Detection & Response Lead
N
NebiusCloud security
Remote - EuropeFull-TimeLead
Salary not disclosed
Apply NowOpens the employer's application page
Job Details
- Experience
- 6+ years in security operations, detection engineering, or incident response — with at least 1–2 years leading or mentoring a team.
- Required Skills
- SQLKubernetesLinux
Requirements
- Have 6+ years of experience in security operations, detection engineering, or incident response.
- Have at least 1–2 years of experience leading or mentoring a team.
- Bring hands-on experience with cloud-native environments, including Kubernetes, Linux workloads, and container-based infrastructure.
- Have detection engineering experience writing and tuning rules or detections in SIEM platforms such as Chronicle, Splunk, or Elastic.
- Have experience using SQL.
- Have experience building or operating SOAR workflows and automating response at scale.
- Have working knowledge of threat intelligence frameworks, including MITRE ATT&CK, Pyramid of Pain, or Kill Chain, and how to operationalize them in detections.
- Have incident response fundamentals in memory forensics, log analysis, network traffic analysis, and post-incident reporting.
- Be able to coordinate with engineering, compliance, legal, and executive stakeholders during active incidents.
- Experience with Golang and Temporal is desirable.
- Experience with AI/ML and GPU cluster-related threats is desirable.
- Familiarity with eBPF-based detection or runtime security tools such as Falco or Tetragon, and a background in threat hunting, are desirable.
Responsibilities
- Lead detection development and work with alert consumers across 20+ teams to maintain low false-positive and false-negative rates.
- Architect and operate detection coverage across cloud and bare-metal environments.
- Build and extend internal D&R tools and pipelines, onboard logs, and automate response runbooks.
- Integrate threat intelligence into detection logic and incident response playbooks, tracking relevant cloud infrastructure adversary TTPs.
- Lead incident response end to end, including scoping, containment, root cause analysis, post-incident reviews, and follow-up actions.
- Partner with Compliance and Engineering to detect threats while meeting engineering and regulatory needs.
- Define and report D&R metrics, including MTTD, MTTR, detection coverage, and false-positive rates.
- Build and maintain the Security Incident Response program, including its people, processes, and tools.
- Develop tools, runbooks, and on-call processes that scale with the company.
View Full Description & ApplyYou'll be redirected to the employer's site