Nebius

Detection & Response Lead

Nebius
Apply
9 hours ago
Amsterdam, NetherlandsStaff+

Responsibilities

  • Lead detection development and tune detections to maintain strong signal quality and low false-positive and false-negative rates.
  • Architect and operate detection coverage across cloud and bare-metal environments.
  • Build and extend internal detection and response tools and pipelines, including log onboarding and automated response runbooks.
  • Integrate threat intelligence and adversary TTPs into detection logic and incident response playbooks.
  • Lead incident response from scoping and containment through root cause analysis, post-incident reviews, and closure of corrective actions.
  • Build and maintain the Security Incident Response program across people, processes, and tools.
  • Define and report D&R metrics including MTTD, MTTR, detection coverage, and false-positive rates.
  • Build scalable tools, runbooks, and on-call processes while coordinating with engineering, compliance, legal, and executive stakeholders.
  • Lead and mentor a small, growing team of analysts and engineers.

Requirements

  • 6+ years of experience in security operations, detection engineering, or incident response.
  • 1–2 years of experience leading or mentoring a team.
  • Deep hands-on experience with cloud-native environments, Kubernetes, Linux workloads, and container-based infrastructure.
  • Strong detection engineering experience writing and tuning rules in SIEM platforms such as Chronicle, Splunk, or Elastic, with SQL proficiency.
  • Experience building or operating SOAR workflows and automating response at scale, ideally with Golang and Temporal.
  • Working knowledge of MITRE ATT&CK, Pyramid of Pain, and Kill Chain frameworks and their operationalization in detections.
  • Experience with memory forensics, log analysis, network traffic analysis, and post-incident reporting.
  • Ability to coordinate with engineering, compliance, legal, and executive stakeholders during active incidents.
  • Experience with AI/ML and GPU-cluster-related threats is a plus.
  • Familiarity with eBPF-based detection or runtime security tools such as Falco and Tetragon is a plus.
  • Background in threat hunting is a plus.

Benefits

  • Flexible, remote-first culture.
  • Competitive compensation with equity upside at a Nasdaq-listed company.
  • Career growth and learning opportunities.
  • Flexibility, ownership, and an international collaborative environment.
  • Opportunity to work on impactful AI projects and infrastructure supporting frontier AI.

Tech Stack

Categories

Nebius

About Nebius

1,001-5,000 employees

Nebius builds a full-stack AI cloud offering GPU compute, storage, and tools for training and deploying ML models for startups, enterprises, and research labs. It sells consumption-based cloud infrastructure (IaaS/PaaS) and managed services tailored to generative AI workloads, including large-scale model training and inference. The company is headquartered in Amsterdam and operates as an independent provider.

Contact me