Director, Customer Identity and Access Management
About the role
Nscale is hiring a Director of Identity to lead the engineering function accountable for authentication, authorisation, and identity propagation across the platform - for humans, agents, and workloads. Identity sits on the critical path of every API call and every Console, SDK, or CLI action: when we are slow, the platform is slow; when we are wrong, we create significant security and reputational risk.
This is a high impact role with scope across Product, Platform, Infrastructure, SRE, and Security. You will set direction, hire and grow a high-performing team, and own end-to-end outcomes: a secure sign-in experience, consistent and auditable access control, and a paved road that makes secure patterns the default.
You’ll operate as a player‑coach: technically deep enough to make high-leverage architectural calls, and organisationally strong enough to align stakeholders and ship iteratively without compromising correctness.
What you’ll work on
- Authentication & federation: login/session flows, token issuance and exchange, key management, identity verification, and enterprise federation (SSO, SCIM, group/role sync, outbound federation).
- Authorisation & policy: RBAC/ABAC models, policy definition and enforcement, permission resolution services, and scalable guardrails.
- Propagation & workload identity: standardised identity headers/claims, service-to-service identity, workload identity, and secure delegation patterns.
- Paved roads: shared libraries, SDKs, middleware, docs, and compatibility contracts that make secure patterns the default.
- Operational trust: reliability/latency discipline, safe incremental releases, incident response, observability, and auditability/evidence generation.
Responsibilities
- Mission outcomes. Own the end-to-end identity experience and security posture across the platform, and the feedback loops that drive the roadmap.
- Org leadership & operating model. Set the multi-year Identity strategy, organisational design, and delivery approach; accountable for org-wide delivery, budget, and headcount. Hire and develop engineers and managers, build a leadership bench, and create the structure that enables the function to scale.
- Platform coherency. Establish standards and patterns for identity usage across all services and product surfaces, reducing bespoke integrations and inconsistent permission models - with proactive detection to ensure adherence.
- Security-by-default. Make the secure path the easy path: opinionated primitives, strong defaults, and guardrails that prevent classes of mistakes.
- Reliability & performance. Hold a high bar for correctness, availability, and latency on the systems that gate every request. Ensure rollout safety and fast recovery.
- Cross-functional alignment. Represent Identity in architectural and roadmap conversations with Product, Platform, Infrastructure, SRE, and Security - resolving trade-offs and ensuring decisions stick when you are not in the room.
- Industry awareness. Stay abreast of identity, security, and cloud industry direction - and translate relevant shifts (standards, vendor roadmaps, regulatory changes, and threats) into pragmatic platform improvements.
- Metrics & accountability. Define and track the KPIs that matter: authentication success rate, authz decision latency, incident rate/MTTR, adoption of shared libraries, policy coverage, and access review hygiene.
- Sovereignty & key custody. Ensure our identity and key-management posture supports sovereignty requirements (where needed), with clear controls and evidence for where keys and trust roots are held and operated.
Requirements
This role needs someone who can operate across two modes without losing effectiveness in either: deep technical work on hard problems, and the leadership that makes an identity function hold together.
- Senior technical leadership. Staff+ / Principal engineering background (or equivalent), with the ability to challenge designs across distributed systems, security boundaries, and the full stack.
- Track record leading teams. Experience hiring, leading, and developing engineering teams with strong delivery and operational standards.
- Identity domain expertise. Deep experience with authentication and authorisation systems (e.g., OAuth 2.0/OIDC, RBAC/ABAC, token exchange, JWT/JWKS, policy engines such as OPA/Cedar, Zanzibar-style patterns).
- Distributed systems & cloud fluency. Hands-on experience designing, building, and operating scalable production systems for or on a major cloud provider (AWS/GCP/Azure), including day-2 operations.
- Critical-path discipline. Comfort working on systems with large blast radius - rollback plans, incremental delivery, and correctness guarantees - while preserving release momentum and navigating one-way-door decisions when they arise.
- Communication and influence. Ability to work with Security, Product, and Engineering leadership, extract signal from design partner conversations, and translate it into measurable deliverables.
- Bias for action. Ability to turn ambiguous goals into a practical, high-impact sequence of deliverables.
Preferred
- Experience building workload identity and service-to-service authentication at scale (mTLS, SPIFFE/SPIRE, token minting, short-lived credentials).
- Experience designing for agent identity: service accounts, delegated/impersonation flows, scoped credentials, and policy enforcement for autonomous systems.
- Experience with large-scale policy and permissions management, including UX for access requests, reviews, and auditable automated approval systems.
- Proven success shipping platforms or internal products adopted broadly by engineering teams.
- Experience with Kubernetes and infrastructure-as-code (Terraform/Pulumi), event-driven architectures, and message queues (NATS/Kafka/RabbitMQ).
- Comfort partnering closely with developer experience functions: documentation and tooling that drive adoption.
- Familiarity with GPU orchestration or ML platform concerns (identity boundaries across workload scheduling and multi-tenant environments).
The range below reflects the base salary for the position. Actual compensation may vary based on job-related factors such as skill set, experience, education, and location. In addition to base salary, this role may be eligible for bonus, equity, and/or commission programs. Nscale may offer a competitive benefits package including medical, dental, vision, flexible paid time off, parental leave, and retirement plan participation.
Salary Range
$230,000-$400,000 USD
For information on how Nscale handles candidate personal data, please see our Employee & Candidate Privacy Notice: Here.

