Detection & Response Lead
Nebius
About Nebius: Nebius is leading a new era in cloud infrastructure for the global AI economy. We are building a full-stack AI cloud platform that supports developers and enterprises from data and model training through to production deployment, without the cost and complexity of building large in-house AI/ML infrastructure. Built by engineers, for engineers. From large-scale GPU orchestration to inference optimization, we own the hard problems across compute, storage, networking and applied AI. Listed on Nasdaq (NBIS) and headquartered in Amsterdam, we have a global footprint with R&D hubs across Europe, the UK, North America and Israel. Our team of 1,500+ includes hundreds of engineers with deep expertise across hardware, software and AI R&D. Detection and Response The team is responsible for detection engineering, threat intelligence, and incident response across Nebius Cloud. Its goal is to improve and maintain Nebius's security monitoring capabilities, as well as to build and maintain an end-to-end Security Incident Response program - people, processes, and tools. The Role We're hiring a Detection Engineering & Response Lead to build and run our D&R capability from the ground up. You'll own the detection engineering, threat intelligence, and incident response functions across Nebius Cloud - and lead a small, growing team of analysts and engineers. This is a lead engineering role responsible for detection development, handling the most complex security incidents, forensics, and shaping the D&R strategy. What you’ll do - Lead detection development: maintain low false-positive and false-negative rates. Work closely with alerts consumers (20+ teams) to keep noise low and signal high, ensuring they can act quickly without missing genuine threats - Architect and operate detection coverage across our cloud and bare-metal environments - Build and extend our internal D&R tools and pipelines - onboard new logs, build and automate response runbooks - Integrate threat intelligence into detection logic and IR playbooks, tracking adversary TTPs relevant to Cloud infrastructure - Lead incident response end-to-end: scoping, containment, root cause analysis, post-incident reviews and controlling critical action items are closed to prevent future possible incidents - Partner with Compliance and Engineering teams to detect real threats while meeting the needs of both engineers and regulators - Define and report on D&R metrics: MTTD, MTTR, detection coverage, false positive rates, etc - Build and maintain Security Incident Response program: people, processes, tools - Build tools, runbooks, and on-call processes that scale as the company grows What we look for - 6+ years in security operations, detection engineering, or incident response — with at least 1–2 years leading or mentoring a team.
- Deep hands-on experience with cloud-native environments (Kubernetes, Linux workloads, container-based infrastructure). - Strong detection engineering skills: writing and tuning rules/detections in SIEM Platforms (e. g. , Chronicle, Splunk, Elastic) and SQL. - Experience building or operating SOAR workflows and automating response at scale (ideally with Golang and Temporal). - Working knowledge of threat intelligence frameworks (MITRE ATT&CK, Pyramid of Pain, Kill Chain) and how to operationalize them in detections. - Solid IR fundamentals: memory forensics, log analysis, network traffic analysis, and post-incident reporting. - Stakeholder management: able to coordinate across engineers, compliance, legal, executives during active incident phase. Serve as the primary owner and driver for complex changes, as a result of incidents post-mortem. Nice to have: - Experience with AI/ML and GPU clusters related threats. - Familiarity with eBPF-based detection or runtime security tooling (Falco, Tetragon). - Background in threat hunting.
$164.9k - $245k
...sharing the airspace is non-negotiable. Detect and Avoid (DAA) is how our aircraft sense... ...by our dedicated radar team.As the DAA Lead, you own the DAA capability across that... ...into a shipped, certifiable product. Responsibilities Own DAA as a portfolio, not a point solution...SuggestedPermanent employmentFull timeTemporary workRemote work$140k - $150k
Job DescriptionEverforth ECS is seeking an Incident Response Lead to work in our Washington, DC office / remote. The role is contingent... ...operations specialist consisting of hunting threats, developing detection mechanisms, refining processes, and elevating the...SuggestedWork at officeRemote work- ...As the Incident Response Lead, this full-time remote position will manage client security incidents, directing response efforts, establishing... ...Hands-on investigative depth in Microsoft 365 and endpoint detection tools Ability to build defensible incident timelines from...SuggestedFull timeRemote work
$105k - $135k
...Center staffed entirely in the United States. Our Managed Detection and Response practice, formerly Quadrant Information Security, combines... ...than monitoring for them. ~ Direct experience acting as the lead on security incidents, meaning you set the direction and...SuggestedContract workImmediate startRemote work$40 - $80 per hour
...Incident Response Lead, Cyber Security $40-80/hr Remote Freelance CODING About the Role What if your hard-won experience in the SOC trenches could directly strengthen how organizations detect, respond to, and contain real threats? We're looking for a seasoned...SuggestedHourly payOngoing contractContract workFreelanceRemote workFlexible hoursNight shift- ...Financial Group (MUFG), one of the world’s leading financial groups. Across the globe, we’... ...actions based upon that analysis. Responsibilities include rapidly responding to potential... ...the development of security operations detections, playbooks, and automations to ensure threat...Full timeWork at officeLocal areaRemote work1 day per week
- ...threat intelligence, threat hunting, and detection engineering for our SOC. You will build a... ...that safeguard 12,000+ customers. You'll lead a remote team of analysts and detection... ..., and collaborate with SOC, Incident Response, and Security Engineering leaders to #J...Remote work
$120.19k - $223.21k
...over 30 years of expertise, Strada blends leading-edge technology with human ingenuity to... ...highly skilled and motivated Incident Response Lead to join our cybersecurity team. This... ...Leads, who own monitoring operations, detection engineering, alert triage processes, SIEM...Full timeLocal areaRemote workWorldwideVisa sponsorshipFlexible hours- ...Senior Midmarket Account Executive: Detection & Response Antigen Security is a rapidly growing Technology Services Distributor specializing... ...& Response, your role is to consistently generate qualified leads, carry and exceed quota, and help customers address their...Work experience placementRemote work
- ...reporting to the Cyber Monitoring and Incident Response Team Director, you are responsible for... ...team of analysts and associates who detect, investigate, and respond to cyber security... ...DTCC.Utilize metrics, feedback from team leads, feedback from stakeholders, threat intelligence...Remote workFlexible hours
- ...Mandiant, part of Google Cloud, seeks a Senior Incident Response Security Consultant to lead end-to-end incident investigations across cloud, network, and endpoints. You will guide technical teams, communicate findings to executives, and drive remediation strategies on...Remote job
- ...listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for an Incident Response Engagement-Lead based in the United States. This role leads complex cyber incident engagements from initial scoping through containment,...Full time
- Mandiant is seeking a Principal Incident Response Security Consultant to lead end-to-end incident response engagements for high-profile breaches, including host and network forensics, cloud evidence analysis, log review, malware triage, threat hunting, and producing detailed...Remote work
$58k - $62k
...Catholic Charities of the Archdiocese of Newark is currently seeking a Full Time Lead Mobile Response Worker for its Mobile Response & Stabilization Services Program located in Jersey City, NJ. ABOUT THE MOBILE RESPONSE & STABILIZATION SERVICES PROGRAM: ~...Full timeImmediate start- ...executive protection, intelligence, investigations, and emergency response, offering exciting career opportunities for professionals... ...Enhanced Protection Services, is hiring an Emergency Response Center Lead Operator. The Emergency Response Center (ERC) Team Lead is responsible...Contract workFor subcontractorWork at officeLocal area
- ...Fractional Machine Learning Lead – Seizure Detection & Prediction Location: Chicago, IL - Remote/Hybrid (Local presence preferred) Type... ...scale our clinical builds and studies in late 2026. Key Responsibilities Algorithm Development & Validation: Finalize and...Contract workPart timeLocal areaRemote work
- ...IT Security & Compliance Lead (Healthcare) Location: 620 Foster Ave, Brooklyn, NY... ...based in our Administration office and is responsible for managing and maintaining the entire... ...actions, and continuously improve detection and response capabilities Compliance...Full timeWork at officeRemote workMonday to Friday
- ...Position Summary The Lead AML/CFT Analyst is responsible for managing the day-to-day operations of the AML/CFT program, including supervision of... ...improvements to enhance operational efficiency and risk detection Supports CRB oversight activities and ensure adherence...Work experience placementWork at officeRemote work
- ...business.The UAS Operations Team Leader is responsible for the leadership, daily management,... ...thorough incident investigation protocols; lead or delegate root cause analysis and... ...thermal imagers, LiDAR scanners, methane/gas detection sensors Manage secure transport,...Hourly payFull timeLocal areaRemote work
- ...(NLP) technologies. As a Vice President and Applied AI/ML Lead, you’ll play a pivotal role in building innovative solutions... ...including reproducibility, testing, monitoring, drift detection, and incident response to sustain reliable production performance.Partner with risk...
- The Threat Management Red Team Lead is a cybersecurity leader responsible for defining, building, and leading the enterprise adversary emulation program... ...scenarios and drives measurable improvements in detection and response capabilities. This role requires a blend...Contract workFor contractorsWork experience placementLocal areaRemote work
- ...organization is looking for an Offensive Security Lead to mature and grow our Penetration... ...Vulnerability Management, SOC/Incident Response, Application Security, and engineering teams... ...drive real remediation and inform detection engineering.Manage external partnerships...Remote work
$116.72k - $126.29k
...facilities, U.S. citizenship is required. Responsibilities for this Position The Program... ...applications, managing tool configurations, leading upgrades and technology improvements,... ...as intelligent ticket triage, anomaly detection, automated reporting, predictive...Work experience placementRemote workFlexible hoursShift work$112.7k - $193.2k
...Growing together.We're seeking a skilled Lead Software Engineer to help build intelligent... ...improve observability, speed up incident response, and support self-healing infrastructure... ...feature sets that support anomaly detection, predictive alerting, capacity forecasting...Minimum wageFull timeWork experience placementWork at officeLocal areaRemote work- ...are looking for a Distribution Center Team Lead to join our Rexel team in Carrollton, TX!... ...: The Distribution Center Lead is responsible for helping supervise and perform other aspects... ...with co-workers and clients and detect hazardous conditions - Constantly - at least...For contractorsWork at officeImmediate startMonday to FridayFlexible hoursShift workWeekend work
$160k - $200k
...beyond our planet. About the RoleThe Cybersecurity Lead role at Apex is a critical leadership role responsible for overseeing the daily operations of the... ...Operations Center (SOC), ensuring proactive threat detection, incident response, and team performance. This position...Full timeWork at office$108k - $138.6k
...Alternate Locations: Newell Brands is a leading consumer products company with a portfolio... .../SOAR) is a hands-on engineering role responsible for the design, build, and continuous optimization... .... This role owns the full lifecycle of detection engineering - from ingestion and...Full timeFor contractorsRemote work$158.6k - $285.5k
...:We are seeking an Associate Director to lead the design, selection, and implementation... ...handling, and continuous compliance. Build detection and reporting for credential misuse and... ...; partner with SecOps and Cyber Incident Response on playbooks and response. Author standards...Permanent employmentFull timeTemporary workWork at officeRemote workWork from home$140k - $180k
...partners are watching. The goal is not just detection; it's ensuring issues can be discovered,... ...are detected, triaged, and resolved.Lead the rollout of Splunk Observability across... ...management processes, including major incident response and escalation design.Comfortable...Temporary workWork at officeRemote work- ...operations center background and want to lead others while working on interesting problems and helping to advance incident response capabilities? Have you always wanted to make... ...implementing and honing a myriad of detective and preventive controls and processes in an...Full timeWork at officeRemote work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Detection & Response Lead. Be the first to apply!





