1,450,551open jobs
86,146companies
223,842added this week
Browse all
Salary
≈ $129k – $295k per year (Estimated)
Location
Remote (likely United States)also open in Austria, Belgium, Bulgaria, Croatia, Czech Republic, Denmark +25
Seniority
Staff · 6+ years exp
Employment
Full-Time

First seen by Alion on Oct 8, 2026.

Overview
Company
Impact
Profile match
Nebius is an international technology company that specializes in building full-stack artificial intelligence infrastructure and high-performance cloud GPU platforms for AI model development. Headquartered in Amsterdam, Netherlands, the firm operates energy-efficient data centers across Europe and North America to provide scalable compute, storage, and software tools for machine learning workloads.
About Nebius:

Nebius is leading a new era in cloud infrastructure for the global AI economy. We are building a full-stack AI cloud platform that supports developers and enterprises from data and model training through to production deployment, without the cost and complexity of building large in-house AI/ML infrastructure.

Built by engineers, for engineers. From large-scale GPU orchestration to inference optimization, we own the hard problems across compute, storage, networking and applied AI.

Listed on Nasdaq (NBIS) and headquartered in Amsterdam, we have a global footprint with R&D hubs across Europe, the UK, North America and Israel. Our team of 1,500+ includes hundreds of engineers with deep expertise across hardware, software and AI R&D.

Detection and Response

The team is responsible for detection engineering, threat intelligence, and incident response across Nebius Cloud. Its goal is to improve and maintain Nebius's security monitoring capabilities, as well as to build and maintain an end-to-end Security Incident Response program - people, processes, and tools.

The Role

We're hiring a Detection Engineering & Response Lead to build and run our D&R capability from the ground up. You'll own the detection engineering, threat intelligence, and incident response functions across Nebius Cloud - and lead a small, growing team of analysts and engineers.

This is a lead engineering role responsible for detection development, handling the most complex security incidents, forensics, and shaping the D&R strategy.

What you’ll do
  • Lead detection development: maintain low false-positive and false-negative rates. Work closely with alerts consumers (20+ teams) to keep noise low and signal high, ensuring they can act quickly without missing genuine threats
  • Architect and operate detection coverage across our cloud and bare-metal environments
  • Build and extend our internal D&R tools and pipelines - onboard new logs, build and automate response runbooks
  • Integrate threat intelligence into detection logic and IR playbooks, tracking adversary TTPs relevant to Cloud infrastructure
  • Lead incident response end-to-end: scoping, containment, root cause analysis, post-incident reviews and controlling critical action items are closed to prevent future possible incidents
  • Partner with Compliance and Engineering teams to detect real threats while meeting the needs of both engineers and regulators
  • Define and report on D&R metrics: MTTD, MTTR, detection coverage, false positive rates, etc
  • Build and maintain Security Incident Response program: people, processes, tools
  • Build tools, runbooks, and on-call processes that scale as the company grows
What we look for
  • 6+ years in security operations, detection engineering, or incident response — with at least 1–2 years leading or mentoring a team.
  • Deep hands-on experience with cloud-native environments (Kubernetes, Linux workloads, container-based infrastructure).
  • Strong detection engineering skills: writing and tuning rules/detections in SIEM Platforms (e.g., Chronicle, Splunk, Elastic) and SQL.
  • Experience building or operating SOAR workflows and automating response at scale (ideally with Golang and Temporal).
  • Working knowledge of threat intelligence frameworks (MITRE ATT&CK, Pyramid of Pain, Kill Chain) and how to operationalize them in detections.
  • Solid IR fundamentals: memory forensics, log analysis, network traffic analysis, and post-incident reporting.
  • Stakeholder management: able to coordinate across engineers, compliance, legal, executives during active incident phase. Serve as the primary owner and driver for complex changes, as a result of incidents post-mortem.
Nice to have:
  • Experience with AI/ML and GPU clusters related threats.
  • Familiarity with eBPF-based detection or runtime security tooling (Falco, Tetragon).
  • Background in threat hunting.
Why this role at Nebius
  • Build D&R at a company scaling from startup to global infrastructure provider in real time.
  • Opportunity to evolve our internal D&R platform into a new cloud security product, delivering novel security observability for a range of neocloud customers - from big tech to AI startups.
  • Work alongside world-class engineers on infrastructure that powers frontier AI.
  • Competitive compensation with equity upside in a Nasdaq-listed, high-growth company.
  • Flexible, remote-first culture.
Hiring Process
  • Recruiter's chat (30mins)
  • Live-coding interview (60mins) to asses basic coding skills
  • Security interview (60mins) to asses domain expertise
  • Incident Response interview (90mins) to assess practical experience
  • (Optional) Technical deep dive (90mins) to present a complex and impact project.
  • Final interview to close the hiring process (45mins)
Benefits & Perks:
  • Competitive compensation
  • Career growth and learning opportunities
  • Flexibility and ownership
  • Collaborative and innovative culture
  • Opportunity to work on impactful AI projects
  • International environment and talented teams
What's it like to work at Nebius:

Fast moving - Bold thinking - Constant growth - Meaningful impact - Trust and real ownership - Opportunity to shape the future of AI

Equal Opportunity Statement:

Nebius is an equal opportunity employer. We are committed to fostering an inclusive and diverse workplace and to providing equal employment opportunities in all aspects of employment. We do not discriminate on the basis of race, color, religion, sex (including pregnancy), national origin, ancestry, age, disability, genetic information, marital status, veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by applicable law.

Applicants must be authorized to work in the country in which they apply and will be required to provide proof of employment eligibility as a condition of hire.

If you need accommodations during the application process, please let us know.

Originally posted on Himalayas

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
1,450,551 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Security
Similar stack
Same company
In your city
≈ $136k – $329k per year (Estimated) • Remote (Europe) • 6+ years exp
Python
JavaScript
DevOps
CI/CD
Kubernetes
Linux
Cybersecurity
Burp Suite
Semgrep
OWASP Top 10
Threat Modeling
Apply
≈ $125k – $325k per year (Estimated) • Remote (Europe) • 6+ years exp
Python
AI/ML
vLLM
LLM
InfiniBand
Red Teaming
DevOps
SLURM
Kubernetes
eBPF
IAM
Cybersecurity
CVE
Threat Modeling
Apply
≈ $117k – $304k per year (Estimated) • Remote (Europe) • 6+ years exp
Go
SQL
DevOps
Splunk
Kubernetes
eBPF
Linux
Cybersecurity
Falco
Cyber Kill Chain
Cilium Tetragon
SIEM
Apply
≈ $24k – $60k per year (Estimated) • Remote (India) • 8+ years exp • India
Python
PowerShell
AI/ML
Agentic Workflows
DevOps
Azure
AWS
Kubernetes
Cybersecurity
Microsoft Sentinel
Microsoft Entra ID
Active Directory
SIEM
Management
Telegram
Apply
≈ $26k – $64k per year (Estimated) • Remote (India) • 10+ years exp • India
AI/ML
LLM Guardrails
Agentic Workflows
DevOps
Azure
AWS
Kubernetes
Cybersecurity
ISO 27001
SOC 2
FedRAMP
Management
Telegram
Apply
$168k – $227k per year • In office • Full-Time • 8+ years exp • Bachelor's Degree • Mountain View
SQL
DevOps
Splunk
Management
Agile
ITIL
Apply
≈ $44k – $74k per year (Estimated) • Hybrid • Guyancourt
Java
Java
Apache Tomcat
DevOps
Ansible
Dynatrace
GitLab CI
CI/CD
Windows Server
Jenkins
Kubernetes
Linux
Windows
Unix
Apply
$11k – $16k per year • In office • Full-Time • Sandton
SQL
C#
C#
.NET
Apply
$54k – $104k per year • Equity • Hybrid • Full-Time • 4+ years exp • Bachelor's Degree • San Francisco
SQL
Management
Confluence
Jira
Agile
Apply
$68k – $140k per year • Equity • Hybrid • Full-Time • 7+ years exp • Bachelor's Degree • San Francisco
SQL
Management
Confluence
Jira
Agile
Apply
≈ $129k – $295k per year (Estimated) • Remote (likely United States) • Full-Time • 6+ years exp
Go
SQL
DevOps
Splunk
Kubernetes
eBPF
Linux
Cybersecurity
Falco
Cyber Kill Chain
Cilium Tetragon
SIEM
Apply
≈ $131k – $273k per year (Estimated) • Remote (likely United States) • Full-Time • 6+ years exp
Python
AI/ML
vLLM
LLM
InfiniBand
Red Teaming
DevOps
SLURM
Kubernetes
eBPF
IAM
Cybersecurity
CVE
Threat Modeling
Apply
≈ $41k – $118k per year (Estimated) • Remote (likely Europe) • Full-Time • 2+ years exp • Amsterdam
Python
PowerShell
DevOps
Azure DevOps
Cybersecurity
Microsoft Sentinel
GDPR
Microsoft Entra ID
SIEM
DLP
Apply
$224k – $270k per year • Remote (United States) • Full-Time
Chips/EDA
PoC Library
Management
Jira
Apply
$130k – $180k per year • Hybrid • Full-Time • Berlin
Python
Bash
DevOps
CI/CD
Linux
Apply
See all jobs
This is one of many
1,450,551 more open roles from verified company boards, updated every day.