远程工作雷达

漏洞运营中心负责人

Vulnerability Operation Center Lead

开发工程限定地区(需当地身份)
公司nebius
薪资未公开
工作地点Remote - Europe
地域资格限定地区(需当地身份)
时区要求无特别要求
用工类型未标注
发布时间2026-07-15
数据来源Greenhouse
前往企业招聘页投递 →
注意地域限制:该职位明确限定在 Remote - Europe 招聘。如果你是位于中国大陆的求职者,通常需要当地工作身份才能投递,或需与雇主确认是否接受独立合同(Contractor)形式合作。

关于Nebius:

Nebius正在引领全球AI经济的云基础设施新纪元。我们构建了一个全栈AI云平台,支持开发者和企业从数据和模型训练到生产部署的全流程,而无需承担构建大型内部AI/ML基础设施的成本和复杂性。

由工程师打造,面向工程师。从大规模GPU编排到推理优化,我们在计算、存储、网络和应用AI领域都负责解决最困难的问题。

在纳斯达克上市(NBIS),总部位于阿姆斯特丹,我们在欧洲、英国、北美和以色列设有多个研发中心。我们的团队超过1500人,包括数百名在硬件、软件和AI研发方面有深厚专业知识的工程师。

漏洞运营中心

该团队负责Nebius云基础设施、产品和硬件堆栈的完整漏洞管理生命周期——从检测、分类到修复跟踪和报告。团队的重点是提升漏洞分类能力与漏洞数据质量,推动有效的修复,并作为应对最关键零日漏洞的第一道防线。

职位描述

我们正在从零开始建立漏洞运营中心,需要一位资深从业者来领导该团队。你将负责Nebius云基础设施、产品和硬件堆栈的完整漏洞管理生命周期——从检测、分类到修复跟踪和报告。这是一个高影响力、拥有较大自主权的职位:你将定义流程、选择工具、直接与工程团队合作,并制定Nebius应对漏洞的标准方式。

你将负责的工作

  • 通过数据丰富(内部和外部情报来源)、质量指标、AI辅助分类、上下文感知风险评分以及漏洞相关性/链式分析,改进并维护自动化漏洞分类能力和漏洞数据质量。
  • 对最关键/零日漏洞进行实际验证和分类。
  • 与组织内漏洞数据使用者和利益相关者密切合作,通过提供高质量、可操作的发现结果,满足工程、合规和监管要求,并推动有效的修复。
  • 参与内部平台的开发,包括统一漏洞管理系统(UVM)和安全编排平台,以实现核心漏洞管理的自动化。
查看英文原文

About Nebius:

Nebius is leading a new era in cloud infrastructure for the global AI economy. We are building a full-stack AI cloud platform that supports developers and enterprises from data and model training through to production deployment, without the cost and complexity of building large in-house AI/ML infrastructure.

Built by engineers, for engineers. From large-scale GPU orchestration to inference optimization, we own the hard problems across compute, storage, networking and applied AI.

Listed on Nasdaq (NBIS) and headquartered in Amsterdam, we have a global footprint with R&D hubs across Europe, the UK, North America and Israel. Our team of 1,500+ includes hundreds of engineers with deep expertise across hardware, software and AI R&D.

Vulnerability Operation Center

The team maintains the full vulnerability management lifecycle - from detection and triage through remediation tracking and reporting - across Nebius's cloud infrastructure, product, and hardware stack. The team's focus is on improving vulnerability triaging capabilities and vulnerability data quality, driving effective remediation, and serving as the first line of response for the most critical zero-day vulnerabilities.

The role

We're building a Vulnerability Operations Center from the ground up and need a senior practitioner to lead it. You'll own the full vulnerability management lifecycle - from detection through triage to remediation tracking and reporting - across Nebius' cloud infrastructure, product and hardware stack. This is a high-impact role with big ownership: you'll define processes, select tooling, work directly with engineering teams, and set the standard for how Nebius responds to vulnerabilities.

What You'll Do

  • Improve and maintain automated vulnerability triaging capabilities and vulnerability data quality through data enrichment (internal and external intelligence feeds), quality metrics, AI-assisted triage, context-aware risk scoring, and vulnerability correlation/chaining.
  • Hands-on validation and triaging of most critical/zero-days vulnerabilities
  • Work closely with vulnerability data consumers and stakeholders across the organization to meet engineering, compliance, and regulatory requirements by delivering high-quality, actionable findings and driving effective remediation.
  • Contribute to the development of internal platforms, including the Unified Vulnerability Management (UVM) system and the security orchestration platform, to automate core vulnerability management workflows and reduce manual effort.
  • Identify current deficiencies in patch management, drive and oversee improvements across engineering teams and business units to improve remediation efficiency and reduce organizational risk
  • Own vulnerability intake from all sources - scanners, bug bounty, threat intel feeds, and penetration tests
  • Prioritize findings using risk-based frameworks (CVSS, EPSS, SSVC, asset criticality, exploitability context, business impact) and reduce false positive noise
  • Drive remediation accountability across infrastructure, platform, and product engineering teams
  • Identify, track and report vulnerability management metrics, present KPIs and trends to security leadership
  • Coordinate response to critical/zero-day vulnerabilities, acting as the primary point of contact across security, engineering, and operations
  • Define and maintain integration between VOC tooling and the broader security ecosystem.

What We're Looking For

  • 5–8 years in information security with at least 3 years focused on vulnerability management or security operations
  • Deep familiarity with vulnerability scanning tools and their strengths/limitations in cloud-native environments
  • Strong grasp of CVE/NVD, CVSS scoring, EPSS, SSVC and how to apply them to real-world prioritization
  • Experience managing vulnerabilities across IaaS/cloud infrastructure (AWS, GCP, Azure, or private cloud) - experience with GPU/HPC environments is a plus
  • Deep understanding of vulnerability sources limitations and corner cases for different vulnerability classes
  • Able to write and review code (ability or willingness to develop in Golang) - well enough to assess exploitability, validate fixes, and build lightweight automation (e.g., variant-detection scripts, triage tooling, data pipelines for trend analysis)
  • Strong grasp of common vulnerability classes at the code and infrastructure level.
  • Comfortable feeding well-documented vulnerability patterns into AI-assisted code review workflows and critically evaluating the output
  • Track record of working cross-functionally with engineering teams and holding stakeholders accountable to timelines without being a bottleneck
  • Strong written and verbal communication - able to translate technical risk into business impact for non-security audiences

Nice to Have

  • Experience building vulnerability management program from scratch
  • Familiarity with container and Kubernetes security
  • Experience with supply chain security (SBOMs, dependency scanning)
  • Bug bounty triage experience
  • Public talks or research articles

Why this role at Nebius

  • Build a Platform Security Vulnerability program from scratch and get to build and lead your own team while doing it
  • The potential to evolve an in-house AI-powered vulnerability management platform into a cloud security offering for Nebius customers
  • Work alongside world-class engineers on infrastructure that powers frontier AI.
  • Competitive compensation with equity upside in a Nasdaq-listed, high-growth company.
  • Flexible, remote-first culture

#LI-CP1
Benefits & Perks:

  • Competitive compensation
  • Career growth and learning opportunities
  • Flexibility and ownership
  • Collaborative and innovative culture
  • Opportunity to work on impactful AI projects
  • International environment and talented teams

What's it like to work at Nebius:

Fast moving - Bold thinking - Constant growth - Meaningful impact - Trust and real ownership - Opportunity to shape the future of AI

Equal Opportunity Statement:

Nebius is an equal opportunity employer. We are committed to fostering an inclusive and diverse workplace and to providing equal employment opportunities in all aspects of employment. We do not discriminate on the basis of race, color, religion, sex (including pregnancy), national origin, ancestry, age, disability, genetic information, marital status, veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by applicable law.

Applicants must be authorized to work in the country in which they apply and will be required to provide proof of employment eligibility as a condition of hire.

If you need accommodations during the application process, please let us know.

本页面信息整理自 Greenhouse,版权归原发布方所有。职位可能随时关闭,投递请以原始页面为准。 本站只做信息聚合展示,不参与招聘流程,也不向求职者收取任何费用。

该公司其他在招职位

定价总监

nebiusRemote2026-06-26
职能支持全球可投

应用安全工程师

nebiusIsrael€75,000 - €240,000/年Full Time今天
开发工程限定地区(需当地身份)

← 返回全部职位