Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Detection & Response Lead

Full-time

Nebius

About Nebius: Nebius is leading a new era in cloud infrastructure for the global AI economy. We are building a full-stack AI cloud platform that supports developers and enterprises from data and model training through to production deployment, without the cost and complexity of building large in-house AI/ML infrastructure. Built by engineers, for engineers. From large-scale GPU orchestration to inference optimization, we own the hard problems across compute, storage, networking and applied AI. Listed on Nasdaq (NBIS) and headquartered in Amsterdam, we have a global footprint with R&D hubs across Europe, the UK, North America and Israel. Our team of 1,500+ includes hundreds of engineers with deep expertise across hardware, software and AI R&D. Detection and Response The team is responsible for detection engineering, threat intelligence, and incident response across Nebius Cloud. Its goal is to improve and maintain Nebius's security monitoring capabilities, as well as to build and maintain an end-to-end Security Incident Response program - people, processes, and tools. The Role We're hiring a Detection Engineering & Response Lead to build and run our D&R capability from the ground up. You'll own the detection engineering, threat intelligence, and incident response functions across Nebius Cloud - and lead a small, growing team of analysts and engineers. This is a lead engineering role responsible for detection development, handling the most complex security incidents, forensics, and shaping the D&R strategy. What you’ll do - Lead detection development: maintain low false-positive and false-negative rates. Work closely with alerts consumers (20+ teams) to keep noise low and signal high, ensuring they can act quickly without missing genuine threats - Architect and operate detection coverage across our cloud and bare-metal environments - Build and extend our internal D&R tools and pipelines - onboard new logs, build and automate response runbooks - Integrate threat intelligence into detection logic and IR playbooks, tracking adversary TTPs relevant to Cloud infrastructure - Lead incident response end-to-end: scoping, containment, root cause analysis, post-incident reviews and controlling critical action items are closed to prevent future possible incidents - Partner with Compliance and Engineering teams to detect real threats while meeting the needs of both engineers and regulators - Define and report on D&R metrics: MTTD, MTTR, detection coverage, false positive rates, etc - Build and maintain Security Incident Response program: people, processes, tools - Build tools, runbooks, and on-call processes that scale as the company grows What we look for - 6+ years in security operations, detection engineering, or incident response — with at least 1–2 years leading or mentoring a team.

- Deep hands-on experience with cloud-native environments (Kubernetes, Linux workloads, container-based infrastructure). - Strong detection engineering skills: writing and tuning rules/detections in SIEM Platforms (e. g. , Chronicle, Splunk, Elastic) and SQL. - Experience building or operating SOAR workflows and automating response at scale (ideally with Golang and Temporal). - Working knowledge of threat intelligence frameworks (MITRE ATT&CK, Pyramid of Pain, Kill Chain) and how to operationalize them in detections. - Solid IR fundamentals: memory forensics, log analysis, network traffic analysis, and post-incident reporting. - Stakeholder management: able to coordinate across engineers, compliance, legal, executives during active incident phase. Serve as the primary owner and driver for complex changes, as a result of incidents post-mortem. Nice to have: - Experience with AI/ML and GPU clusters related threats. - Familiarity with eBPF-based detection or runtime security tooling (Falco, Tetragon). - Background in threat hunting.

Vacancy posted 10 hours ago
Similar jobs that could be interesting for youBased on the Detection & Response Lead in Remote vacancy
  • $164.9k - $245k

     ...sharing the airspace is non-negotiable. Detect and Avoid (DAA) is how our aircraft sense...  ...by our dedicated radar team.As the DAA Lead, you own the DAA capability across that...  ...into a shipped, certifiable product. Responsibilities Own DAA as a portfolio, not a point solution... 
    Suggested
    Permanent employment
    Full time
    Temporary work
    Remote work

    Joby Aviation

    Santa Cruz, CA
    3 days ago
  • $140k - $150k

    Job DescriptionEverforth ECS is seeking an Incident Response Lead to work in our Washington, DC office / remote. The role is contingent...  ...operations specialist consisting of hunting threats, developing detection mechanisms, refining processes, and elevating the... 
    Suggested
    Work at office
    Remote work

    ECS Federal

    Washington DC
    4 days ago
  •  ...As the Incident Response Lead, this full-time remote position will manage client security incidents, directing response efforts, establishing...  ...Hands-on investigative depth in Microsoft 365 and endpoint detection tools Ability to build defensible incident timelines from... 
    Suggested
    Full time
    Remote work

    Virtual Vocations Inc

    United States
    1 day ago
  • $105k - $135k

     ...Center staffed entirely in the United States. Our Managed Detection and Response practice, formerly Quadrant Information Security, combines...  ...than monitoring for them. ~ Direct experience acting as the lead on security incidents, meaning you set the direction and... 
    Suggested
    Contract work
    Immediate start
    Remote work

    Rippling

    New York, NY
    3 days ago
  • $40 - $80 per hour

     ...Incident Response Lead, Cyber Security $40-80/hr Remote Freelance CODING About the Role What if your hard-won experience in the SOC trenches could directly strengthen how organizations detect, respond to, and contain real threats? We're looking for a seasoned... 
    Suggested
    Hourly pay
    Ongoing contract
    Contract work
    Freelance
    Remote work
    Flexible hours
    Night shift

    Alignerr

    United States
    3 days ago
  •  ...Financial Group (MUFG), one of the world’s leading financial groups. Across the globe, we’...  ...actions based upon that analysis. Responsibilities include rapidly responding to potential...  ...the development of security operations detections, playbooks, and automations to ensure threat... 
    Full time
    Work at office
    Local area
    Remote work
    1 day per week

    MUFG

    Tempe, AZ
    4 days ago
  •  ...threat intelligence, threat hunting, and detection engineering for our SOC. You will build a...  ...that safeguard 12,000+ customers. You'll lead a remote team of analysts and detection...  ..., and collaborate with SOC, Incident Response, and Security Engineering leaders to #J... 
    Remote work

    Jobleads-US

    New York, NY
    3 days ago
  • $120.19k - $223.21k

     ...over 30 years of expertise, Strada blends leading-edge technology with human ingenuity to...  ...highly skilled and motivated Incident Response Lead to join our cybersecurity team. This...  ...Leads, who own monitoring operations, detection engineering, alert triage processes, SIEM... 
    Full time
    Local area
    Remote work
    Worldwide
    Visa sponsorship
    Flexible hours

    Strada

    Remote
    6 days ago
  •  ...Senior Midmarket Account Executive: Detection & Response Antigen Security is a rapidly growing Technology Services Distributor specializing...  ...& Response, your role is to consistently generate qualified leads, carry and exceed quota, and help customers address their... 
    Work experience placement
    Remote work

    Antigen Security

    Royal Oak, MI
    5 days ago
  •  ...reporting to the Cyber Monitoring and Incident Response Team Director, you are responsible for...  ...team of analysts and associates who detect, investigate, and respond to cyber security...  ...DTCC.Utilize metrics, feedback from team leads, feedback from stakeholders, threat intelligence... 
    Remote work
    Flexible hours

    DTCC- The Depository Trust & Clearing Corporation

    Tampa, FL
    4 days ago
  •  ...Mandiant, part of Google Cloud, seeks a Senior Incident Response Security Consultant to lead end-to-end incident investigations across cloud, network, and endpoints. You will guide technical teams, communicate findings to executives, and drive remediation strategies on... 
    Remote job

    Jobleads-US

    Alabama
    2 days ago
  •  ...listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for an Incident Response Engagement-Lead based in the United States. This role leads complex cyber incident engagements from initial scoping through containment,... 
    Full time

    Jobgether

    Remote
    10 days ago
  • Mandiant is seeking a Principal Incident Response Security Consultant to lead end-to-end incident response engagements for high-profile breaches, including host and network forensics, cloud evidence analysis, log review, malware triage, threat hunting, and producing detailed... 
    Remote work

    Forensic Focus Limited

    New York, NY
    2 days ago
  • $58k - $62k

     ...Catholic Charities of the Archdiocese of Newark is currently seeking a  Full Time Lead Mobile Response Worker  for its Mobile Response & Stabilization Services Program located in Jersey City, NJ.   ABOUT THE MOBILE RESPONSE & STABILIZATION SERVICES PROGRAM: ~... 
    Full time
    Immediate start

    Catholic Charities of the Archdiocese of Newark

    Jersey City, NJ
    more than 2 months ago
  •  ...executive protection, intelligence, investigations, and emergency response, offering exciting career opportunities for professionals...  ...Enhanced Protection Services, is hiring an Emergency Response Center Lead Operator. The Emergency Response Center (ERC) Team Lead is responsible... 
    Contract work
    For subcontractor
    Work at office
    Local area

    Allied Universal® Enhanced Protection Services

    Richardson, TX
    13 days ago
  •  ...Fractional Machine Learning Lead – Seizure Detection & Prediction Location: Chicago, IL - Remote/Hybrid (Local presence preferred) Type...  ...scale our clinical builds and studies in late 2026. Key Responsibilities Algorithm Development & Validation: Finalize and... 
    Contract work
    Part time
    Local area
    Remote work

    Stealth Startup

    Chicago, IL
    7 hours ago
  •  ...IT Security & Compliance Lead (Healthcare) Location: 620 Foster Ave, Brooklyn, NY...  ...based in our Administration office and is responsible for managing and maintaining the entire...  ...actions, and continuously improve detection and response capabilities Compliance... 
    Full time
    Work at office
    Remote work
    Monday to Friday

    Premium Health Center

    Brooklyn, NY
    3 hours ago
  •  ...Position Summary The Lead AML/CFT Analyst is responsible for managing the day-to-day operations of the AML/CFT program, including supervision of...  ...improvements to enhance operational efficiency and risk detection Supports CRB oversight activities and ensure adherence... 
    Work experience placement
    Work at office
    Remote work

    North Easton Savings Bank

    Abbeville County, SC
    4 days ago
  •  ...business.The UAS Operations Team Leader is responsible for the leadership, daily management,...  ...thorough incident investigation protocols; lead or delegate root cause analysis and...  ...thermal imagers, LiDAR scanners, methane/gas detection sensors  Manage secure transport,... 
    Hourly pay
    Full time
    Local area
    Remote work

    Occidental Petroleum

    Houston, TX
    4 days ago
  •  ...(NLP) technologies. As a Vice President and Applied AI/ML Lead, you’ll play a pivotal role in building innovative solutions...  ...including reproducibility, testing, monitoring, drift detection, and incident response to sustain reliable production performance.Partner with risk... 

    JP Morgan Chase

    Seattle, WA
    4 days ago
  • The Threat Management Red Team Lead is a cybersecurity leader responsible for defining, building, and leading the enterprise adversary emulation program...  ...scenarios and drives measurable improvements in detection and response capabilities. This role requires a blend... 
    Contract work
    For contractors
    Work experience placement
    Local area
    Remote work

    Sherwin-Williams

    Cleveland, OH
    9 hours ago
  •  ...organization is looking for an Offensive Security Lead to mature and grow our Penetration...  ...Vulnerability Management, SOC/Incident Response, Application Security, and engineering teams...  ...drive real remediation and inform detection engineering.Manage external partnerships... 
    Remote work

    SoFi

    Cottonwood Heights, UT
    3 days ago
  • $116.72k - $126.29k

     ...facilities, U.S. citizenship is required. Responsibilities for this Position The Program...  ...applications, managing tool configurations, leading upgrades and technology improvements,...  ...as intelligent ticket triage, anomaly detection, automated reporting, predictive... 
    Work experience placement
    Remote work
    Flexible hours
    Shift work

    General Dynamics Mission Systems

    Scottsdale, AZ
    3 days ago
  • $112.7k - $193.2k

     ...Growing together.We're seeking a skilled Lead Software Engineer to help build intelligent...  ...improve observability, speed up incident response, and support self-healing infrastructure...  ...feature sets that support anomaly detection, predictive alerting, capacity forecasting... 
    Minimum wage
    Full time
    Work experience placement
    Work at office
    Local area
    Remote work

    UnitedHealth Group

    Minnetonka, MN
    3 days ago
  •  ...are looking for a Distribution Center Team Lead to join our Rexel team in Carrollton, TX!...  ...: The Distribution Center Lead is responsible for helping supervise and perform other aspects...  ...with co-workers and clients and detect hazardous conditions - Constantly - at least... 
    For contractors
    Work at office
    Immediate start
    Monday to Friday
    Flexible hours
    Shift work
    Weekend work

    Rexel

    Carrollton, TX
    1 day ago
  • $160k - $200k

     ...beyond our planet. About the RoleThe Cybersecurity Lead role at Apex is a critical leadership role responsible for overseeing the daily operations of the...  ...Operations Center (SOC), ensuring proactive threat detection, incident response, and team performance. This position... 
    Full time
    Work at office

    Apex Technology

    Los Angeles, CA
    9 hours ago
  • $108k - $138.6k

     ...Alternate Locations: Newell Brands is a leading consumer products company with a portfolio...  .../SOAR) is a hands-on engineering role responsible for the design, build, and continuous optimization...  .... This role owns the full lifecycle of detection engineering - from ingestion and... 
    Full time
    For contractors
    Remote work

    Newell Brands

    Atlanta, GA
    9 hours ago
  • $158.6k - $285.5k

     ...:We are seeking an Associate Director to lead the design, selection, and implementation...  ...handling, and continuous compliance. Build detection and reporting for credential misuse and...  ...; partner with SecOps and Cyber Incident Response on playbooks and response. Author standards... 
    Permanent employment
    Full time
    Temporary work
    Work at office
    Remote work
    Work from home

    Moderna Therapeutics

    Cambridge, MA
    9 hours ago
  • $140k - $180k

     ...partners are watching. The goal is not just detection; it's ensuring issues can be discovered,...  ...are detected, triaged, and resolved.Lead the rollout of Splunk Observability across...  ...management processes, including major incident response and escalation design.Comfortable... 
    Temporary work
    Work at office
    Remote work

    Bessemer Trust

    Woodbridge, NJ
    1 day ago
  •  ...operations center background and want to lead others while working on interesting problems and helping to advance incident response capabilities? Have you always wanted to make...  ...implementing and honing a myriad of detective and preventive controls and processes in an... 
    Full time
    Work at office
    Remote work

    Crane

    Stamford, CT
    4 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Detection & Response Lead. Be the first to apply!