Nebius
Detection Engineering & Response Lead
Posted
3 weeks ago
Experience
6+ Years
Deadline
Closed
Job Summary
The Detection Engineering & Response Lead builds, optimizes, and coordinates Nebius Cloud’s end-to-end threat visibility and incident resolution ecosystem. Core daily duties include engineering advanced, low-noise detection metrics mapped to the MITRE ATT&CK grid across cloud and bare-metal fabrics, scripting automated SOAR pipelines, executing memory and log forensics during highly complex security threats, tracking cloud-infrastructure adversaries, and leading comprehensive post-incident remediation strategies across engineering teams.
Foundational Experience & Security Prerequisites
- Verifiable Security Tenure: Minimum of 6+ years of professional experience operating within dedicated security operations centers (SOC), detection engineering teams, or active incident response environments.
- Engineering Leadership Blueprint: Minimum of 1–2 years of formal experience leading, mentoring, or scaling a technical team of security engineers or analysts.
- Cloud-Native Architecture Depth: Extensive, deep hands-on security experience navigating cloud-native platforms, including Kubernetes complexes, production Linux workloads, and large-scale containerized microservice architectures.
- Advanced Detection Engineering: Expert proficiency in parsing, indexing, writing, and tuning telemetry detection rules inside enterprise SIEM systems (e.g., Chronicle, Splunk, Elastic) along with expert fluency in structured data modeling via SQL.
- Response Orchestration & Automation: Practical experience building, operating, and configuring Security Orchestration, Automation, and Response (SOAR) playbooks and multi-tool pipelines at scale. Strong architectural familiarity with automated workflow engines—ideally utilizing Golang and Temporal—is highly valued.
- Threat Framework Literacy: Comprehensive knowledge of modern threat intelligence conceptual models (including the MITRE ATT&CK framework, the Pyramid of Pain, and Cyber Kill Chain mechanics) with a proven ability to translate abstract indicators of compromise (IoCs) into precise telemetry rules.
- High-Fidelity Incident Response: Strong foundational skills in primary incident forensics, encompassing volatile memory forensics, deep log analysis, network packet traffic parsing, and technical root-cause reporting.
- Executive Stakeholder Presence: Exceptional communication habits with a proven capacity to single-handedly steer cross-functional incident response phases across internal software teams, legal counsel, regulatory compliance directors, and executive leaders.
- Regulatory Authorization: Applicants must be legally authorized to work in their country of application within Europe at the time of hire.
Preferred Technical Multipliers
- Specialized Infrastructure Security: Direct experience defending against security vectors unique to AI/ML platforms, massive GPU clusters, or distributed model training pipelines.
- Advanced Runtime Telemetry: Hands-on experience deploying or managing eBPF-based runtime security monitoring systems and specialized Linux kernel auditing utilities (such as Falco or Tetragon).
- Active Threat Hunting: A documented professional background executing proactive, hypothesis-driven threat hunting loops inside large-scale production cloud systems.
Key Responsibilities
1. Detection Architecture Leadership & Framework Calibration
- Architect, build, and continuously refine an enterprise detection strategy across Nebius’s multi-tenant cloud fabrics and bare-metal environments to ensure complete MITRE ATT&CK matrix visibility.
- Write, test, and tune high-fidelity detection rules to minimize alert fatigue, systematically driving down false-positive numbers while keeping false-negative risks at near-zero parameters.
- Partner directly with over 20+ distinct engineering alert-consumer segments to optimize notification loops, keeping structural signal data high and operational noise low.
2. Autonomous SOAR Engineering & Log Lifecycle Strategy
- Build, expand, and maintain internal D&R pipelines, identifying and onboarding novel telemetry data streams, cluster logs, and system metrics safely.
- Design and code automated mitigation and containment workflows inside the SOAR platform to ensure instant isolation of compromised cloud compute primitives or container nodes.
- Establish repeatable, highly scalable on-call rotation processes, runbooks, and alerting playbooks that grow alongside Nebius’s multi-region system footprint.
3. End-to-End Incident Response & Threat Hunting Governance
- Manage the lifecycle of complex security incidents end-to-end, steering rapid scoping, definitive blast-radius containment, technical forensics, and complete root-cause analysis.
- Operationalize incoming adversarial intelligence and emerging cloud-infrastructure TTPs directly into active validation logic and automated playbooks.
- Coordinate cross-functional incident mitigation post-mortems, serving as the lead engineer driving structural code fixes, architectural hardening, and policy changes across Compliance and Engineering teams.
- Define, trace, and regularly report core D&R capability metrics, including Mean Time to Detection (MTTD), Mean Time to Remediation (MTTR), telemetry coverage indices, and rule efficiency.
Core Competencies & Cybersecurity Strengths
- Hyperscale Landscape Defense: Deep technical insight into Kubernetes cluster namespaces, API server auditing, node isolation paths, and ingress/egress network security boundaries.
- Scripted Security Tooling: The programmatic agility to write custom scripts and automate alerting integrations directly within the cloud orchestration layer without needing external software support.
- Volatile Forensics Analysis: The capability to capture, trace, and extract meaningful threat timelines from live memory blocks, volatile kernel spaces, and highly ephemeral container file systems.
- Cross-Functional Collaboration: The unique ability to keep a cool head during high-severity system compromises, explaining technical issues clearly to legal and executive teams while guiding engineering patches.
- Productized Engineering Vision: An analytical mindset capable of translating internal operational tools and observability data setups into public-facing cloud security features for enterprise clients.
Skills Required:
- Computer / Software / It / Data
Quick Actions
Share Vacancy