Detection & Response Lead

N
NebiusCloud security
Remote - EuropeFull-TimeLead
Salary not disclosed
Apply NowOpens the employer's application page

Job Details

Experience
6+ years in security operations, detection engineering, or incident response — with at least 1–2 years leading or mentoring a team.
Required Skills
SQLKubernetesLinux

Requirements

  • Have 6+ years of experience in security operations, detection engineering, or incident response.
  • Have at least 1–2 years of experience leading or mentoring a team.
  • Bring hands-on experience with cloud-native environments, including Kubernetes, Linux workloads, and container-based infrastructure.
  • Have detection engineering experience writing and tuning rules or detections in SIEM platforms such as Chronicle, Splunk, or Elastic.
  • Have experience using SQL.
  • Have experience building or operating SOAR workflows and automating response at scale.
  • Have working knowledge of threat intelligence frameworks, including MITRE ATT&CK, Pyramid of Pain, or Kill Chain, and how to operationalize them in detections.
  • Have incident response fundamentals in memory forensics, log analysis, network traffic analysis, and post-incident reporting.
  • Be able to coordinate with engineering, compliance, legal, and executive stakeholders during active incidents.
  • Experience with Golang and Temporal is desirable.
  • Experience with AI/ML and GPU cluster-related threats is desirable.
  • Familiarity with eBPF-based detection or runtime security tools such as Falco or Tetragon, and a background in threat hunting, are desirable.

Responsibilities

  • Lead detection development and work with alert consumers across 20+ teams to maintain low false-positive and false-negative rates.
  • Architect and operate detection coverage across cloud and bare-metal environments.
  • Build and extend internal D&R tools and pipelines, onboard logs, and automate response runbooks.
  • Integrate threat intelligence into detection logic and incident response playbooks, tracking relevant cloud infrastructure adversary TTPs.
  • Lead incident response end to end, including scoping, containment, root cause analysis, post-incident reviews, and follow-up actions.
  • Partner with Compliance and Engineering to detect threats while meeting engineering and regulatory needs.
  • Define and report D&R metrics, including MTTD, MTTR, detection coverage, and false-positive rates.
  • Build and maintain the Security Incident Response program, including its people, processes, and tools.
  • Develop tools, runbooks, and on-call processes that scale with the company.
View Full Description & ApplyYou'll be redirected to the employer's site
View details
Apply Now