Company Logo
Software Engineer

Netflix - 1d ago

Company Logo
Senior Software Engineer

Reddit - 4d ago

Detection Engineering & Response Lead

Requirements

  • 6+ years in security operations, detection engineering, or incident response — with at least 1–2 years leading or mentoring a team
  • Deep hands-on experience with cloud-native environments (Kubernetes, Linux workloads, container-based infrastructure)
  • Strong detection engineering skills: writing and tuning rules/detections in SIEM platforms (e.g., Chronicle, Splunk, Elastic) and SQL
  • Experience building or operating SOAR workflows and automating response at scale (ideally with Golang and Temporal)
  • Working knowledge of threat intelligence frameworks (MITRE ATT&CK, Pyramid of Pain, Kill Chain) and how to operationalize them in detections

Nice to Haves

  • Experience with AI/ML and GPU clusters related threats
  • Familiarity with eBPF-based detection or runtime security tooling (Falco, Tetragon)
  • Background in threat hunting

What you'll be doing

  • Lead detection development: maintain low false-positive and false-negative rates. Work closely with alerts consumers (20+ teams) to keep noise low and signal high, ensuring they can act quickly without missing genuine threats.
  • Architect and operate detection coverage across our cloud and bare-metal environments
  • Build and extend our internal D&R tools and pipelines - onboard new logs, build and automate response runbooks
  • Integrate threat intelligence into detection logic and IR playbooks, tracking adversary TTPs relevant to Cloud infrastructure
  • Lead incident response end-to-end: scoping, containment, root cause analysis, post-incident reviews and controlling critical action items are closed to prevent future possible incidents.
  • Partner with Compliance and Engineering teams to detect real threats while meeting the needs of both engineers and regulators
  • Define and report on D&R metrics: MTTD, MTTR, detection coverage, false positive rates, etc.
  • Build and maintain Security Incident Response program: people, processes, tools
  • Build tools, runbooks, and on-call processes that scale as the company grows

Perks and Benefits

  • Competitive compensation
  • Career growth and learning opportunities
  • Flexibility and ownership
  • Collaborative and innovative culture
  • Opportunity to work on impactful AI projects
  • International environment and talented teams
AI Summary ✨
Nebius logo

Nebius

Remote EMEA

Remote EMEA
Experience: Senior
Posted: September 21, 2026
Last seen: 2 hours ago
Golang
Kubernetes
Nodejs
security

Why we track Nebius

Nebius is the Amsterdam-headquartered, Nasdaq-listed AI cloud that spun out of Yandex. They build GPU clusters, their own server hardware, and a full cloud stack for AI training and inference, with engineering concentrated in Amsterdam and teams in London, Prague, Berlin, Finland, and Paris plus remote roles across Europe. Pay is strong: levels.fyi shows a €140K median in the Netherlands (€160K at the G17 level) and a £183K median in London.

Similar jobs

  • 5 days ago
    Remote
  • 8 days ago
    Remote EMEA
  • 8 days ago
    Remote EMEA
  • See all jobs in undefined