Nebius

Lead Detection Engineer

Nebius
Apply
2 months ago
Tel Aviv-Yafo, IsraelStaff+

Responsibilities

  • Define detection coverage strategy across endpoint, identity, cloud, and infrastructure environments.
  • Build and own the Detection-as-Code pipeline, including version control, testing, peer review, and deployment practices.
  • Design architecture connecting detections to enrichment, triage, and automated response workflows.
  • Establish technical standards for designing, testing, documenting, deploying, and retiring detections.
  • Improve detection quality through fidelity metrics, false-positive reduction, coverage measurement, and continuous validation.
  • Design and build high-fidelity behavioral detections across SIEM and EDR platforms.
  • Research emerging attacker techniques and translate threat intelligence into scalable, evasion-resistant detections.
  • Validate detections through threat simulations and continuous detection testing.
  • Partner with SOC analysts to connect detection performance with real investigations.
  • Define and track detection engineering metrics and communicate coverage and effectiveness to security leadership.
  • Make architectural decisions that scale with the team and organization.

Requirements

  • At least 3 years of experience in detection engineering, security operations, or a hybrid offensive/defensive security role.
  • Experience owning or leading detection engineering work as a senior technical contributor.
  • Strong understanding of attacker tradecraft and adversary behavior.
  • Hands-on experience with at least one enterprise SIEM and EDR platform, such as Splunk, Microsoft Sentinel, or CrowdStrike.
  • Strong query development skills in SPL, KQL, Sigma, or similar technologies.
  • Solid engineering practices involving Git, code review, and Detection-as-Code workflows.
  • Experience using MITRE ATT&CK to design, validate, and measure detection coverage.
  • Ability to make and defend technical decisions and establish standards adopted by others.
  • Offensive security background or certifications is a bonus.
  • Threat hunting and detection validation framework experience is a bonus.
  • Experience designing SOAR playbooks and automated response workflows is a bonus.
  • Cloud security experience across Azure, AWS, or GCP is a bonus.
  • Experience building AI-assisted detection, investigation, or triage workflows is a bonus.

Benefits

  • Competitive compensation (amount not specified)
  • Career growth and learning opportunities
  • Flexibility and ownership
  • Collaborative and innovative culture
  • Opportunity to work on impactful AI projects
  • International environment and talented teams
  • Office-based work is available in Tel Aviv, Israel
  • Applicants must be authorized to work in the country of application
Nebius

About Nebius

1,001-5,000 employees

The Nebius AI Cloud brings powerful full-stack infrastructure for AI developers and practitioners across startups, enterprises and science institutes to build and deploy generative AI applications and rapidly deliver scientific breakthroughs by training and running ML models within a secure, high-performance, and cost-optimized cloud environment.

Contact me