Security Analyst - Tier 3
The role
Nebius is seeking a deeply experienced Security Analyst - Tier 3 for its Security Operations Center (SOC). This role is a senior individual-contributor position, leading challenging investigations, setting the standards the SOC operates by. This role reports to the SOC Manager, under the Detection and Response function within the CISO Office.
Your responsibilities will include:
Lead complex, multi-stage, multi-domain investigations end to end, from scoping through deep technical analysis to a clear determination of impact and root cause.
Serve as the SOC's senior escalation point and the quality gate for investigations across the team.
Support the Incident Response team during confirmed incidents with continued telemetry investigation, scoping, and analytical depth.
Continuously sharpen how the SOC investigates, identifying gaps in methods, runbooks, and tooling through daily casework and turning them into concrete improvements.
Mentor Tier 1 and Tier 2 analysts through case reviews, coaching, and pairing during investigations.
Partner with Security Engineering, Platform Security, Threat Intelligence, SOC Automation, and additional teams to turn what the SOC learns into stronger detection and response across Nebius.
Participate in readiness activities - tabletops, post-incident reviews, and purple-team engagements.
Participate in the on-call rotation as the senior point of contact outside business hours.
We expect you to have:
Experience
Around 8-10 years of hands-on experience in security operations or incident response, with a track record of leading complex investigations.
Technical Expertise
Expert-level investigation capability across multiple domains: endpoint, identity, cloud, and network.
Solid understanding of cloud-native environments, including containers, Kubernetes.
Deep practical fluency with EDR, SIEM query languages, and log analysis.
Deep knowledge of Windows and Linux internals, applied to artifact and behavioral analysis.
Fluency in attacker TTPs (MITRE ATT&CK), including the Cloud and Containers matrices.
Strong scripting and data-analysis skills (Python, SQL/KQL) for investigation at scale, with the ability to validate findings independently and challenge assumptions.
Advanced certifications such as GCIH, GCFA, GNFA, GCFE, or OSCP are an advantage.
Leadership & Communication
Technical leadership through credibility, raising the team's bar without relying on formal authority.
Calm and structured during high-severity incidents, making sound decisions amid uncertainty.
Excellent written communication, turning complex investigations to clear narratives others can act on.
Fluent in English, written and verbal, comfortable working with international teams and stakeholders.