Skip to main content
Nebius

Offensive Security Lead

RemoteEurope
Published
Role
Security
Experience
Lead
Company size
Enterprise
Salary not disclosed
Check eligibility

Open to Anywhere in Europe. Set where you work from to check your eligibility.

No BS summary

Offensive security lead with 6+ years in pentesting/red teaming/adversary simulation and 1–2 years leading or mentoring. Must know cloud-native attacks, Kubernetes privilege escalation, cloud IAM abuse, virtualization/container escapes, and Python/Go-style custom tooling. Remote Europe, with authorization to work in the country of application.

Core skills

KubernetesRed teamingPenetration testing

Required skills

cloud IAMPython/Go

Optional skills

ML infrastructuremodel serving pipelinesGPU clustersreverse engineeringexploit developmentapplication securityeBPFkernel-level exploitation

What you'll do

  • Build and lead a red team function within the Product Security Team, including hiring and developing offensive security engineers.
  • Validate and extend early-stage Secure SDLC threat models via continuous penetration testing.
  • Assess threat severity and mitigation status while challenging assumptions made during threat modeling and system development.
  • Automate routine validations to keep pace with increasing feature flow, reserving manual analysis for complex cases.
  • Plan and execute full-scoped red team engagements against the Nebius cloud platform, including compute, storage, inference, networking, orchestration layers, and internal tooling.
  • Identify threats able to impact the organization's operations.
  • Work with Detection & Response and other security engineering teams to run purple team exercises, validate detection coverage, and close gaps.
  • Research novel attacks against GPU infrastructure, inference stack, and AI platform managed services.
  • Assess tenant-isolation boundaries and how they can be broken at the low-level stack.
  • Conduct targeted assessments of new products and infrastructure changes before they ship.
  • Deliver clear, actionable reports for technical audiences and leadership with prioritized findings and remediation guidance.
  • Establish red team processes, tooling, and methodology that scales as the platform grows.

What they require

  • 6+ years in offensive security, penetration testing, red teaming, or adversary simulation.
  • At least 1–2 years leading or mentoring a team.
  • Deep experience attacking cloud-native environments, including Kubernetes privilege escalation, cloud IAM abuse, virtualization and container escapes.
  • Strong fundamentals across the attack lifecycle: initial access, persistence, lateral movement, and data exfiltration.
  • Proficiency developing custom tooling and post-exploitation capabilities in Python, Go, or similar.
  • Experience running purple team exercises and working constructively with blue teams.
  • Ability to write clear, senior-level reports with business-contextualized risk that engineers can easily use.
  • Preferred: Experience attacking ML infrastructure, model serving pipelines, or GPU clusters.
  • Preferred: Reverse engineering and exploit development experience.
  • Preferred: Application security experience.
  • Preferred: Familiarity with eBPF bypass techniques or kernel-level exploitation.
  • Preferred: Background in vulnerability research or CVE discovery.
  • Preferred: Experience with cloud provider internals such as hypervisor or networking layers.
  • Preferred: Presenting security research at conferences like BlackHat or DefCon.
  • Applicants must be authorized to work in the country in which they apply and provide proof of employment eligibility as a condition of hire.

Benefits

  • Competitive compensation.
  • Equity upside in a Nasdaq-listed, high-growth company.
  • Career growth and learning opportunities.
  • Flexibility and ownership.
  • Collaborative and innovative culture.
  • Opportunity to work on impactful AI projects.
  • International environment and talented teams.
  • Flexible, remote-first culture.
  • Opportunity to build a red team from scratch at a company operating frontier AI infrastructure.
  • Novel attack surface including GPU clusters, AI platforms, and multi-tenant cloud at scale.
  • Work alongside world-class engineers on infrastructure that powers frontier AI.

Dutch company developing a portfolio of AI-related technology assets

🇳🇱 NetherlandsTechnology, Information And InternetMid-sizenebius.group/

Details

Apply routeDom
Salary not disclosed