← Все вакансии/Senior/Nebius
SeniorOfficeTel Aviv

Lead Detection Engineer

N
Nebius
Уровень
Senior
Формат
Office
О роли

Описание вакансии

About the company

Nebius is leading a new era in cloud infrastructure for the global AI economy. We are building a full-stack AI cloud platform that supports developers and enterprises from data and model training through to production deployment, without the cost and complexity of building large in-house AI/ML infrastructure.

Built by engineers, for engineers. From large-scale GPU orchestration to inference optimization, we own the hard problems across compute, storage, networking and applied AI.

Listed on Nasdaq (NBIS) and headquartered in Amsterdam, we have a global footprint with R&D hubs across Europe, the UK, North America and Israel. Our team of 1,500+ includes hundreds of engineers with deep expertise across hardware, software and AI R&D.

The role

Nebius is looking for a Lead Detection Engineer. This is an individual contributor role with full technical ownership. You'll set the direction for detection engineering: the standards, the tooling, the coverage strategy, and the automation that operationalizes it all. You'll work closely with SOC analysts and Platform Engineering to make detection a first-class engineering discipline.

You’re welcome to work in our offices in Tel Aviv, Israel.

Responsibilities
  • Detection coverage strategy across endpoint, identity, cloud, and infrastructure — how it's measured, prioritized, and continuously improved.
  • Detection-as-Code pipeline: version control, testing, peer review, CI/CD, and deployment practices for all detection logic.
  • Architecture connecting detections to enrichment, triage, and automated response workflows.
  • Technical standards for how detections are designed, tested, documented, deployed, and retired.
  • Detection quality: fidelity metrics, false positive reduction, coverage measurement, and continuous validation loops.
  • Design and build high-fidelity behavioral detections across SIEM and EDR platforms.
  • Research emerging attacker techniques and translate threat intelligence into scalable, evasion-resistant detections.
  • Validate detections through threat simulations and continuous detection testing.
  • Partner with SOC analysts to close the feedback loop between detections and real investigations.
  • Define and track detection engineering metrics; communicate coverage posture and effectiveness to security leadership.
  • Make architectural decisions that scale as the team and organization grow.
Requirements
  • Minimum 3 years in detection engineering, security operations, or a hybrid offensive/defensive role — with demonstrated depth, not just breadth.
  • Experience owning or leading detection engineering work as a senior technical contributor.
  • Strong understanding of attacker tradecraft and adversary behavior.
  • Hands-on experience with at least one enterprise SIEM and EDR platform — Splunk, Microsoft Sentinel, CrowdStrike, or equivalent.
  • Cloud security depth across Azure, AWS, or GCP.
  • Strong query development skills in SPL, KQL, Sigma, or similar.
  • Strong scripting skills (Python, PowerShell, etc.).
  • Solid engineering practices: Git, CI/CD, code review, Detection-as-Code workflows.
  • Experience using MITRE ATT&CK to design, validate, and measure detection coverage.
  • Ability to make and defend technical decisions and establish standards others adopt.
Nice to have
  • Offensive security background or certifications.
  • Experience with threat hunting and detection validation frameworks.
  • Experience designing SOAR playbooks and automated response workflows.
  • Experience building AI-assisted detection, investigation, or triage workflows.
Conditions
  • Competitive compensation.
  • Career growth and learning opportunities.
  • Flexibility and ownership.
  • Collaborative and innovative culture.
  • Opportunity to work on impactful AI projects.
  • International environment and talented teams.
Стек и навыки

С чем работаем