We're hiring a Detection Engineering & Response Lead to build and run our D&R capability from the ground up. You'll own the detection engineering, threat intelligence, and incident response functions across Nebius Cloud - and lead a small, growing team of analysts and engineers
This is a lead engineering role responsible for detection development, handling the most complex security incidents, forensics, and shaping the D&R strategy
Lead detection development: maintain low false-positive and false-negative rates. Work closely with alerts consumers (20+ teams) to keep noise low and signal high, ensuring they can act quickly without missing genuine threats
Architect and operate detection coverage across our cloud and bare-metal environments
Build and extend our internal D&R tools and pipelines - onboard new logs, build and automate response runbooks
Integrate threat intelligence into detection logic and IR playbooks, tracking adversary TTPs relevant to Cloud infrastructure
Lead incident response end-to-end: scoping, containment, root cause analysis, post-incident reviews and controlling critical action items are closed to prevent future possible incidents
Partner with Compliance and Engineering teams to detect real threats while meeting the needs of both engineers and regulators
Define and report on D&R metrics: MTTD, MTTR, detection coverage, false positive rates, etc
Build and maintain Security Incident Response program: people, processes, tools
Build tools, runbooks, and on-call processes that scale as the company grows