams to reproduce, validate, and remediate findings. * Create clear remediation roadmaps and track progress toward resolution. * Identify recurring vulnerability patterns and work with engineering teams to address systemic risks and technical debt. Bug Bounty and Responsible Disclosure * Design, launch, and scale Nscale's bug bounty and vulnerability disclosure programs across platforms such as HackerOne, Bugcrowd, or equivalent. * Establish clear scope definitions, reward guidelines, and submission processes that encourage high-quality vulnerability disclosures. * Build trusted relationships with security researchers and the broader security community. * Manage researcher communications, triage workflows, and resolution timelines with professionalism and transparency. * Act as the primary liaison between external researchers and internal security and engineering teams during vulnerability disclosure. Security Coordination and Incident Response * Support incident classification and escalation workflows when vulnerabilities or security issues are discovered in production environments. * Coordinate responsible disclosure timelines and remediation activities with affected stakeholders. * Contribute to root-cause analysis and process improvements following vulnerability discovery or security incidents. * Document findings, remediation steps, and lessons learned to improve product and platform security practices. * Maintain detailed records of findings and resolutions for audit and compliance purposes. Program Measurement and Improvement * Track and report on product and platform security KPIs, including vulnerability trends, remediation timelines, recurrence, and researcher engagement. * Analyze patterns in vulnerability types to identify systemic risks, control gaps, and technical debt. * Provide regular insights to leadership on security risks, emerging threats, researcher feedback, and program effectiveness. * Recommend enhancements to security controls, testing coverage, program scope, and remediation processes based on data. * Benchmark Nscale's product and platform security practices against industry peers in cloud infrastructure and AI/GPU platforms. Threat Intelligence and Security Awareness * Monitor emerging vulnerabilities, attack vectors, and security trends relevant to cloud platforms, GPU infrastructure, Kubernetes, containers, and AI systems. * Share findings with security, product, platform, and engineering teams to inform prevention and detection strategies. * Support security awareness and training initiatives by communicating lessons learned from vulnerabilities and incidents. * Promote security ownership across engineering teams through practical guidance, collaboration, and knowledge sharing. KPIs * Reduction in product and platform security risk and recurring vulnerability types * Time to validate, prioritize, and resolve reported vulnerabilities * Security review and threat-modeling coverage for critical products and platform changes * Adoption and effectiveness of secure engineering standards and controls * Researcher engagement and responsible disclosure outcomes, The responsibilities outlined in this job description are not exhaustive and are intended to provide a general overview of the position. The employee may be required to perform additional duties, tasks, and responsibilities as assigned by management, consistent with the skills and qualifications required for the role. ## Related Videos - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Understanding Kubernetes in a visual way](https://www.wearedevelopers.com/videos/100085-understanding-kubernetes-in-a-visual-way) - [Mutation Testing and Fuzzing in C#](https://www.wearedevelopers.com/videos/703-mutation-testing-and-fuzzing-in-c) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Instant KAI Sandboxes with vCluster: Multi-Tenant, Multi-Scheduler GPU Sharing](https://www.wearedevelopers.com/videos/100333-instant-kai-sandboxes-with-vcluster-multi-tenant-multi-scheduler-gpu-sharing) - [Test-reduction - Doing more with less](https://www.wearedevelopers.com/videos/977-test-reduction-doing-more-with-less) ## Related Articles - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)