Skip to main content
Nebius

Vulnerability Operation Center Lead

RemoteEurope
Published
Role
Security
Experience
Lead
Company size
Enterprise
Salary not disclosed
Check eligibility

Open to Anywhere in Europe. Set where you work from to check your eligibility.

No BS summary

Lead-level security practitioner with 5–8 years in information security and 3+ years in vulnerability management or security operations. Must know cloud vulnerability management, CVE/NVD, CVSS, EPSS, SSVC, scanners, remediation workflows, and be able to write/review code; Europe remote and work authorization in the country of application required.

Core skills

Vulnerability managementVulnerability triageCloud security

Required skills

Vulnerability scanning toolsCVENVDCVSSEPSSSSVCAWS/GCP/AzureGo

Optional skills

KubernetesSBOMsDependency scanning

What you'll do

  • Own the full vulnerability management lifecycle from detection through triage to remediation tracking and reporting across Nebius' cloud infrastructure, product and hardware stack.
  • Define vulnerability management processes.
  • Select vulnerability management tooling.
  • Work directly with engineering teams.
  • Set the standard for how Nebius responds to vulnerabilities.
  • Improve and maintain automated vulnerability triaging capabilities and vulnerability data quality through data enrichment, quality metrics, AI-assisted triage, context-aware risk scoring, and vulnerability correlation/chaining.
  • Perform hands-on validation and triaging of the most critical and zero-day vulnerabilities.
  • Work closely with vulnerability data consumers and stakeholders across the organization to meet engineering, compliance, and regulatory requirements.
  • Deliver high-quality, actionable findings and drive effective remediation.
  • Contribute to internal platforms including the Unified Vulnerability Management system and the security orchestration platform to automate core vulnerability management workflows and reduce manual effort.
  • Identify deficiencies in patch management.
  • Drive and oversee patch management improvements across engineering teams and business units to improve remediation efficiency and reduce organizational risk.
  • Own vulnerability intake from scanners, bug bounty, threat intelligence feeds, and penetration tests.
  • Prioritize findings using risk-based frameworks including CVSS, EPSS, SSVC, asset criticality, exploitability context, and business impact.
  • Reduce false positive noise.
  • Drive remediation accountability across infrastructure, platform, and product engineering teams.
  • Identify, track and report vulnerability management metrics.
  • Present KPIs and trends to security leadership.
  • Coordinate response to critical and zero-day vulnerabilities as the primary point of contact across security, engineering, and operations.
  • Define and maintain integration between VOC tooling and the broader security ecosystem.
  • Build a Platform Security Vulnerability program from scratch.
  • Build and lead your own team.

What they require

  • 5–8 years in information security with at least 3 years focused on vulnerability management or security operations.
  • Deep familiarity with vulnerability scanning tools and their strengths and limitations in cloud-native environments.
  • Strong grasp of CVE/NVD, CVSS scoring, EPSS, SSVC and how to apply them to real-world prioritization.
  • Experience managing vulnerabilities across IaaS/cloud infrastructure such as AWS, GCP, Azure, or private cloud.
  • Deep understanding of vulnerability source limitations and corner cases for different vulnerability classes.
  • Able to write and review code well enough to assess exploitability, validate fixes, and build lightweight automation such as variant-detection scripts, triage tooling, and data pipelines for trend analysis.
  • Ability or willingness to develop in Golang.
  • Strong grasp of common vulnerability classes at the code and infrastructure level.
  • Comfortable feeding well-documented vulnerability patterns into AI-assisted code review workflows and critically evaluating the output.
  • Track record of working cross-functionally with engineering teams and holding stakeholders accountable to timelines without being a bottleneck.
  • Strong written and verbal communication; able to translate technical risk into business impact for non-security audiences.
  • Preferred: Experience with GPU/HPC environments.
  • Preferred: Experience building a vulnerability management program from scratch.
  • Preferred: Experience with container and Kubernetes security.
  • Preferred: Experience with supply chain security such as SBOMs and dependency scanning.
  • Preferred: Bug bounty triage experience.
  • Preferred: Public talks or research articles.
  • Applicants must be authorized to work in the country in which they apply and will be required to provide proof of employment eligibility as a condition of hire.

Benefits

  • Competitive compensation.
  • Equity upside in a Nasdaq-listed, high-growth company.
  • Career growth and learning opportunities.
  • Flexibility and ownership.
  • Collaborative and innovative culture.
  • Opportunity to work on impactful AI projects.
  • International environment and talented teams.
  • Flexible, remote-first culture.
  • Work alongside world-class engineers on infrastructure that powers frontier AI.
  • Potential to evolve an in-house AI-powered vulnerability management platform into a cloud security offering for Nebius customers.
  • Fast moving environment.
  • Bold thinking.
  • Constant growth.
  • Meaningful impact.
  • Trust and real ownership.
  • Opportunity to shape the future of AI.

Dutch company developing a portfolio of AI-related technology assets

🇳🇱 NetherlandsTechnology, Information And InternetMid-sizenebius.group/

Details

Apply routeDom
Salary not disclosed