安全解决方案工程师
Security Solutions Engineer
关于Nebius:
Nebius正在引领全球AI经济的云基础设施新时代。我们正在构建一个全栈AI云平台,支持开发者和企业从数据和模型训练到生产部署,无需承担构建大型内部AI/ML基础设施的成本和复杂性。
由工程师打造,为工程师而生。从大规模GPU编排到推理优化,我们在计算、存储、网络和应用AI领域掌握着最困难的问题。
在纳斯达克上市(股票代码:NBIS),总部位于阿姆斯特丹,我们在欧洲、英国、北美和以色列设有研发中心,拥有全球化的业务布局。我们的团队超过1500人,其中包括数百名在硬件、软件和AI研发方面具有深厚专业知识的工程师。
职位描述
我们正在寻找一位具备扎实战略解决方案评估、供应商评估和实际PoC验证经验的安全解决方案工程师。该职位是连接识别客户安全需求与实施最佳实践、企业级解决方案的关键桥梁。您将负责定义标准、研究市场,并对公司采用的所有主要安全工具和服务进行技术验证。
主要职责:
1. 战略研究与需求定义
- 威胁到解决方案映射:主动分析客户期望、法规/合规驱动因素和威胁模型,以明确新安全解决方案的功能性和非功能性需求。
- 市场分析与调研:进行全面的市场扫描,识别关键领域(如CSPM/CNAPP、DLP、IAM/IGA、EDR/XDR、数据安全、Kubernetes安全和AI/ML安全)中的前沿安全产品、平台和供应商。
- 供应商尽职调查:根据技术能力、安全态势、集成需求、路线图、数据驻留/合规性和支持质量等评估潜在供应商,并筛选出进入PoC阶段的候选者。
2. 技术验证与PoC领导
- PoC规划与设计:为所有安全解决方案的PoC制定详细、客观且符合威胁场景的测试计划和成功标准,包括定量的成功指标、关键攻击场景的覆盖范围以及自动化机会。
- 实操环境搭建:独立设计并部署隔离的PoC环境,准确模拟我们的生产基础设施(例如
查看英文原文
About Nebius:
Nebius is leading a new era in cloud infrastructure for the global AI economy. We are building a full-stack AI cloud platform that supports developers and enterprises from data and model training through to production deployment, without the cost and complexity of building large in-house AI/ML infrastructure.
Built by engineers, for engineers. From large-scale GPU orchestration to inference optimization, we own the hard problems across compute, storage, networking and applied AI.
Listed on Nasdaq (NBIS) and headquartered in Amsterdam, we have a global footprint with R&D hubs across Europe, the UK, North America and Israel. Our team of 1,500+ includes hundreds of engineers with deep expertise across hardware, software and AI R&D.
The role
We are seeking a Security Solutions Engineer with a strong background in strategic solution evaluation, vendor assessment, and hands-on Proof-of-Concept (PoC) validation. This role is a crucial bridge between identifying customer security requirements and implementing best-in-class, enterprise-grade solutions. You will be responsible for defining the criteria, researching the market, and executing technical validation for all major security tooling and services adopted by the company.
Key responsibilities:
1. Strategic Research & Requirement Definition
- Threat-to-Solution Mapping: Proactively analyze customer expectations, regulatory/compliance drivers, and threat models to define precise functional and non-functional requirements for new security solutions.
- Market Analysis & Scouting: Conduct thorough market scans to identify cutting-edge security products, platforms, and vendors across key domains (e.g., CSPM/CNAPP, DLP, IAM/IGA, EDR/XDR, data security, Kubernetes security, and AI/ML security).
- Vendor Due Diligence: Evaluate potential vendors based on technical capability, security posture, integration requirements, roadmap, data residency/compliance, and support quality, and shortlist candidates for the PoC phase.
2. Technical Validation & Proof-of-Concept (PoC) Leadership
- PoC Planning & Design: Develop detailed, objective, and threat-aligned test plans and success criteria for all security solution Proof-of-Concepts (PoCs), including quantitative success metrics, coverage of key attack scenarios, and opportunities for automation.
- Hands-on Environment Setup: Independently architect and deploy isolated PoC environments that accurately simulate our production infrastructure (e.g., setting up cloud VPCs, Kubernetes clusters, integrating with test data via IaC, and mimicking typical workloads).
- Testing & Analysis: Execute security research methodologies within the PoC (e.g., simulating attack scenarios, conducting deep feature validation, assessing false positive/negative rates) to rigorously test the vendor solution's effectiveness.
- Artifact Generation: Document all findings, including technical performance data, integration challenges, security gaps discovered, and clear comparative analysis metrics.
3. Decision Support & Communication
- Recommendation & Insight: Deliver comprehensive, data-driven reports and compelling presentations to security and product leadership and engineering stakeholders, providing a clear recommendation for the optimal solution and vendor selection.
- Integration Planning: Work closely with Security Engineering, Platform/Infra, and DevOps teams to ensure selected solutions are feasible to integrate, operate, and scale, and to hand off PoC learnings into implementation plans.
Must-haves:
- Experience: Minimum 6+ years in Security Engineering, Security Architecture, or a dedicated Security Research role focused on solution validation and vendor management.
- Technical Depth: Deep understanding of modern cloud security principles (e.g., AWS/Azure/GCP security models, Kubernetes/containers, network segmentation, IaC scanning, least privilege, identity-centric security, confidential computing).
- Programming and Automation - Strong scripting / programming skills (e.g., Python, Go, or similar) for automating PoCs, building test harnesses, and integrating tools via APIs and CI/CD pipelines.
- Solutions Expertise: Proven, hands-on experience with the architecture, deployment, and testing of two or more enterprise-grade security tools (e.g., SIEM/SOAR platforms, Endpoint Detection and Response (EDR), Vulnerability Management, Secrets Management).
- PoC Proficiency: Demonstrated ability to plan and execute complex technical Proof-of-Concepts, including setting up test environments and defining quantitative success metrics.
- Soft Skills: Exceptional analytical skills with the ability to translate complex technical findings into clear business risk and strategic recommendations. Strong written and verbal communication.
Nice-to-haves:
- Experience in Cloud or Cloud-Heavy companies.
- Experience in a compliance-focused industry (e.g., finance, healthcare, or cloud infrastructure) and familiarity with frameworks such as ISO 27001, SOC 2, or GDPR.
- Advanced professional certifications such as CISSP, CCSK or relevant cloud certifications (e.g., AWS/GCP/Azure Security Specialty).
- Experience contributing to security standards, open-source tools, talks, or publications.
Benefits & Perks:
- Competitive compensation
- Career growth and learning opportunities
- Flexibility and ownership
- Collaborative and innovative culture
- Opportunity to work on impactful AI projects
- International environment and talented teams
What's it like to work at Nebius:
Fast moving - Bold thinking - Constant growth - Meaningful impact - Trust and real ownership - Opportunity to shape the future of AI
Equal Opportunity Statement:
Nebius is an equal opportunity employer. We are committed to fostering an inclusive and diverse workplace and to providing equal employment opportunities in all aspects of employment. We do not discriminate on the basis of race, color, religion, sex (including pregnancy), national origin, ancestry, age, disability, genetic information, marital status, veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by applicable law.
Applicants must be authorized to work in the country in which they apply and will be required to provide proof of employment eligibility as a condition of hire.
If you need accommodations during the application process, please let us know.