5 hours ago
Amsterdam, NetherlandsSenior
Responsibilities
- Validate and extend Secure SDLC threat models through continuous penetration testing, automate routine validations, and assess threat severity and mitigation status.
- Plan and execute red team engagements against cloud compute, storage, inference, networking, orchestration, and internal tooling layers.
- Conduct purple team exercises with Detection & Response and security engineering teams to validate detection coverage and close gaps.
- Research novel attacks against GPU infrastructure, firmware, vendor drivers, device passthrough, SR-IOV/IOMMU, RDMA/InfiniBand, inference systems, and managed AI platform services.
- Assess tenant-isolation boundaries and conduct targeted security assessments of new products and infrastructure changes before release.
- Produce clear reports with prioritized findings, business-contextualized risk, and remediation guidance for technical and leadership audiences.
- Establish scalable red team processes, tooling, and methodology as the platform grows.
Requirements
- At least 6 years of experience in offensive security, penetration testing, red teaming, or adversary simulation.
- Deep experience attacking cloud-native environments, including Kubernetes privilege escalation, cloud IAM abuse, virtualization, and container escapes.
- Strong knowledge of the attack lifecycle, including initial access, persistence, lateral movement, and data exfiltration.
- Proficiency developing custom tooling and post-exploitation capabilities with Python, Go, or similar languages.
- Experience running purple team exercises and collaborating constructively with blue teams.
- Ability to write clear, senior-level reports that contextualize business risk and provide actionable guidance.
- Experience attacking ML infrastructure, model-serving pipelines, or GPU clusters is preferred.
- Reverse engineering, exploit development, application security, eBPF bypass, kernel exploitation, vulnerability research, CVE discovery, cloud-provider internals, or conference presentation experience is preferred.
Benefits
- Flexible, remote-first work arrangement.
- Competitive compensation and equity upside.
- Career growth and learning opportunities.
- Flexibility, ownership, collaborative culture, and an international environment.
- Opportunity to work on impactful AI projects with teams building GPU clusters, AI platforms, and multi-tenant cloud infrastructure.
Tech Stack
Categories
About Nebius
Nebius builds a full-stack AI cloud offering GPU compute, storage, and tools for training and deploying ML models for startups, enterprises, and research labs. It sells consumption-based cloud infrastructure (IaaS/PaaS) and managed services tailored to generative AI workloads, including large-scale model training and inference. The company is headquartered in Amsterdam and operates as an independent provider.
