9 hours ago
Amsterdam, NetherlandsStaff+
Responsibilities
- Lead detection development and tune detections to maintain strong signal quality and low false-positive and false-negative rates.
- Architect and operate detection coverage across cloud and bare-metal environments.
- Build and extend internal detection and response tools and pipelines, including log onboarding and automated response runbooks.
- Integrate threat intelligence and adversary TTPs into detection logic and incident response playbooks.
- Lead incident response from scoping and containment through root cause analysis, post-incident reviews, and closure of corrective actions.
- Build and maintain the Security Incident Response program across people, processes, and tools.
- Define and report D&R metrics including MTTD, MTTR, detection coverage, and false-positive rates.
- Build scalable tools, runbooks, and on-call processes while coordinating with engineering, compliance, legal, and executive stakeholders.
- Lead and mentor a small, growing team of analysts and engineers.
Requirements
- 6+ years of experience in security operations, detection engineering, or incident response.
- 1–2 years of experience leading or mentoring a team.
- Deep hands-on experience with cloud-native environments, Kubernetes, Linux workloads, and container-based infrastructure.
- Strong detection engineering experience writing and tuning rules in SIEM platforms such as Chronicle, Splunk, or Elastic, with SQL proficiency.
- Experience building or operating SOAR workflows and automating response at scale, ideally with Golang and Temporal.
- Working knowledge of MITRE ATT&CK, Pyramid of Pain, and Kill Chain frameworks and their operationalization in detections.
- Experience with memory forensics, log analysis, network traffic analysis, and post-incident reporting.
- Ability to coordinate with engineering, compliance, legal, and executive stakeholders during active incidents.
- Experience with AI/ML and GPU-cluster-related threats is a plus.
- Familiarity with eBPF-based detection or runtime security tools such as Falco and Tetragon is a plus.
- Background in threat hunting is a plus.
Benefits
- Flexible, remote-first culture.
- Competitive compensation with equity upside at a Nasdaq-listed company.
- Career growth and learning opportunities.
- Flexibility, ownership, and an international collaborative environment.
- Opportunity to work on impactful AI projects and infrastructure supporting frontier AI.
Tech Stack
Categories
About Nebius
Nebius builds a full-stack AI cloud offering GPU compute, storage, and tools for training and deploying ML models for startups, enterprises, and research labs. It sells consumption-based cloud infrastructure (IaaS/PaaS) and managed services tailored to generative AI workloads, including large-scale model training and inference. The company is headquartered in Amsterdam and operates as an independent provider.
