About the company
Nebius is leading a new era in cloud infrastructure for the global AI economy. We are building a full-stack AI cloud platform that supports developers and enterprises from data and model training through to production deployment, without the cost and complexity of building large in-house AI/ML infrastructure.
Responsibilities
- Collection: Run systematic searches based on Nebius Priority Intelligence Requirements across OSINT sources (Shodan/Censys, crt.sh, GitHub, VirusTotal/URLscan, Google dorks), commercial threat intelligence platforms, and Dark Web / Telegram monitoring.
- Intelligence Systems & Feeds: Receive and process alerts from the intelligence platforms the company is connected to, proactively query those systems (queries, pivoting), and cross-reference and validate findings against additional intelligence sources to reduce false positives, enrich alerts, and assess relevance to Nebius.
- Feed Consolidation: Aggregate, correlate, and consolidate cyber threat intelligence feeds and sources into a unified, actionable intelligence picture.
- Analysis: Identify spoofed/lookalike domains, brand impersonation, leaked credentials, infrastructure exposures, publicly exposed assets, and map threat actor TTPs to MITRE ATT&CK.
- Threat Impact Assessment: Analyze the likelihood that an emerging threat will affect the organization, identify weaknesses/exposures it could exploit, and assess the potential operational impact on Nebius.
- Incident Investigation: Provide intelligence support to the SOC / cybersecurity teams during security incidents: enrich observed IOCs, perform attribution to known threat actors where possible, supply context on expected TTPs, and monitor external sources for additional signals related to the incident.
- Threat Hunting Support: Support intelligence-driven hunt missions to augment detection capabilities and identify threats across the environment.
- Threat Actor Tracking: Document activity, campaigns, and TTPs of threat groups relevant to Cloud/AI infrastructure.
- IOC Management: Collect, validate, structure, defang, and prioritize indicators with source attribution and confidence levels.
- Watchlist Maintenance: Continuously update the search-term dictionary, monitored domains, brands, and intelligence watchlists used for threat monitoring.
- Documentation & Reporting: Write findings following the standard report format (BLUF, key findings, assessment, IOC feed, source coverage, and confidence level) as input to the Lead.
- Intelligence Hygiene: Log false positives separately (what was found, why dismissed), maintain proper TLP classification, and clearly distinguish verified facts from analytical assessment.
Requirements
- Understanding of CTI methodology and the intelligence cycle.
- Hands-on familiarity with OSINT tools (Shodan, Censys, crt.sh, VirusTotal, etc.).
- Experience working with intelligence systems/platforms and handling an alert stream (triage), including consolidating multiple feeds.
- Experience validating intelligence across multiple independent sources.
- Understanding of the MITRE ATT&CK framework and TTP mapping.
- Ability to support incident investigations and hunt missions, working closely with the SOC in real time.
- Analytical capabilities of logical reasoning, critical thinking, and problem-solving.
- Critical analytical thinking – verifying findings across multiple sources, avoiding jumping to conclusions, and distinguishing fact from inference.
- Concise technical writing ability (BLUF, structured reports).
- Understanding of common attack techniques targeting Cloud infrastructure.
- It will be an added bonus if you have:
- Experience with Cloud/AI infrastructure.
- Experience with Digital Risk Protection (DRP), external attack surface monitoring, or brand monitoring.
Conditions
- Competitive compensation
- Career growth and learning opportunities
- Flexibility and ownership
- Collaborative and innovative culture
- Opportunity to work on impactful AI projects
- International environment and talented teams