The opportunity
Scale AI sits at the intersection of frontier AI, enterprise software, and national security. We safeguard high-value assets: proprietary AI data and infrastructure, a global contributor ecosystem, and sensitive enterprise and government customer data.
What you'll do
Drive execution of Scale's multi-year secure-by-default roadmap across non-US: markets, surfacing regional needs into global architecture decisions.
Translate regional regulatory requirements (GDPR, ISO 27001/27017/27018, SOC: 2, UK Cyber Essentials Plus, EU AI Act, NIS2, and country-specific data residency / sovereign-cloud rules) into concrete engineering controls.
Track regional security metrics and accountability, and represent the: international perspective in global prioritisation, audits, and roadmap reviews.
Own the regional execution of identity, fine-grained RBAC, secrets: management, CI/CD hardening, encryption, logging, and infrastructure protection with a particular focus on cross-border data flows and in-region telemetry.
Stand up high-fidelity detection and response capabilities that meet local: time zone coverage, breach-notification timelines, and regulator expectations.
Drive systemic risk reduction through platform-level controls, partnering: with the global security engineering team rather than building parallel stacks.
What they're looking for
- Ensure enterprise-grade protection of customer data, proprietary datasets,: and AI assets across regional deployments, including support for in-region processing, encryption with customer-managed keys, and data-localisation commitments.
- Design and enforce robust multi-tenant isolation, fine-grained RBAC, and: privilege lifecycle management across customer environments serving international enterprises and public sector buyers.
- Address AI-specific attack surfaces; prompt injection, tool abuse in agentic: workflows, data exfiltration, and model/data integrity risks.
- Champion secure SDLC practices, threat modeling, and code review standards within FDE teams.