检测工程与响应负责人
Detection Engineering & Response Lead
关于Nebius:
Nebius正在引领全球AI经济的云基础设施新时代。我们打造了一个全栈AI云平台,支持开发者和企业从数据和模型训练到生产部署的全流程,无需承担构建大型内部AI/ML基础设施的成本和复杂性。
由工程师打造,面向工程师。从大规模GPU编排到推理优化,我们在计算、存储、网络和应用AI领域掌握各种难题。
在纳斯达克上市(股票代码:NBIS),总部位于阿姆斯特丹,我们在欧洲、英国、北美和以色列设有研发中心,拥有全球业务覆盖。我们的团队超过1500人,包括数百名在硬件、软件和AI研发方面有深厚专业知识的工程师。
检测与响应
检测与响应团队负责Nebius云中的检测工程、威胁情报和事件响应。其目标是提升和维护Nebius的安全监控能力,并建立和维护一个端到端的安全事件响应计划——包括人员、流程和工具。
职位描述
我们正在招聘一名检测工程与响应负责人,从零开始构建和运营我们的D&R能力。你将负责Nebius云中的检测工程、威胁情报和事件响应功能,并领导一支小型且不断壮大的分析师和工程师团队。
这是一个负责检测开发、处理最复杂的安全事件、取证以及制定D&R策略的领导型工程岗位。
你将负责的工作包括:
- 领导检测开发:保持低误报率和漏报率。与20多个警报消费团队紧密合作,降低噪音,提高信号质量,确保他们能快速行动而不遗漏真实威胁。
- 设计并运行覆盖我们云环境和裸金属环境的检测方案
- 构建和扩展我们的内部D&R工具和流水线——接入新日志,构建并自动化响应操作手册
- 将威胁情报整合到检测逻辑和事件响应剧本中,追踪与云基础设施相关的攻击者战术、技术和程序(TTPs)
- 全程主导事件响应:包括范围界定、遏制、根本原因分析、事件后评审,并控制关键行动项以防止未来可能发生的事件。
- 与合规和工程团队合作,在满足工程师和监管机构需求的同时识别真实威胁。
- 定义并报告D&R指标
查看英文原文
About Nebius:
Nebius is leading a new era in cloud infrastructure for the global AI economy. We are building a full-stack AI cloud platform that supports developers and enterprises from data and model training through to production deployment, without the cost and complexity of building large in-house AI/ML infrastructure.
Built by engineers, for engineers. From large-scale GPU orchestration to inference optimization, we own the hard problems across compute, storage, networking and applied AI.
Listed on Nasdaq (NBIS) and headquartered in Amsterdam, we have a global footprint with R&D hubs across Europe, the UK, North America and Israel. Our team of 1,500+ includes hundreds of engineers with deep expertise across hardware, software and AI R&D.
Detection and Response
The Detection and Response team is responsible for detection engineering, threat intelligence, and incident response across Nebius Cloud. Its goal is to improve and maintain Nebius's security monitoring capabilities, as well as to build and maintain an end-to-end Security Incident Response program - people, processes, and tools.
The Role
We're hiring a Detection Engineering & Response Lead to build and run our D&R capability from the ground up. You'll own the detection engineering, threat intelligence, and incident response functions across Nebius Cloud - and lead a small, growing team of analysts and engineers.
This is a lead engineering role responsible for detection development, handling the most complex security incidents, forensics, and shaping the D&R strategy.
What you’ll do
- Lead detection development: maintain low false-positive and false-negative rates. Work closely with alerts consumers (20+ teams) to keep noise low and signal high, ensuring they can act quickly without missing genuine threats.
- Architect and operate detection coverage across our cloud and bare-metal environments
- Build and extend our internal D&R tools and pipelines - onboard new logs, build and automate response runbooks.
- Integrate threat intelligence into detection logic and IR playbooks, tracking adversary TTPs relevant to Cloud infrastructure
- Lead incident response end-to-end: scoping, containment, root cause analysis, post-incident reviews and controlling critical action items are closed to prevent future possible incidents.
- Partner with Compliance and Engineering teams to detect real threats while meeting the needs of both engineers and regulators.
- Define and report on D&R metrics: MTTD, MTTR, detection coverage, false positive rates, etc.
- Build and maintain Security Incident Response program: people, processes, tools.
- Build tools, runbooks, and on-call processes that scale as the company grows.
What we look for
- 6+ years in security operations, detection engineering, or incident response — with at least 1–2 years leading or mentoring a team.
- Deep hands-on experience with cloud-native environments (Kubernetes, Linux workloads, container-based infrastructure).
- Strong detection engineering skills: writing and tuning rules/detections in SIEM platforms (e.g., Chronicle, Splunk, Elastic) and SQL.
- Experience building or operating SOAR workflows and automating response at scale (ideally with Golang and Temporal).
- Working knowledge of threat intelligence frameworks (MITRE ATT&CK, Pyramid of Pain, Kill Chain) and how to operationalize them in detections.
- Solid IR fundamentals: memory forensics, log analysis, network traffic analysis, and post-incident reporting.
- Stakeholder management: able to coordinate across engineers, compliance, legal, executives during active incident phase. Serve as the primary owner and driver for complex changes, as a result of incidents post-mortem.
Nice to have
- Experience with AI/ML and GPU clusters related threats.
- Familiarity with eBPF-based detection or runtime security tooling (Falco, Tetragon).
- Background in threat hunting.
Why this role at Nebius
- Build D&R at a company scaling from startup to global infrastructure provider in real time.
- Ability to evolve our internal D&R platform into a new cloud security product, delivering novel security observability for a range of neocloud customers - from big tech to AI startups.
- Work alongside world-class engineers on infrastructure that powers frontier AI.
- Competitive compensation with equity upside in a Nasdaq-listed, high-growth company.
- Flexible, remote-first culture.
#LI-CP1
Benefits & Perks:
- Competitive compensation
- Career growth and learning opportunities
- Flexibility and ownership
- Collaborative and innovative culture
- Opportunity to work on impactful AI projects
- International environment and talented teams
What's it like to work at Nebius:
Fast moving - Bold thinking - Constant growth - Meaningful impact - Trust and real ownership - Opportunity to shape the future of AI
Equal Opportunity Statement:
Nebius is an equal opportunity employer. We are committed to fostering an inclusive and diverse workplace and to providing equal employment opportunities in all aspects of employment. We do not discriminate on the basis of race, color, religion, sex (including pregnancy), national origin, ancestry, age, disability, genetic information, marital status, veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by applicable law.
Applicants must be authorized to work in the country in which they apply and will be required to provide proof of employment eligibility as a condition of hire.
If you need accommodations during the application process, please let us know.