Cyber Risk Lead

NscaleSeattle, WA
$150,000 - $180,000Hybrid

About The Position

Nscale is seeking a Cyber Risk Lead to establish and manage enterprise-wide cyber security risk across its global AI infrastructure. This senior individual contributor role integrates risk management, statistical analysis, engineering, and governance. The position involves owning the cyber risk register, risk treatment, and remediation governance, collaborating with various teams including control and system owners, compliance engineering, and the enterprise risk team. The role approaches risk as an engineering problem, aiming to create a dynamic, threat-informed cyber risk program that quantifies, prioritizes, and reduces cyber risk as Nscale expands.

Requirements

  • 8+ years of experience in enterprise security risk management, including building or running a risk register and treatment program.
  • Risk quantification and treatment expertise grounded in a recognized method such as the NIST Cybersecurity Framework, ISO 27005, or FAIR.
  • A track record of driving remediation across engineering teams, not simply logging issues.
  • Comfort working directly with risk data using SQL, scripting, or equivalent tooling to pull and trend risk, vulnerability, and asset data.
  • Experience building risk tooling or automation, including integrations between scanners, asset inventories, GRC platforms, and engineering issue trackers.
  • Ability to use automation and AI-assisted workflows to reduce manual GRC work.
  • Strong understanding of cloud infrastructure and security controls, including the ability to read infrastructure-as-code such as Terraform well enough to assess whether a control is effective.
  • Experience with automation-first risk management, continuous control monitoring, or actuarial approaches to risk modeling.
  • Experience with AI infrastructure, hyperscale, regulated environments, critical infrastructure, data center operations, or sovereign cloud requirements.

Nice To Haves

  • Relevant certifications such as CISSP or CRISC
  • A strong statistics or mathematics background

Responsibilities

  • Build and operate Nscale’s continuously measured cyber risk program, transforming technical telemetry into actionable risk insights.
  • Develop and maintain a dynamic cyber risk model that reflects asset exposure across technology, data centers, and software supply chains.
  • Model realistic attack scenarios using threat intelligence, adversary TTPs, historical incidents, and attack path analysis to prioritize risks by likelihood and loss magnitude.
  • Quantify cyber risk using recognized methodologies such as FAIR, NIST SP 800-30, or ISO 27005, adapting them to support engineering decisions rather than compliance reporting.
  • Own the cyber risk treatment lifecycle, translating prioritized risks into actionable engineering work with clear ownership, measurable objectives, and expected risk reduction.
  • Establish measurable risk treatment objectives and engineering service levels.
  • Validate that remediation activities produce demonstrable reductions in cyber risk.
  • Align cyber risk with enterprise risk management through shared taxonomies, scoring models, and reporting that accurately represent enterprise exposure.
  • Establish engineering service levels, escalation paths, and governance that drive timely remediation while balancing operational and business priorities.
  • Hold remediation owners accountable for closing risks within agreed service levels.
  • Validate completed remediation through technical evidence rather than administrative closure.
  • Maintain the cyber risk register and closure discipline while control owners resolve identified gaps.
  • Integrate risk into the compliance-as-code platform so posture is continuous and evidence-backed.
  • Apply risk-as-code where it materially improves risk and issue management.
  • Improve the fidelity of cyber risk measurements through engineering automation, analytics, and new data sources.
  • Connect risk, vulnerability, asset, GRC, and engineering workflow data to reduce manual effort and improve visibility.
  • Report material enterprise risk scenarios using defensible logic and clear, articulate presentations.
  • Provide leadership with measured insights into Nscale’s cyber risk posture and treatment progress.
  • Help shape the broader GRC program architecture as it grows.

Benefits

  • Highly competitive US compensation package (base + bonus + equity)
  • Performance reviews every 12 months
  • Dynamic progression plan tailored to ambitions
  • Flexible workplace
  • Medical
  • Dental
  • Vision
  • Flexible paid time off
  • Parental leave
  • Retirement plan participation
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service