Skip to content
Scale AIScale AI

Head of International Security

Leads Scale’s international security strategy across enterprise and public-sector markets, translating regional regulations into engineering controls and securing cloud infrastructure, products, data, and AI systems. Requires 8+ years of cybersecurity experience, technical cloud-security depth, and experience leading security programs and customer engagements.

About the job

Responsibilities

Execute the Global Security Strategy Across International Markets

  • Drive execution of Scale's multi-year secure-by-default roadmap across non-US markets, surfacing regional needs into global architecture decisions.
  • Translate regional regulatory requirements, including GDPR, ISO 27001/27017/27018, SOC 2, UK Cyber Essentials Plus, EU AI Act, NIS2, and country-specific data residency and sovereign-cloud rules, into concrete engineering controls.
  • Track regional security metrics and accountability, and represent the international perspective in global prioritization, audits, and roadmap reviews.

Lead Regional Security Engineering and Threat Detection

  • Own regional execution of identity, fine-grained RBAC, secrets management, CI/CD hardening, encryption, logging, and infrastructure protection, with a focus on cross-border data flows and in-region telemetry.
  • Establish high-fidelity detection and response capabilities that meet local time-zone coverage, breach-notification timelines, and regulator expectations.
  • Drive systemic risk reduction through platform-level controls in partnership with the global security engineering team.

Secure Products, Data, and AI Systems for International Customers

  • Protect customer data, proprietary datasets, and AI assets across regional deployments, including in-region processing, customer-managed encryption keys, and data-localization commitments.
  • Design and enforce multi-tenant isolation, fine-grained RBAC, and privilege lifecycle management across customer environments.
  • Address AI-specific attack surfaces, including prompt injection, tool abuse in agentic workflows, data exfiltration, and model or data integrity risks.
  • Champion secure SDLC practices, threat modeling, and code-review standards within FDE teams.

Lead Insider Risk and Contributor Integrity

  • Partner with Product and Operations to reduce fraud, account compromise, collusion, and identity-based abuse without degrading platform usability.
  • Implement auditability, privilege governance, and behavioral anomaly detection across sensitive workflows in a manner defensible to international regulators.

Partner with International Customers and Governments

  • Serve as the lead security partner in international enterprise and public-sector engagements, including customer security reviews, regulator interactions, and trust initiatives across the UK, EU, MENA, and beyond.
  • Drive execution of the international clearable-infrastructure plan without fragmenting the core platform.
  • Partner with Sales, Legal, and Compliance to streamline security reviews and build customer confidence.

Requirements

  • 8+ years in cybersecurity, including security engineering, product security, detection and response, or cloud security.
  • At least 4 years leading or formally mentoring engineers in high-growth or enterprise environments.
  • Experience building and scaling security programs that materially improved risk posture.
  • Strong technical depth in cloud-native security, AWS, Google Cloud, Azure, IAM, Zero Trust, infrastructure security, logging and monitoring, and secure SDLC practices.
  • Hands-on familiarity with GDPR, ISO 27001, SOC 2, UK Cyber Essentials Plus, NIS2, and the EU AI Act.
  • Experience managing insider risk or securing environments with significant third-party, contractor, or marketplace-style user populations.
  • Ability to work cross-functionally with Engineering, Product, Legal, Compliance, Sales, and Public Sector stakeholders.
  • Right to work in the UK.
  • Willingness to travel regularly and undergo country-specific clearance vetting when required.

Nice-to-Haves

  • Experience securing AI/ML platforms, LLM-based systems, or agentic applications.
  • Familiarity with training-data poisoning, prompt injection, tool or plugin abuse, and protection of model-related intellectual property.
  • Experience at the intersection of enterprise SaaS and government or national-security customers.
  • Working knowledge of GCC sovereign compliance and privacy regulations, including UAE DESC CSP and Qatar NCSA NISCF/NIA.
  • Experience building secure-by-design multi-tenant systems for large global clients across multiple regulatory regimes.
  • Experience leading red-teaming, adversarial testing, or offense-informed defense programs.
  • Active or eligible UK clearance (SC or DV), NATO clearance, or equivalent allied-jurisdiction clearance.

Skills

AWS, GCP, Azure, IAM, Zero Trust, RBAC, Secrets Management, CI/CD, Encryption, Logging And Monitoring, Secure Sdlc, Threat Modeling, GDPR, ISO 27001, SOC 2

GitLab

GitLab

United States
Principal Security Researcher
$203k+/yrRemote10+ YOESecurity Engineering

Leads offensive security research across GitLab’s codebase and AI-powered agentic surfaces, identifying systemic vulnerabilities, developing exploit proofs of concept, and driving remediation. Requires 10+ years of security research or penetration-testing experience and proficiency in multiple programming languages.

GitLab

GitLab

United States
Principal Security Awareness & Human Risk Engineer
$203k+/yrRemote10+ YOESecurity Engineering

Own GitLab’s global security awareness and human-risk program, leading phishing simulations, behavior-change initiatives, training platforms, vendor strategy, and audit support. Requires 10+ years scaling enterprise awareness programs and strong stakeholder influence in a distributed organization.

GitLab

GitLab

United States
Staff Security Researcher
$168k+/yrRemote7+ YOESecurity Engineering

Conducts advanced application and AI security research for GitLab, identifying and validating systemic vulnerabilities, developing scalable research tooling, and guiding remediation. Requires 7+ years in offensive security and expertise across multiple technical domains and programming languages.

Anthropic

Anthropic

London, United Kingdom

Staff Software Security Engineer
£255k+/yrHybrid8+ YOESecurity Engineering

The Staff Software Security Engineer will secure large-scale AI clusters and multicloud infrastructure through network controls, identity management, secure development workflows, and threat modeling. The role requires 8+ years of software engineering experience, strong systems programming skills, and deep cloud and Kubernetes security expertise.

Chainguard

Chainguard

United States
Staff Vulnerability Management Engineer
$170k+/yrRemote7+ YOESecurity Engineering

Leads vulnerability disclosure operations at scale, including novel vulnerability measurement, CVE assignment, embargo coordination, and industry collaboration. The Staff individual contributor provides technical leadership and requires extensive software security or open source experience.