Nebius logo

Nebius

Lead Detection Engineer at Nebius

IsraelFull-timeCEO & CSO OfficePosted 3 months ago
Apply with Pipeline

About the Role

<div class="content-intro"><p><strong>About Nebius:</strong></p> <p>Nebius is leading a new era in cloud infrastructure for the global AI economy. We are building a full-stack AI cloud platform that supports developers and enterprises from data and model training through to production deployment, without the cost and complexity of building large in-house AI/ML infrastructure.</p> <p>Built by engineers, for engineers. From large-scale GPU orchestration to inference optimization, we own the hard problems across compute, storage, networking and applied AI.</p> <p>Listed on Nasdaq (NBIS) and headquartered in Amsterdam, we have a global footprint with R&amp;D hubs across Europe, the UK, North America and Israel. Our team of 1,500+ includes hundreds of engineers with deep expertise across hardware, software and AI R&amp;D.</p></div><h3><strong><span data-ccp-props="{}">The role</span></strong></h3> <p><span data-ccp-props="{}">Nebius is looking for a Lead Detection Engineer.<span class="TextRun SCXW227745913 BCX0" lang="EN-US" data-contrast="none"><span class="NormalTextRun SCXW227745913 BCX0">This is&nbsp;</span><span class="NormalTextRun ContextualSpellingAndGrammarErrorV2Themed SCXW227745913 BCX0">an</span><span class="NormalTextRun SCXW227745913 BCX0">&nbsp;individual contributor role with full technical ownership.&nbsp;</span><span class="NormalTextRun SCXW227745913 BCX0">You'll</span><span class="NormalTextRun SCXW227745913 BCX0">&nbsp;set the direction for detection engineering: the standards, the tooling, the coverage strategy, and the automation that operationalizes it all.&nbsp;</span><span class="NormalTextRun SCXW227745913 BCX0">You'll</span><span class="NormalTextRun SCXW227745913 BCX0"> work closely with SOC analysts and Platform Engineering to make detection a first-class engineering discipline.</span></span></span></p> <p><span data-ccp-props="{}">You’re welcome to work in our offices in Tel Aviv, Israel</span></p> <p><strong><span data-contrast="auto"><span data-ccp-charstyle="Strong">Your responsibilities will include:</span></span></strong><span data-ccp-props="{&quot;134233117&quot;:true,&quot;134233118&quot;:true}">&nbsp;</span></p> <ul> <li><span data-contrast="none">Detection coverage strategy across endpoint, identity, cloud, and infrastructure — how&nbsp;it's&nbsp;measured, prioritized, and continuously improved.</span><span data-ccp-props="{&quot;201341983&quot;:2,&quot;335559740&quot;:276}">&nbsp;</span></li> <li><span data-contrast="none">Detection-as-Code pipeline: version control, testing, peer review, CI/CD, and deployment practices for all detection logic.</span><span data-ccp-props="{&quot;201341983&quot;:2,&quot;335559740&quot;:276}">&nbsp;</span></li> <li><span data-contrast="none">Architecture connecting detections to enrichment, triage, and automated response workflows.</span><span data-ccp-props="{&quot;201341983&quot;:2,&quot;335559740&quot;:276}">&nbsp;</span></li> <li><span data-contrast="none">Technical standards for how detections are designed, tested, documented, deployed, and retired.</span><span data-ccp-props="{&quot;201341983&quot;:2,&quot;335559740&quot;:276}">&nbsp;</span></li> <li><span data-contrast="none">Detection quality: fidelity metrics, false positive reduction, coverage measurement, and continuous validation loops.</span><span data-ccp-props="{&quot;201341983&quot;:2,&quot;335559740&quot;:276}">&nbsp;</span></li> <li><span data-contrast="none">Design and build high-fidelity behavioral detections across SIEM and EDR platforms.</span><span data-ccp-props="{&quot;201341983&quot;:2,&quot;335559740&quot;:276}">&nbsp;</span></li> <li><span data-contrast="none">Research emerging attacker techniques and translate threat intelligence into scalable, evasion-resistant detections.</span><span data-ccp-props="{&quot;201341983&quot;:2,&quot;335559740&quot;:276}">&nbsp;</span></li> <li><span data-contrast="none">Validate detections through threat simulations and continuous detection testing.</span><span data-ccp-props="{&quot;201341983&quot;:2,&quot;335559740&quot;:276}">&nbsp;</span></li> <li><span data-contrast="none">Partner with SOC analysts to close the feedback loop between detections and real investigations.</span><span data-ccp-props="{&quot;201341983&quot;:2,&quot;335559740&quot;:276}">&nbsp;</span></li> <li><span data-contrast="none">Define and track detection engineering metrics; communicate&nbsp;coverage&nbsp;posture and effectiveness to security leadership.</span><span data-ccp-props="{&quot;201341983&quot;:2,&quot;335559740&quot;:276}">&nbsp;</span></li> <li><span data-contrast="none">Make architectural decisions that scale as the team and organization grow.</span><span data-ccp-props="{&quot;201341983&quot;:2,&quot;335559740&quot;:276}">&nbsp;</span></li> </ul> <p><strong><span data-contrast="auto"><span data-ccp-charstyle="Strong">We expect you to have:</span></span></strong><span data-ccp-props="{&quot;134233117&quot;:true,&quot;134233118&quot;:true}">&nbsp;</span></p> <ul> <li><span data-contrast="none">Minimum 3 years in detection engineering, security operations, or a hybrid offensive/defensive role — with&nbsp;demonstrated&nbsp;depth, not just breadth.</span><span data-ccp-props="{&quot;201341983&quot;:2,&quot;335559740&quot;:276}">&nbsp;</span></li> <li><span data-contrast="none">Experience owning or leading detection engineering work as a senior technical contributor</span><span data-ccp-props="{&quot;201341983&quot;:2,&quot;335559740&quot;:276}">&nbsp;</span></li> <li><span data-contrast="none">Strong understanding of attacker tradecraft and adversary behavior.</span><span data-ccp-props="{&quot;201341983&quot;:2,&quot;335559740&quot;:276}">&nbsp;</span></li> <li><span data-contrast="none">Hands-on experience with at least one enterprise SIEM and EDR platform — Splunk, Microsoft Sentinel, CrowdStrike, or equivalent.</span><span data-ccp-props="{&quot;201341983&quot;:2,&quot;335559740&quot;:276}">&nbsp;</span></li> <li><span data-contrast="none">Cloud security depth across Azure, AWS, or GCP.</span><span data-ccp-props="{&quot;201341983&quot;:2,&quot;335559740&quot;:276}">&nbsp;</span></li> <li><span data-contrast="none">Strong query development skills in SPL, KQL, Sigma, or similar.</span><span data-ccp-props="{&quot;201341983&quot;:2,&quot;335559740&quot;:276}">&nbsp;</span></li> <li><span data-ccp-props="{&quot;201341983&quot;:2,&quot;335559740&quot;:276}">Strong scripting skills (python, powershell etc)</span></li> <li><span data-contrast="none">Solid engineering practices: Git, CI/CD, code review, Detection-as-Code workflows.</span><span data-ccp-props="{&quot;201341983&quot;:2,&quot;335559740&quot;:276}">&nbsp;</span></li> <li><span data-contrast="none">Experience using MITRE ATT&amp;CK to design,&nbsp;validate, and measure detection coverage  </span><span data-ccp-props="{&quot;201341983&quot;:2,&quot;335559740&quot;:276}">&nbsp;</span></li> <li><span data-contrast="none">Ability to make and defend technical decisions and&nbsp;establish&nbsp;standards others adopt.</span><span data-ccp-props="{&quot;201341983&quot;:2,&quot;335559740&quot;:276}">&nbsp;</span></li> </ul> <p><strong><span data-contrast="auto"><span data-ccp-charstyle="Strong">It will be an added bonus if you have:</span></span></strong><span data-ccp-props="{&quot;134233117&quot;:true,&quot;134233118&quot;:true}">&nbsp;</span></p> <ul> <li><span data-contrast="none">Offensive security background or certifications.</span><span data-ccp-props="{&quot;201341983&quot;:2,&quot;335559740&quot;:276}">&nbsp;</span></li> <li><span data-contrast="none">Experience with threat hunting and detection validation frameworks.</span><span data-ccp-props="{&quot;201341983&quot;:2,&quot;335559740&quot;:276}">&nbsp;</span></li> <li><span data-contrast="none">Experience designing SOAR playbooks and automated response workflows.</span><span data-ccp-props="{&quot;201341983&quot;:2,&quot;335559740&quot;:276}">&nbsp;</span></li> <li><span data-contrast="none">Experience building AI-assisted detection, investigation, or triage workflows.</span><span data-ccp-props="{&quot;201341983&quot;:2,&quot;335559740&quot;:276}">&nbsp;</span></li> </ul><div class="content-conclusion"><p><strong>Benefits &amp; Perks:</strong></p> <ul> <li>Competitive compensation</li> <li>Career growth and learning opportunities</li> <li>Flexibility and ownership</li> <li>Collaborative and innovative culture</li> <li>Opportunity to work on impactful AI projects</li> <li>International environment and talented teams</li> </ul> <p><strong>What's it like to work at Nebius:</strong></p> <p>Fast moving&nbsp;- Bold thinking&nbsp;- Constant growth&nbsp;- Meaningful impact&nbsp;- Trust and real ownership&nbsp;- Opportunity to shape the future of AI&nbsp;</p> <p><strong>Equal Opportunity Statement:</strong></p> <p>Nebius is an equal opportunity employer. We are committed to fostering an inclusive and diverse workplace and to providing equal employment opportunities in all aspects of employment. We do not discriminate on the basis of race, color, religion, sex (including pregnancy), national origin, ancestry, age, disability, genetic information, marital status, veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by applicable law.</p> <p>Applicants must be authorized to work in the country in which they apply and will be required to provide proof of employment eligibility as a condition of hire.&nbsp;</p> <p>If you need accommodations during the application process, please let us know.</p></div>