Detection & Response Lead @Nebius
All Others
Salary unspecified
Remote Location
Employment Type full-time
Posted 2mths ago

[Hiring] Detection & Response Lead @Nebius

2mths ago - Nebius is hiring a remote Detection & Response Lead. πŸ’Έ Salary: unspecified πŸ“Location: Worldwide

Role Description

We're hiring a Detection & Response Lead to build and run our D&R capability from the ground up. You'll own the detection engineering, threat intelligence, and incident response functions across Nebius Cloud and lead a small, growing team of analysts and engineers. This is a lead engineering role responsible for:

  • Detection development: achieve full MITRE coverage, maintain low false-positive and false-negative rates.
  • Working closely with alerts consumers (20+ teams) to keep noise low and signal high, ensuring they can act quickly without missing genuine threats.
  • Architecting and operating detection coverage across our cloud and bare-metal environments.
  • Building and extending our internal D&R tools and pipelines - onboarding new logs, building and automating response runbooks.
  • Integrating threat intelligence into detection logic and IR playbooks, tracking adversary TTPs relevant to Cloud infrastructure.
  • Leading incident response end-to-end: scoping, containment, root cause analysis, post-incident reviews, and controlling critical action items to prevent future incidents.
  • Partnering with Compliance and Engineering teams to detect real threats while meeting the needs of both engineers and regulators.
  • Defining and reporting on D&R metrics: MTTD, MTTR, detection coverage, false positive rates, etc.
  • Building and maintaining the Security Incident Response program: people, processes, tools.
  • Building tools, runbooks, and on-call processes that scale as the company grows.

Qualifications

  • 6+ years in security operations, detection engineering, or incident response β€” with at least 1–2 years leading or mentoring a team.
  • Deep hands-on experience with cloud-native environments (Kubernetes, Linux workloads, container-based infrastructure).
  • Strong detection engineering skills: writing and tuning rules/detections in SIEM platforms (e.g., Chronicle, Splunk, Elastic) and SQL.
  • Experience building or operating SOAR workflows and automating response at scale (ideally with Golang and Temporal).
  • Working knowledge of threat intelligence frameworks (MITRE ATT&CK, Pyramid of Pain, Kill Chain) and how to operationalize them in detections.
  • Solid IR fundamentals: memory forensics, log analysis, network traffic analysis, and post-incident reporting.
  • Stakeholder management: able to coordinate across engineers, compliance, legal, executives during active incident phase.

Requirements

  • Experience with AI/ML and GPU clusters related threats (nice to have).
  • Familiarity with eBPF-based detection or runtime security tooling (Falco, Tetragon) (nice to have).
  • Background in threat hunting (nice to have).

Benefits

  • Competitive compensation with equity upside in a Nasdaq-listed, high-growth company.
  • Flexible, remote-first culture.
  • Career growth and learning opportunities.
  • Flexibility and ownership.
  • Collaborative and innovative culture.
  • Opportunity to work on impactful AI projects.
  • International environment and talented teams.
Before You Apply
️
worldwide Be aware of the location restriction for this remote position: Worldwide
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Detection & Response Lead @Nebius
All Others
Salary unspecified
Remote Location
Employment Type full-time
Posted 2mths ago
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 120,000+ Remote Jobs
️
worldwide Be aware of the location restriction for this remote position: Worldwide
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 120,000+ Remote Jobs
Γ—
Apply to the best remote jobs
before everyone else

Access 120,000+ vetted remote jobs and get daily alerts.

4.9 β˜…β˜…β˜…β˜…β˜… from 500+ reviews

⚑ 124,125+ remote jobs, refreshed hourly

πŸ”” Real-time alerts: Apply first, direct to employer

πŸ›‘οΈ Vetted companies, no scams, true remote only

Unlock All Jobs Now

Maybe later