Nebius

Detection Engineering & Response Lead

Lead · Удалённо · Израиль · Английский B2

Навыки

  • Embedded
  • Форензика и реагирование
  • Go
  • Kubernetes
  • Linux
  • Machine Learning
  • Мониторинг и observability
Ещё 8
  • Ответственность за результат
  • SIEM
  • SOLID и паттерны
  • Splunk / ArcSight / QRadar
  • SQL
  • SRE-практики
  • Работа со стейкхолдерами
  • YARA / threat intelligence

О компании и продукте

  • Nebius is leading a new era in cloud infrastructure for the global AI economy. We are building a full-stack AI cloud platform that supports developers and enterprises from data and model training through to production deployment, without the cost and complexity of building large in-house AI/ML infrastructure.
  • Built by engineers, for engineers. From large-scale GPU orchestration to inference optimization, we own the hard problems across compute, storage, networking and applied AI.
  • Listed on Nasdaq (NBIS) and headquartered in Amsterdam, we have a global footprint with R&D hubs across Europe, the UK, North America and Israel. Our team of 1,500+ includes hundreds of engineers with deep expertise across hardware, software and AI R&D.
  • The Detection and Response team is responsible for detection engineering, threat intelligence, and incident response across Nebius Cloud. Its goal is to improve and maintain Nebius's security monitoring capabilities, as well as to build and maintain an end-to-end Security Incident Response program - people, processes, and tools.

Задачи

  • Lead detection development: maintain low false-positive and false-negative rates
  • Work closely with alerts consumers (20+ teams) to keep noise low and signal high, ensuring they can act quickly without missing genuine threats
  • Architect and operate detection coverage across our cloud and bare-metal environments
  • Build and extend our internal D&R tools and pipelines - onboard new logs, build and automate response runbooks
  • Integrate threat intelligence into detection logic and IR playbooks, tracking adversary TTPs relevant to Cloud infrastructure
  • Lead incident response end-to-end: scoping, containment, root cause analysis, post-incident reviews and controlling critical action items are closed to prevent future possible incidents
  • Partner with Compliance and Engineering teams to detect real threats while meeting the needs of both engineers and regulators
  • Define and report on D&R metrics: MTTD, MTTR, detection coverage, false positive rates, etc
  • Build and maintain Security Incident Response program: people, processes, tools
  • Build tools, runbooks, and on-call processes that scale as the company grows

Требования

  • 6+ years in security operations, detection engineering, or incident response — with at least 1–2 years leading or mentoring a team
  • Deep hands-on experience with cloud-native environments (Kubernetes, Linux workloads, container-based infrastructure)
  • Strong detection engineering skills: writing and tuning rules/detections in SIEM platforms (e.g., Chronicle, Splunk, Elastic) and SQL
  • Experience building or operating SOAR workflows and automating response at scale (ideally with Golang and Temporal)
  • Working knowledge of threat intelligence frameworks (MITRE ATT&CK, Pyramid of Pain, Kill Chain ) and how to operationalize them in detections
  • Solid IR fundamentals: memory forensics, log analysis, network traffic analysis, and post-incident reporting
  • Stakeholder management: able to coordinate across engineers, compliance, legal, executives during active incident phase
  • Serve as the primary owner and driver for complex changes, as a result of incidents post-mortem

Будет плюсом

  • Experience with AI/ML and GPU clusters related threats
  • Familiarity with eBPF-based detection or runtime security tooling (Falco, Tetragon)
  • Background in threat hunting
  • Why this role at Nebius
  • Build D&R at a company scaling from startup to global infrastructure provider in real time
  • Ability to evolve our internal D&R platform into a new cloud security product, delivering novel security observability for a range of neocloud customers - from big tech to AI startups
  • Work alongside world-class engineers on infrastructure that powers frontier AI
  • Flexible, remote-first culture
  • Benefits & Perks
  • Competitive compensation
  • Career growth and learning opportunities
  • Flexibility and ownership
  • Collaborative and innovative culture
  • Opportunity to work on impactful AI projects
  • International environment and talented teams
  • What's it like to work at Nebius
  • Fast moving - Bold thinking - Constant growth - Meaningful impact - Trust and real ownership - Opportunity to shape the future of AI

Условия

  • Competitive compensation with equity upside in a Nasdaq-listed, high-growth company

Паспорт вакансии

История публикации

Появилась в Вакандии26 дней
Перепубликациинетпубликовалась один раз
Проверяли на источникеВидели сегодня
Среди похожихНет данных22 из 30 · похожих вакансий слишком мало для сравнения

Откуда что взялось

Отмечено то, что вывели мы. Без пометки — значение назвал работодатель.

ГрейдLeadвычитано из текста вакансии
Формат работыУдалённо
ГеографияИзраильвычитано из текста вакансии
Зарплата≈ 18 833 USD в месяцнаша оценка, в вакансии не названа

Почему на этом месте в выдаче

Порядок выдачи объявлен контрактом: свежесть решает между днями, полнота и зарплата — внутри дня.

Полнота карточки1004 из 4 полей: грейд, формат, география, зарплата
Зарплата названа0вилки работодателя нет, показана наша оценка

Проверка Вакандии

Источники и свежесть

Тип источника
Карьерный сайт работодателя
Найдено публикаций
1
Посмотреть публикации и даты
  • greenhouseОсновная публикация · 2026-07-06

Работодатель

Nebius

50 активных вакансий · вилка работодателя указана в 23%

Открыть профиль компании

Безопасность

Отклик уходит на сайт источника

Вакандия показывает вакансию, но не отправляет отклик и не проверяет работодателя. Сам отклик вы оставляете на внешнем сайтеcareers.nebius.com.

Признаки мошенничества
  • Просят предоплату, «залог» или деньги за обучение и оборудование.
  • Требуют код из SMS, данные банковской карты или доступ к «Госуслугам».
  • Быстро уводят в мессенджер и торопят с решением.
  • Обещают большой доход без опыта и без деталей задач.

Настоящий работодатель не просит денег и платёжных данных до трудоустройства.

Продолжить поиск

Похожие вакансии

Причина сходства указана на каждой карточке

  1. Почему похожа: похожая специализация · тот же формат

    Spendesk

    Senior Security Engineer

    • Senior
    • Удалённо
    • Париж, Франция
    Подробнее