Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Detection & Response Lead (Cybersecurity): Building and running the D&R capability from the ground up for an AI cloud platform with an accent on detection engineering, threat intelligence, and incident response. Focus on architecting detection coverage across cloud and bare-metal environments, automating response runbooks, and leading complex security incidents.
Location: Remote (Europe)
Company
Nebius is building a full-stack AI cloud platform for the global AI economy, specializing in GPU orchestration and inference optimization.
What you will do
- Lead detection development to achieve full MITRE coverage and maintain high signal-to-noise ratios.
- Architect and operate detection coverage across cloud and bare-metal environments.
- Develop internal D&R tools, automate response runbooks, and onboard new logs.
- Manage end-to-end incident response including scoping, containment, and root cause analysis.
- Integrate threat intelligence into detection logic and IR playbooks.
- Define D&R metrics (MTTD, MTTR) and establish the Security Incident Response program.
Requirements
- 6+ years in security operations, detection engineering, or incident response.
- 1–2 years of experience leading or mentoring a team.
- Deep experience with cloud-native environments (Kubernetes, Linux, containers).
- Proficiency in writing and tuning rules in SIEM platforms (Chronicle, Splunk, Elastic) and SQL.
- Experience with SOAR workflows and automation, ideally using Golang and Temporal.
- Must be authorized to work in the country in which you apply.
Nice to have
- Knowledge of AI/ML and GPU cluster threats.
- Experience with eBPF-based detection (Falco, Tetragon).
- Background in threat hunting.
Culture & Benefits
- Competitive compensation with equity upside in a Nasdaq-listed company.
- Flexible, remote-first work culture.
- Opportunities for career growth and learning.
- Collaborative and innovative international environment.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →