Detection Engineering & Response Lead @Nebius
All Others
Salary unspecified
Employment Type full-time
Posted YDay

[Hiring] Detection Engineering & Response Lead @Nebius

YDay - Nebius is hiring a remote Detection Engineering & Response Lead. πŸ’Έ Salary: unspecified πŸ“Location: Northern America, Europe, Western Asia (Middle East)

Role Description

The Detection Engineering & Response Lead will build and run our D&R capability from the ground up. You'll own the detection engineering, threat intelligence, and incident response functions across Nebius Cloud and lead a small, growing team of analysts and engineers.

  • Lead detection development: maintain low false-positive and false-negative rates.
  • Work closely with alerts consumers (20+ teams) to keep noise low and signal high, ensuring they can act quickly without missing genuine threats.
  • Architect and operate detection coverage across our cloud and bare-metal environments.
  • Build and extend our internal D&R tools and pipelines - onboard new logs, build and automate response runbooks.
  • Integrate threat intelligence into detection logic and IR playbooks, tracking adversary TTPs relevant to Cloud infrastructure.
  • Lead incident response end-to-end: scoping, containment, root cause analysis, post-incident reviews, and controlling critical action items are closed to prevent future possible incidents.
  • Partner with Compliance and Engineering teams to detect real threats while meeting the needs of both engineers and regulators.
  • Define and report on D&R metrics: MTTD, MTTR, detection coverage, false positive rates, etc.
  • Build and maintain Security Incident Response program: people, processes, tools.
  • Build tools, runbooks, and on-call processes that scale as the company grows.

Qualifications

  • 6+ years in security operations, detection engineering, or incident response β€” with at least 1–2 years leading or mentoring a team.
  • Deep hands-on experience with cloud-native environments (Kubernetes, Linux workloads, container-based infrastructure).
  • Strong detection engineering skills: writing and tuning rules/detections in SIEM Platforms (e.g., Chronicle, Splunk, Elastic) and SQL.
  • Experience building or operating SOAR workflows and automating response at scale (ideally with Golang and Temporal).
  • Working knowledge of threat intelligence frameworks (MITRE ATT&CK, Pyramid of Pain, Kill Chain) and how to operationalize them in detections.
  • Solid IR fundamentals: memory forensics, log analysis, network traffic analysis, and post-incident reporting.
  • Stakeholder management: able to coordinate across engineers, compliance, legal, executives during active incident phase.

Requirements

  • Experience with AI/ML and GPU clusters related threats (nice to have).
  • Familiarity with eBPF-based detection or runtime security tooling (Falco, Tetragon) (nice to have).
  • Background in threat hunting (nice to have).

Benefits

  • Competitive compensation.
  • Career growth and learning opportunities.
  • Flexibility and ownership.
  • Collaborative and innovative culture.
  • Opportunity to work on impactful AI projects.
  • International environment and talented teams.
Before You Apply
️
remote Be aware of the location restriction for this remote position: Northern America, Europe, Western Asia (Middle East)
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Detection Engineering & Response Lead @Nebius
All Others
Salary unspecified
Employment Type full-time
Posted YDay
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 125,000+ Remote Jobs
️
remote Be aware of the location restriction for this remote position: Northern America, Europe, Western Asia (Middle East)
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 125,000+ Remote Jobs
Γ—
Apply to the best remote jobs
before everyone else

Access 125,000+ vetted remote jobs and get daily alerts.

4.9 β˜…β˜…β˜…β˜…β˜… from 500+ reviews

⚑ 129,494+ remote jobs, refreshed hourly

πŸ”” Real-time alerts: Apply first, direct to employer

πŸ›‘οΈ Vetted companies, no scams, true remote only

Unlock All Jobs Now

Maybe later