Detection & Response Lead

Nebius · Remote - Europe · Other

Posted 2026-10-06

Apply for this role →

Detection and Response

The team is responsible for detection engineering, threat intelligence, and incident response across Nebius Cloud. Its goal is to improve and maintain Nebius's security monitoring capabilities, as well as to build and maintain an end-to-end Security Incident Response program - people, processes, and tools.

The Role

We're hiring a Detection Engineering & Response Lead to build and run our D&R capability from the ground up. You'll own the detection engineering, threat intelligence, and incident response functions across Nebius Cloud - and lead a small, growing team of analysts and engineers.

This is a lead engineering role responsible for detection development, handling the most complex security incidents, forensics, and shaping the D&R strategy.

What you’ll do

Lead detection development: maintain low false-positive and false-negative rates. Work closely with alerts consumers (20+ teams) to keep noise low and signal high, ensuring they can act quickly without missing genuine threats

Architect and operate detection coverage across our cloud and bare-metal environments

Build and extend our internal D&R tools and pipelines - onboard new logs, build and automate response runbooks

Integrate threat intelligence into detection logic and IR playbooks, tracking adversary TTPs relevant to Cloud infrastructure

Lead incident response end-to-end: scoping, containment, root cause analysis, post-incident reviews and controlling critical action items are closed to prevent future possible incidents

Partner with Compliance and Engineering teams to detect real threats while meeting the needs of both engineers and regulators

Define and report on D&R metrics: MTTD, MTTR, detection coverage, false positive rates, etc

Build and maintain Security Incident Response program: people, processes, tools

Build tools, runbooks, and on-call processes that scale as the company grows

What we look for

6+ years in security operations, detection engineering, or incident response — with at least 1–2 years leading or mentoring a team.

Deep hands-on experience with cloud-native environments (Kubernetes, Linux workloads, container-based infrastructure).

Strong detection engineering skills: writing and tuning rules/detections in SIEM Platforms (e.g., Chronicle, Splunk, Elastic) and SQL.

Experience building or operating SOAR workflows and automating response at scale (ideally with Golang and Temporal).

Working knowledge of threat intelligence frameworks (MITRE ATT&CK, Pyramid of Pain, Kill Chain) and how to operationalize them in detections.

Solid IR fundamentals: memory forensics, log analysis, network traffic analysis, and post-incident reporting.

Stakeholder management: able to coordinate across engineers, compliance, legal, executives during active incident phase. Serve as the primary owner and driver for complex changes, as a result of incidents post-mortem.

Nice to have:

Experience with AI/ML and GPU clusters related threats.

Familiarity with eBPF-based detection or runtime security tooling (Falco, Tetragon).

Background in threat hunting.

Why this role at Nebius

Build D&R at a company scaling from startup to global infrastructure provider in real time.

Opportunity to evolve our internal D&R platform into a new cloud security product, delivering novel security observability for a range of neocloud customers - from big tech to AI startups.

Work alongside world-class engineers on infrastructure that powers frontier AI.

Competitive compensation with equity upside in a Nasdaq-listed, high-growth company.

Flexible, remote-first culture.

Hiring Process

Recruiter's chat (30mins)

Live-coding interview (60mins) to asses basic coding skills

Security interview (60mins) to asses domain expertise

Incident Response interview (90mins) to assess practical experience

(Optional) Technical deep dive (90mins) to present a complex and impact project.

Final interview to close the hiring process (45mins)

Apply for this role →

← Back to all jobs