远程工作雷达

主动安全负责人

Offensive Security Lead

开发工程限定地区(需当地身份)
公司nebius
薪资未公开
工作地点Remote - Europe
地域资格限定地区(需当地身份)
时区要求无特别要求
用工类型未标注
发布时间2026-07-15
数据来源Greenhouse
前往企业招聘页投递 →
注意地域限制:该职位明确限定在 Remote - Europe 招聘。如果你是位于中国大陆的求职者,通常需要当地工作身份才能投递,或需与雇主确认是否接受独立合同(Contractor)形式合作。

关于Nebius:

Nebius正在引领全球AI经济的云基础设施新时代。我们打造了一个全栈AI云平台,支持开发者和企业从数据和模型训练到生产部署,而无需承担构建大型内部AI/ML基础设施的成本和复杂性。

由工程师打造,为工程师服务。从大规模GPU编排到推理优化,我们在计算、存储、网络和应用AI领域都负责解决难题。

在纳斯达克上市(NBIS),总部位于阿姆斯特丹,我们在欧洲、英国、北美和以色列设有研发中心,拥有全球业务布局。我们的团队超过1500人,包括数百名在硬件、软件和AI研发方面有深厚专业知识的工程师。

进攻性安全

内部进攻性安全团队负责渗透测试计划、红队行动和进攻性研究,旨在发现针对Nebius云堆栈中高价值资产的复杂攻击场景。

职位描述

我们正在招聘一名进攻性安全负责人,以建立并运行Nebius的红队能力。你将设计并执行针对我们云平台的对抗性模拟——攻击客户依赖的相同基础设施,并将发现转化为可衡量的安全改进。

这是产品安全团队中的一个实际操作型领导职位。你将组建内部红队,建立渗透测试计划,并进行研究以发现针对Nebius技术栈中高价值资产的复杂攻击场景。

你将负责:

  • 在产品安全团队内建立并领导红队职能,招聘和发展进攻性安全工程师。
  • 通过持续的渗透测试验证和扩展早期阶段的Secure SDLC威胁模型,评估威胁严重性和缓解状态,同时挑战威胁建模和系统开发过程中所做的假设。自动化常规验证以跟上功能更新的速度,将手动分析保留给真正复杂的案例。
  • 规划并执行针对Nebius云平台的全面红队行动——包括计算、存储、推理、网络、编排层和内部工具。识别可能影响组织运营的威胁。与检测与响应及其他安全工程团队密切合作,开展紫队演练,验证检测覆盖率,并协作填补漏洞。
查看英文原文

About Nebius:

Nebius is leading a new era in cloud infrastructure for the global AI economy. We are building a full-stack AI cloud platform that supports developers and enterprises from data and model training through to production deployment, without the cost and complexity of building large in-house AI/ML infrastructure.

Built by engineers, for engineers. From large-scale GPU orchestration to inference optimization, we own the hard problems across compute, storage, networking and applied AI.

Listed on Nasdaq (NBIS) and headquartered in Amsterdam, we have a global footprint with R&D hubs across Europe, the UK, North America and Israel. Our team of 1,500+ includes hundreds of engineers with deep expertise across hardware, software and AI R&D.

Offensive security

The internal offensive security team is responsible for the penetration testing program, red team engagements, and offensive research aimed at uncovering sophisticated attack scenarios targeting high-value assets across the Nebius Cloud stack.

The Role

We're hiring an Offensive Security Lead to build and run Nebius' red team capability. You'll design and execute adversarial simulation across our cloud platform - attacking the same infrastructure our customers depend on - and translate findings into measurable security improvements.

This is a hands-on leadership role within Product Security Team. You will build an internal red team, establish a penetration testing program, and conduct research to uncover sophisticated attack scenarios targeting high-value assets across the Nebius tech stack.

What you’ll do

  • Build and lead a red team function within Product Security Team, hiring and developing offensive security engineers.
  • Validate and extend early-stage Secure SDLC threat models via continuous penetration testing, assessing threat severity and mitigation status while challenging assumptions made during threat modeling and system development. Automate routine validations to keep pace with increasing feature flow, reserving manual analysis for genuinely complex cases.
  • Plan and execute full-scoped red team engagements against Nebius cloud platform - including compute, storage, inference, networking, orchestration layers, and internal tooling. Identify threats, which are able to impact an organization's operations. Work closely with Detection & Response and other security engineering teams to run purple team exercises, validate detection coverage, and close gaps collaboratively.
  • Research novel attacks against GPU infrastructure (e.g., closed-source firmware and vendor driver binaries, device passthrough exploits, SR-IOV/IOMMU misconfigurations, RDMA/InfiniBand fabric attacks, etc.), the inference stack (e.g., vLLM, TRT-LLM), and AI platform managed services (e.g., managed Slurm). Assess tenant-isolation boundaries and how they can be broken at the low-level stack
  • Conduct targeted assessments of new products and infrastructure changes before they ship.
  • Deliver clear, actionable reports for both technical audiences and leadership - with prioritized findings and remediation guidance.
  • Establish red team processes, tooling, and a methodology that scales as the platform grows.

What we’re looking for

  • 6+ years in offensive security - penetration testing, red teaming, or adversary simulation - with at least 1-2 years leading or mentoring a team.
  • Deep experience attacking cloud-native environments: Kubernetes privilege escalation, cloud IAM abuse, virtualization and container escapes.
  • Strong fundamentals across the attack lifecycle: initial access, persistence, lateral movement, data exfiltration.
  • Proficiency developing custom tooling and post-exploitation capabilities (Python, Go, or similar).
  • Experience running purple team exercises and working constructively with blue teams.
  • Ability to write clear, senior-level reports with business-contextualized risk (not just raw findings) that engineers can easily use.

Nice to have

  • Experience attacking ML infrastructure, model serving pipelines, or GPU clusters.
  • Reverse engineering and exploits development experience
  • Application security experience
  • Familiarity with eBPF bypass techniques or kernel-level exploitation.
  • Background in vulnerability research or CVE discovery.
  • Experience with cloud provider internals (hypervisor/networking layers).
  • Presenting your security research at conferences like BlackHat/DefCon, etc.

Why this role at Nebius

  • Build a red team from scratch at a company operating frontier AI infrastructure.
  • Attack surface that's genuinely novel - GPU clusters, AI platforms, multi-tenant cloud at scale.
  • Work alongside world-class engineers on infrastructure that powers frontier AI.
  • Competitive compensation with equity upside in a Nasdaq-listed, high-growth company.
  • Flexible, remote-first culture

#LI-CP1
Benefits & Perks:

  • Competitive compensation
  • Career growth and learning opportunities
  • Flexibility and ownership
  • Collaborative and innovative culture
  • Opportunity to work on impactful AI projects
  • International environment and talented teams

What's it like to work at Nebius:

Fast moving - Bold thinking - Constant growth - Meaningful impact - Trust and real ownership - Opportunity to shape the future of AI

Equal Opportunity Statement:

Nebius is an equal opportunity employer. We are committed to fostering an inclusive and diverse workplace and to providing equal employment opportunities in all aspects of employment. We do not discriminate on the basis of race, color, religion, sex (including pregnancy), national origin, ancestry, age, disability, genetic information, marital status, veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by applicable law.

Applicants must be authorized to work in the country in which they apply and will be required to provide proof of employment eligibility as a condition of hire.

If you need accommodations during the application process, please let us know.

本页面信息整理自 Greenhouse,版权归原发布方所有。职位可能随时关闭,投递请以原始页面为准。 本站只做信息聚合展示,不参与招聘流程,也不向求职者收取任何费用。

该公司其他在招职位

定价总监

nebiusRemote2026-06-26
职能支持全球可投

应用安全工程师

nebiusIsrael€75,000 - €240,000/年Full Time今天
开发工程限定地区(需当地身份)

← 返回全部职位