Skip to main content
Nebius

Detection Engineering & Response Lead

RemoteEurope+Israel
Published
Role
Security
Experience
Lead
Company size
Mid-size
Salary not disclosed
Check eligibility

Open to Anywhere in Europe + IL. Set where you work from to check your eligibility.

No BS summary

Lead engineer to build and run Detection & Response (D&R) from scratch. Owns detection engineering, threat intelligence, and incident response for Nebius Cloud. Manages a team, handles complex incidents, and defines D&R strategy. Requires 6+ years in security ops/detection/IR, with 1-2 years leading teams, and deep cloud-native (Kubernetes) experience.

Core skills

Detection EngineeringIncident ResponseThreat Intelligence

Required skills

KubernetesLinuxSIEM platformsChronicleSplunkElasticSQLSOAR workflowsGoTemporalthreat intelligence frameworksMITRE ATT&CKPyramid of PainKill Chainmemory forensicslog analysisnetwork traffic analysis

Optional skills

AI/MLGPU clusterseBPF-based detectionruntime security toolingFalcoTetragonthreat hunting

Required languages

English

What you'll do

  • Lead detection development: maintain low false-positive and false-negative rates.
  • Work closely with alerts consumers (20+ teams) to keep noise low and signal high, ensuring they can act quickly without missing genuine threats.
  • Architect and operate detection coverage across our cloud and bare-metal environments
  • Build and extend our internal D&R tools and pipelines - onboard new logs, build and automate response runbooks.
  • Integrate threat intelligence into detection logic and IR playbooks, tracking adversary TTPs relevant to Cloud infrastructure
  • Lead incident response end-to-end: scoping, containment, root cause analysis, post-incident reviews and controlling critical action items are closed to prevent future possible incidents.
  • Partner with Compliance and Engineering teams to detect real threats while meeting the needs of both engineers and regulators.
  • Define and report on D&R metrics: MTTD, MTTR, detection coverage, false positive rates, etc.
  • Build and maintain Security Incident Response program: people, processes, tools.
  • Build tools, runbooks, and on-call processes that scale as the company grows.

What they require

  • 6+ years in security operations, detection engineering, or incident response — with at least 1–2 years leading or mentoring a team.
  • Deep hands-on experience with cloud-native environments (Kubernetes, Linux workloads, container-based infrastructure).
  • Strong detection engineering skills: writing and tuning rules/detections in SIEM platforms (e.g., Chronicle, Splunk, Elastic) and SQL.
  • Experience building or operating SOAR workflows and automating response at scale (ideally with Golang and Temporal).
  • Working knowledge of threat intelligence frameworks (MITRE ATT&CK, Pyramid of Pain, Kill Chain ) and how to operationalize them in detections.
  • Solid IR fundamentals: memory forensics, log analysis, network traffic analysis, and post-incident reporting.
  • Stakeholder management: able to coordinate across engineers, compliance, legal, executives during active incident phase.
  • Serve as the primary owner and driver for complex changes, as a result of incidents post-mortem.

Benefits

  • Competitive compensation
  • Career growth and learning opportunities
  • Flexibility and ownership
  • Collaborative and innovative culture
  • Opportunity to work on impactful AI projects
  • International environment and talented teams

Dutch company developing a portfolio of AI-related technology assets

🇳🇱 NetherlandsTechnology, Information And InternetMid-sizenebius.group/
Salary not disclosed