layiq
worthy; deserving; fitting; suitable.
A role, opportunity, or path that merits attention, time, and pursuit.
Loading LAYIQ…Job opportunity
Nscale
New York
Source: Nscale careers · View original posting
From Nscale's posting. “We” and “our” refer to the employer.
Nscale is hiring a Director of Identity to lead the engineering function accountable for authentication, authorisation, and identity propagation across the platform - for humans, agents, and workloads
. Identity sits on the critical path of every API call and every Console, SDK, or CLI action: when we are slow, the platform is slow; when we are wrong, we create significant security and reputational risk.
This is a high impact role with scope across Product, Platform, Infrastructure, SRE, and Security. You will set direction, hire and grow a high-performing team, and own end-to-end outcomes: a secure sign-in experience, consistent and auditable access control, and a paved road that makes secure patterns the default.
You’ll operate as a player‑coach: technically deep enough to make high-leverage architectural calls, and organisationally strong enough to align stakeholders and ship iteratively without compromising correctness.
login/session flows, token issuance and exchange, key management, identity verification, and enterprise federation (SSO, SCIM, group/role sync, outbound federation).
RBAC/ABAC models, policy definition and enforcement, permission resolution services, and scalable guardrails.
standardised identity headers/claims, service-to-service identity, workload identity, and secure delegation patterns.
shared libraries, SDKs, middleware, docs, and compatibility contracts that make secure patterns the default.
reliability/latency discipline, safe incremental releases, incident response, observability, and auditability/evidence generation.
This role needs someone who can operate across two modes without losing effectiveness in either: deep technical work on hard problems, and the leadership that makes an identity function hold together.
Senior technical leadership.
Staff+ / Principal engineering background (or equivalent), with the ability to challenge designs across distributed systems, security boundaries, and the full stack.
Track record leading teams.
Experience hiring, leading, and developing engineering teams with strong delivery and operational standards.
Identity domain expertise.
Deep experience with authentication and authorisation systems (e.g., OAuth 2.0/OIDC, RBAC/ABAC, token exchange, JWT/JWKS, policy engines such as OPA/Cedar, Zanzibar-style patterns).
Distributed systems & cloud fluency.
Hands-on experience designing, building, and operating scalable production systems for or on a major cloud provider (AWS/GCP/Azure), including day-2 operations.
Critical-path discipline.
Comfort working on systems with large blast radius - rollback plans, incremental delivery, and correctness guarantees - while preserving release momentum and navigating one-way-door decisions when they arise.
Communication and influence.
Ability to work with Security, Product, and Engineering leadership, extract signal from design partner conversations, and translate it into measurable deliverables.
Bias for action.
Ability to turn ambiguous goals into a practical, high-impact sequence of deliverables.
Preferred
Experience building workload identity and service-to-service authentication at scale (mTLS, SPIFFE/SPIRE, token minting, short-lived credentials).
Experience designing for agent identity
: service accounts, delegated/impersonation flows, scoped credentials, and policy enforcement for autonomous systems.
Experience with large-scale policy and permissions management, including UX for access requests, reviews, and auditable automated approval systems.
Proven success shipping platforms or internal products adopted broadly by engineering teams.
Experience with Kubernetes and infrastructure-as-code (Terraform/Pulumi), event-driven architectures, and message queues (NATS/Kafka/RabbitMQ).
Comfort partnering closely with developer experience functions: documentation and tooling that drive adoption.
Familiarity with GPU orchestration or ML platform concerns (identity boundaries across workload scheduling and multi-tenant environments).
The range below reflects the base salary for the position. Actual compensation may vary based on job-related factors such as skill set, experience, education, and location. In addition to base salary, this role may be eligible for bonus, equity, and/or commission programs. Nscale may offer a competitive benefits package including medical, dental, vision, flexible paid time off, parental leave, and retirement plan participation.
Compensation
$230,000 — $400,000 USD
For information on how Nscale handles candidate personal data, please see our Employee & Candidate Privacy Notice:
Here.
Nscale does not accept unsolicited candidate submissions from recruitment agencies.
LAYIQ is an independent job-discovery service. This listing does not imply a partnership with or endorsement by the employer. Review the original posting for current details and availability.
Employer posted: