Nebius
OpenDetection Engineering & Response Lead
- Location
- Israel; Remote - Europe
- Posted
- Jul 30, 2026
- Last seen
- Aug 19, 2026
About the role
About Nebius:
Nebius is leading a new era in cloud infrastructure for the global AI economy. We are building a full-stack AI cloud platform that supports developers and enterprises from data and model training through to production deployment, without the cost and complexity of building large in-house AI/ML infrastructure.
Built by engineers, for engineers. From large-scale GPU orchestration to inference optimization, we own the hard problems across compute, storage, networking and applied AI.
Listed on Nasdaq (NBIS) and headquartered in Amsterdam, we have a global footprint with R&D hubs across Europe, the UK, North America and Israel. Our team of 1,500+ includes hundreds of engineers with deep expertise across hardware, software and AI R&D.
Detection and Response
The Detection and Response team is responsible for detection engineering, threat intelligence, and incident response across Nebius Cloud. Its goal is to improve and maintain Nebius's security monitoring capabilities, as well as to build and maintain an end-to-end Security Incident Response program - people, processes, and tools.
The Role
We're hiring a Detection Engineering & Response Lead to build and run our D&R capability from the ground up. You'll own the detection engineering, threat intelligence, and incident response functions across Nebius Cloud - and lead a small, growing team of analysts and engineers.
This is a lead engineering role responsible for detection development, handling the most complex security incidents, forensics, and shaping the D&R strategy.
What you’ll do
• Lead detection development: maintain low false-positive and false-negative rates. Work closely with alerts consumers (20+ teams) to keep noise low and signal high, ensuring they can act quickly without missing genuine threats.
• Architect and operate detection coverage across our cloud and bare-metal environments
• Build and extend our internal D&R tools and pipelines - onboard new logs, build and automate response runbooks.
• Integrate threat intelligence into detection logic and IR playbooks, tracking adversary TTPs relevant to Cloud infrastructure
• Lead incident response end-to-end: scoping, containment, root cause analysis, post-incident <span id="2ce618f9-e966-4781-ada1-cf
