About the company
Nebius is leading a new era in cloud infrastructure for the global AI economy. We are building a full-stack AI cloud platform that supports developers and enterprises from data and model training through to production deployment, without the cost and complexity of building large in-house AI/ML infrastructure.
Built by engineers, for engineers. From large-scale GPU orchestration to inference optimization, we own the hard problems across compute, storage, networking and applied AI.
Listed on Nasdaq (NBIS) and headquartered in Amsterdam, we have a global footprint with R&D hubs across Europe, the UK, North America and Israel. Our team of 1,500+ includes hundreds of engineers with deep expertise across hardware, software and AI R&D.
The role
Nebius is looking for a Lead Detection Engineer. This is an individual contributor role with full technical ownership. You'll set the direction for detection engineering: the standards, the tooling, the coverage strategy, and the automation that operationalizes it all. You'll work closely with SOC analysts and Platform Engineering to make detection a first-class engineering discipline.
You’re welcome to work in our offices in Tel Aviv, Israel.
Responsibilities
- Detection coverage strategy across endpoint, identity, cloud, and infrastructure — how it's measured, prioritized, and continuously improved.
- Detection-as-Code pipeline: version control, testing, peer review, CI/CD, and deployment practices for all detection logic.
- Architecture connecting detections to enrichment, triage, and automated response workflows.
- Technical standards for how detections are designed, tested, documented, deployed, and retired.
- Detection quality: fidelity metrics, false positive reduction, coverage measurement, and continuous validation loops.
- Design and build high-fidelity behavioral detections across SIEM and EDR platforms.
- Research emerging attacker techniques and translate threat intelligence into scalable, evasion-resistant detections.
- Validate detections through threat simulations and continuous detection testing.
- Partner with SOC analysts to close the feedback loop between detections and real investigations.
- Define and track detection engineering metrics; communicate coverage posture and effectiveness to security leadership.
- Make architectural decisions that scale as the team and organization grow.
Requirements
- Minimum 3 years in detection engineering, security operations, or a hybrid offensive/defensive role — with demonstrated depth, not just breadth.
- Experience owning or leading detection engineering work as a senior technical contributor.
- Strong understanding of attacker tradecraft and adversary behavior.
- Hands-on experience with at least one enterprise SIEM and EDR platform — Splunk, Microsoft Sentinel, CrowdStrike, or equivalent.
- Cloud security depth across Azure, AWS, or GCP.
- Strong query development skills in SPL, KQL, Sigma, or similar.
- Strong scripting skills (Python, PowerShell, etc.).
- Solid engineering practices: Git, CI/CD, code review, Detection-as-Code workflows.
- Experience using MITRE ATT&CK to design, validate, and measure detection coverage.
- Ability to make and defend technical decisions and establish standards others adopt.
Nice to have
- Offensive security background or certifications.
- Experience with threat hunting and detection validation frameworks.
- Experience designing SOAR playbooks and automated response workflows.
- Experience building AI-assisted detection, investigation, or triage workflows.
Conditions
- Competitive compensation.
- Career growth and learning opportunities.
- Flexibility and ownership.
- Collaborative and innovative culture.
- Opportunity to work on impactful AI projects.
- International environment and talented teams.