# Head of International Security

**Company:** [Scale AI](https://hotfix.jobs/companies/scale-ai)
**Location:** London, United Kingdom
**Role:** Security Engineering
**Experience:** 8+ years
**Skills:** AWS, GCP, Azure, IAM, Zero Trust, RBAC, Secrets Management, CI/CD, Encryption, Logging And Monitoring, Secure Sdlc, Threat Modeling, GDPR, ISO 27001, SOC 2
**Posted:** 2026-08-04

> Leads Scale’s international security strategy across enterprise and public-sector markets, translating regional regulations into engineering controls and securing cloud infrastructure, products, data, and AI systems. Requires 8+ years of cybersecurity experience, technical cloud-security depth, and experience leading security programs and customer engagements.

## Job Description

## Responsibilities

### Execute the Global Security Strategy Across International Markets
- Drive execution of Scale's multi-year secure-by-default roadmap across non-US markets, surfacing regional needs into global architecture decisions.
- Translate regional regulatory requirements, including GDPR, ISO 27001/27017/27018, SOC 2, UK Cyber Essentials Plus, EU AI Act, NIS2, and country-specific data residency and sovereign-cloud rules, into concrete engineering controls.
- Track regional security metrics and accountability, and represent the international perspective in global prioritization, audits, and roadmap reviews.

### Lead Regional Security Engineering and Threat Detection
- Own regional execution of identity, fine-grained RBAC, secrets management, CI/CD hardening, encryption, logging, and infrastructure protection, with a focus on cross-border data flows and in-region telemetry.
- Establish high-fidelity detection and response capabilities that meet local time-zone coverage, breach-notification timelines, and regulator expectations.
- Drive systemic risk reduction through platform-level controls in partnership with the global security engineering team.

### Secure Products, Data, and AI Systems for International Customers
- Protect customer data, proprietary datasets, and AI assets across regional deployments, including in-region processing, customer-managed encryption keys, and data-localization commitments.
- Design and enforce multi-tenant isolation, fine-grained RBAC, and privilege lifecycle management across customer environments.
- Address AI-specific attack surfaces, including prompt injection, tool abuse in agentic workflows, data exfiltration, and model or data integrity risks.
- Champion secure SDLC practices, threat modeling, and code-review standards within FDE teams.

### Lead Insider Risk and Contributor Integrity
- Partner with Product and Operations to reduce fraud, account compromise, collusion, and identity-based abuse without degrading platform usability.
- Implement auditability, privilege governance, and behavioral anomaly detection across sensitive workflows in a manner defensible to international regulators.

### Partner with International Customers and Governments
- Serve as the lead security partner in international enterprise and public-sector engagements, including customer security reviews, regulator interactions, and trust initiatives across the UK, EU, MENA, and beyond.
- Drive execution of the international clearable-infrastructure plan without fragmenting the core platform.
- Partner with Sales, Legal, and Compliance to streamline security reviews and build customer confidence.

## Requirements
- 8+ years in cybersecurity, including security engineering, product security, detection and response, or cloud security.
- At least 4 years leading or formally mentoring engineers in high-growth or enterprise environments.
- Experience building and scaling security programs that materially improved risk posture.
- Strong technical depth in cloud-native security, AWS, Google Cloud, Azure, IAM, Zero Trust, infrastructure security, logging and monitoring, and secure SDLC practices.
- Hands-on familiarity with GDPR, ISO 27001, SOC 2, UK Cyber Essentials Plus, NIS2, and the EU AI Act.
- Experience managing insider risk or securing environments with significant third-party, contractor, or marketplace-style user populations.
- Ability to work cross-functionally with Engineering, Product, Legal, Compliance, Sales, and Public Sector stakeholders.
- Right to work in the UK.
- Willingness to travel regularly and undergo country-specific clearance vetting when required.

## Nice-to-Haves
- Experience securing AI/ML platforms, LLM-based systems, or agentic applications.
- Familiarity with training-data poisoning, prompt injection, tool or plugin abuse, and protection of model-related intellectual property.
- Experience at the intersection of enterprise SaaS and government or national-security customers.
- Working knowledge of GCC sovereign compliance and privacy regulations, including UAE DESC CSP and Qatar NCSA NISCF/NIA.
- Experience building secure-by-design multi-tenant systems for large global clients across multiple regulatory regimes.
- Experience leading red-teaming, adversarial testing, or offense-informed defense programs.
- Active or eligible UK clearance (SC or DV), NATO clearance, or equivalent allied-jurisdiction clearance.

## Similar jobs

- [Principal Security Researcher](https://hotfix.jobs/jobs/1ceb0cbb-1f4e-4652-8d72-4e04a6b901ef) - GitLab - Remote - $203k – $275k/yr
- [Principal Security Awareness & Human Risk Engineer](https://hotfix.jobs/jobs/78ef4cbc-f12c-4557-b84e-ae3ad525db78) - GitLab - Remote - $203k – $275k/yr
- [Staff Security Researcher](https://hotfix.jobs/jobs/6b308cd8-be33-459a-b904-08e54567ad7b) - GitLab - Remote - $168k – $238k/yr
- [Staff Software Security Engineer](https://hotfix.jobs/jobs/0b2ae9ea-2460-4795-b7f0-fee06fb81642) - Anthropic - London, United Kingdom - £255k – £325k/yr
- [Staff Vulnerability Management Engineer](https://hotfix.jobs/jobs/f6eb93ea-70d6-496f-a251-e679113fd047) - Chainguard - Remote - $170k – $231k/yr

**Apply:** https://hotfix.jobs/jobs/7d85d577-bff0-474d-834e-82863afb5ebb
**Canonical:** https://hotfix.jobs/jobs/7d85d577-bff0-474d-834e-82863afb5ebb