About the company
Nebius is leading a new era in cloud infrastructure for the global AI economy. We are building a full-stack AI cloud platform that supports developers and enterprises from data and model training through to production deployment, without the cost and complexity of building large in-house AI/ML infrastructure.
Built by engineers, for engineers. From large-scale GPU orchestration to inference optimization, we own the hard problems across compute, storage, networking and applied AI.
Listed on Nasdaq (NBIS) and headquartered in Amsterdam, we have a global footprint with R&D hubs across Europe, the UK, North America and Israel. Our team of 1,500+ includes hundreds of engineers with deep expertise across hardware, software and AI R&D.
Responsibilities
- Define the Proactive Security strategy, operating model, roadmap, priorities, budget, and success measures in alignment with Nebius's business objectives and threat profile.
- Build, lead, and develop high-performing Red Team, Penetration Testing, Threat Hunting, and Threat Intelligence teams.
- Create a unified intelligence-led program in which threat intelligence informs testing and hunting, and findings continuously improve defensive controls.
- Prioritize work based on crown jewels, material attack paths, emerging threats, major technology changes, incidents, and business risk.
- Establish clear team charters, engagement models, escalation paths, quality standards, and career-development frameworks.
- Provide the CISO and senior leadership with clear visibility into adversary exposure, validated weaknesses, emerging threats, and remediation progress.
- Lead realistic, intelligence-led adversary simulations across cloud, identity, applications, infrastructure, endpoints, networks, and operational processes.
- Design campaigns that evaluate prevention, detection, response, escalation, and recovery capabilities against relevant threat scenarios.
- Develop and maintain adversary-emulation plans mapped to relevant threat actors, tactics, techniques, and procedures.
- Ensure every engagement operates under documented authorization, rules of engagement, safety controls, deconfliction procedures, and evidence-handling requirements.
- Deliver concise technical and executive reporting that explains demonstrated impact, attack paths, root causes, and prioritized improvements.
- Own the risk-based penetration-testing program for Nebius products, applications, APIs, cloud environments, infrastructure, and critical internal systems.
- Define testing standards, scoping criteria, methodologies, quality assurance, retesting, and reporting requirements.
- Coordinate internal testing and specialized external providers while maintaining consistent quality and risk prioritization.
- Partner with Product, Engineering, Infrastructure, and Security teams to integrate testing into major launches, architectural changes, and high-risk initiatives.
- Track findings through validation, remediation, exception, and closure, and identify systemic or recurring weakness patterns.
- Expand automation and continuous validation where it improves coverage without replacing expert-led testing and judgment.
- Establish a hypothesis-driven threat-hunting program across endpoint, identity, cloud, network, workload, application, and SaaS telemetry.
- Prioritize hunts using threat intelligence, incidents, environmental changes, control gaps, and emerging adversary techniques.
- Search for active, historical, or previously undetected malicious behavior that may not trigger existing alerts.
- Turn validated hunt findings into new detections, telemetry requirements, response playbooks, hardening actions, and future hunt hypotheses.
- Define repeatable hunt methodology, documentation standards, evidence handling, and measurement of hunt effectiveness.
- Partner closely with Detection and Response, Incident Response, Security Engineering, and infrastructure teams during investigations and remediation.
- Own Nebius's threat-intelligence strategy, collection priorities, analysis standards, dissemination model, and intelligence lifecycle.
- Maintain a current view of threat actors, campaigns, vulnerabilities, geopolitical developments, and techniques relevant to Nebius, its customers, and its technology stack.
- Produce strategic intelligence for leadership, operational intelligence for defenders, and tactical intelligence that supports detections, investigations, hunting, and testing.