About the company
Nebius is leading a new era in cloud infrastructure for the global AI economy. We are building a full-stack AI cloud platform that supports developers and enterprises from data and model training through to production deployment, without the cost and complexity of building large in-house AI/ML infrastructure.
Responsibilities
- Engineer, deploy, and continuously tune systems such as Identity & Access, Threat Detection & Response, Cloud & Network Security.
- Define, enforce and maintain security policies & configurations across endpoints, email, SaaS, network, and cloud platforms.
- Design and implement solutions to gain continuous visibility into systems and processes, sensitive data, data flows, misconfigurations, and exposure risks across cloud and multi-cloud environments.
- Monitor, triage, and investigate security alerts and risks, collaborating with Security, IT, Network teams on escalation and remediation.
- Conduct risk assessments and identify gaps in security controls across systems, pipelines, and business processes.
- Support compliance and regulatory requirements (e.g., GDPR, ISO 27001, SOC 2) related to security and privacy.
- Collaborate with Engineering, IT, Product, and GRC teams to embed security controls into systems, and workflows.
- Maintain documentation, runbooks, and guidelines for operations, security posture management, and security practices.
Requirements
- 6+ years of experience in IT security, with a strong focus on System, Network, Information, Cyber. With at least 3 years in a Security Engineering role.
- Proven hands-on engineering experience with enterprise security platforms - including policy authoring, tuning, incident workflow configuration, and platform administration.
- Experience securing data across cloud environments and SaaS platforms, including shadow IT and unmanaged data stores.
- Strong understanding of identity and access management and data access governance principles.
- Experience working cross-functionally with Security, IT, Engineering, Product, and GRC teams.
- Strong analytical mindset with the ability to communicate security risks clearly to technical and non-technical stakeholders.
- Excellent written and verbal communication skills in English.
- Proactive, detail-oriented, and ownership-driven.
- Hands-on experience with multiple technologies such as: XDR (Extended Detection & Response), SWG (Secure Web Gateway), DLP (Data Leakage Prevention), Email Security, Network security (Firewalls, NAC, NDR), IGA (Identity Governance & Administration), CASB (Cloud Access Security Broker), PAM (Privileged Access Management), EPM (Endpoint Privilege Management), BAS (Breach & Attack Simulation), Vulnerability Scanners, SIEM (Security Information & Event Management), SOAR (Security Orchestration, Automation & Response), CTI (Cyber Threat Intelligence), Patch Management, TPRM (Third-Party Risk Management), EASM (External Attack Surface Management).
Conditions
- Competitive compensation.
- Career growth and learning opportunities.
- Flexibility and ownership.
- Collaborative and innovative culture.
- Opportunity to work on impactful AI projects.
- International environment and talented teams.