Detection & Response Lead
Full-time
Nebius
Role Description
We're hiring a Detection & Response Lead to build and run our D&R capability from the ground up. You'll own the detection engineering, threat intelligence, and incident response functions across Nebius Cloud and lead a small, growing team of analysts and engineers. This is a lead engineering role responsible for:
- Detection development: achieve full MITRE coverage, maintain low false-positive and false-negative rates.
- Working closely with alerts consumers (20+ teams) to keep noise low and signal high, ensuring they can act quickly without missing genuine threats.
- Architecting and operating detection coverage across our cloud and bare-metal environments.
- Building and extending our internal D&R tools and pipelines - onboarding new logs, building and automating response runbooks.
- Integrating threat intelligence into detection logic and IR playbooks, tracking adversary TTPs relevant to Cloud infrastructure.
- Leading incident response end-to-end: scoping, containment, root cause analysis, post-incident reviews, and controlling critical action items to prevent future incidents.
- Partnering with Compliance and Engineering teams to detect real threats while meeting the needs of both engineers and regulators.
- Defining and reporting on D&R metrics: MTTD, MTTR, detection coverage, false positive rates, etc.
- Building and maintaining the Security Incident Response program: people, processes, tools.
- Building tools, runbooks, and on-call processes that scale as the company grows.
Qualifications
- 6+ years in security operations, detection engineering, or incident response — with at least 1–2 years leading or mentoring a team.
- Deep hands-on experience with cloud-native environments (Kubernetes, Linux workloads, container-based infrastructure).
- Strong detection engineering skills: writing and tuning rules/detections in SIEM platforms (e.g., Chronicle, Splunk, Elastic) and SQL.
- Experience building or operating SOAR workflows and automating response at scale (ideally with Golang and Temporal).
- Working knowledge of threat intelligence frameworks (MITRE ATT&CK, Pyramid of Pain, Kill Chain) and how to operationalize them in detections.
- Solid IR fundamentals: memory forensics, log analysis, network traffic analysis, and post-incident reporting.
- Stakeholder management: able to coordinate across engineers, compliance, legal, executives during active incident phase.
Requirements
- Experience with AI/ML and GPU clusters related threats (nice to have).
- Familiarity with eBPF-based detection or runtime security tooling (Falco, Tetragon) (nice to have).
- Background in threat hunting (nice to have).
Benefits
- Competitive compensation with equity upside in a Nasdaq-listed, high-growth company.
- Flexible, remote-first culture.
- Career growth and learning opportunities.
- Flexibility and ownership.
- Collaborative and innovative culture.
- Opportunity to work on impactful AI projects.
- International environment and talented teams.
Vacancy posted a month ago
Similar jobs that could be interesting for youBased on the Detection & Response Lead in Remote vacancy
$10k
...move and manage billions, Ramp is the place to do it.About the RoleJoin our growing security team and help drive security detection and response initiatives across Ramp. This will include a focus on maturing our security detection and alerting capabilities across our...SuggestedFull timeWork experience placementWork at officeHome officeFlexible hours- ...technology and data-driven commercial MGA and insurance wholesaler leading innovation in the market. Backed by one of the leading... ...is seeking a senior, hands‑on defender to build a detection and response function responsible for defensive security operations across...Suggested
$164.9k - $245k
...sharing the airspace is non-negotiable. Detect and Avoid (DAA) is how our aircraft sense... ...by our dedicated radar team.As the DAA Lead, you own the DAA capability across that... ...into a shipped, certifiable product. Responsibilities Own DAA as a portfolio, not a point solution...SuggestedPermanent employmentFull timeTemporary workRemote work- The Cybersecurity Security Operations Center (CSOC) Incident Response (IR) Lead is a cybersecurity professional responsible for overseeing... ...knowledge of network security, malware analysis, intrusion detection, and related technologies.Excellent communication and interpersonal...SuggestedContract workFor contractorsLocal areaRemote work
$140k - $150k
Job DescriptionEverforth ECS is seeking an Incident Response Lead to work in our Washington, DC office / remote. The role is contingent... ...operations specialist consisting of hunting threats, developing detection mechanisms, refining processes, and elevating the...SuggestedWork at officeRemote work$40 - $80 per hour
...Incident Response Lead, Cyber Security $40-80/hr Remote Freelance CODING About the Role What if your hard-won experience in the SOC trenches could directly strengthen how organizations detect, respond to, and contain real threats? We're looking for a seasoned...Hourly payOngoing contractContract workFreelanceRemote workFlexible hoursNight shift$240k - $280k
...Your Responsibilities Will Include Obsidian Security is the leading SaaS security platform, trusted by global enterprises like Snowflake, T-Mobile, and Algolia. We... ...a complete SaaS security platform to reduce risk, detect and respond to threats, and prevent breaches at the...Work from home$10k
...About The Role Join our growing security team and help drive security detection and response initiatives across Ramp. This will include a focus on maturing our security detection and alerting capabilities across our federal and public sector environments. Please note...Full timeWork experience placementWork at officeHome officeRelocation packageFlexible hours2 days per week- ...Financial Group (MUFG), one of the world’s leading financial groups. Across the globe, we’... ...actions based upon that analysis. Responsibilities include rapidly responding to potential... ...the development of security operations detections, playbooks, and automations to ensure threat...Full timeWork at officeLocal areaRemote work1 day per week
- First Citizens Bank is seeking a Senior Incident Response Analyst for a remote role that can be hired in multiple U.S. markets. You will join the Cyber Incident Response team, detecting and responding to threats, interacting with business stakeholders, and restoring operations...Remote job
- ...Expert (SME) to provide deep domain expertise supporting fraud detection and identity theft analytics initiatives. This role guides... ...programs within government or financial institutions. Responsibilities include but are not limited to: Provide domain expertise in...Full timeWork at officeLocal areaRemote work
- First Citizens Bank is seeking a Senior Incident Response Analyst to join the Cyber Incident Response team in a remote role across the United States. The candidate will detect and respond to threats, interact with business stakeholders, and restore operations while mentoring...Remote job
- ZKM Consulting is seeking a Lead SOC Analyst to support a client on a CNI project, focusing on maintaining compliance with... ...during investigations. The role requires strong SOC operations experience, incident response and threat detection, #J-18808-Ljbffr ZKM ConsultingRemote job
- ...Angeles, CA. Triskele Labs are one of the leading providers of cybersecurity services in... ...Triskele Labs Digital Forensics and Incident Response (DFIR) team assists clients of all sizes... ...SpectreOps - Adversary Tactics: Detection Application Process A cover letter addressed...Remote jobWork at office
$126k - $180k
...appropriate actions based on that analysis. Responsibilities include rapidly responding to potential... .... Develop security operations detection playbooks, and automate threat detection... ...processes align with policies and regulations. Lead and mentor junior analysts as needed....Work at officeLocal areaRemote work1 day per week- ...Position Title: Cyber Security Incident Response Lead Location: Texas (Teleworker) Clearance Requirements: Public Trust Clearance Pay Rate: Competitive salary based on experience Position Description: We are seeking a highly skilled and experienced Cyber...For contractorsRemote work
$162.8k - $303k
...Job Number: R0247651 Global Incident Response Business Development Leader The Opportunity Serve as the Global Business Development Leader... ...partners, and direct enterprise relationships with our IR retainer. Lead and develop a global team of business development, relationship,...Full timeContract workPart timeWork at officeLocal areaRemote work$100k - $120k
...This position requires a Bachelor's degree and a minimum of 8 years of IT experience, including 4 years specifically in incident response. An active Secret clearance is also essential. The role involves overseeing incident operations, ensuring compliance with standards...Remote work- ...Arrow Components is seeking an Information Technology Manager II to lead advanced cyber incident investigations across enterprise environments. You will direct end-to-end incident response, preserve evidence, and deliver executive summaries with remediation guidance....Remote work
- ...Senior Midmarket Account Executive: Detection & Response Antigen Security is a rapidly growing Technology Services Distributor specializing... ...& Response, your role is to consistently generate qualified leads, carry and exceed quota, and help customers address their...Work experience placementRemote work
- ...reporting to the Cyber Monitoring and Incident Response Team Director, you are responsible for... ...team of analysts and associates who detect, investigate, and respond to cyber security... ...DTCC.Utilize metrics, feedback from team leads, feedback from stakeholders, threat intelligence...Remote workFlexible hours
$225.4k - $281.8k
...Apollo.io is the leading go-to-market solution for revenue teams, trusted by over 500,000 companies and millions of users globally... ...a startup-minded Engineering Manager to lead our Security Detection & Response team. You’ll build and scale a team that ships detection...Full timeRemote workWorldwideFlexible hours$151k - $208k
...Palo Alto Networks, Inc. is looking for a Principal Consultant in Burbank, California, responsible for leading incident response and digital forensics services. This role involves serving as a technical leader on investigations and guiding clients through security incidents...Remote job- Runway is seeking a seasoned GRC professional to lead governance, risk, and compliance across the US, with remote options. You will shape frameworks that balance security and responsible AI, working closely with product, engineering, and legal teams. Responsibilities include...Remote job
- SecureBio is seeking a Public Health Response Manager in Cambridge, MA (or DC or remote for outstanding candidates) to lead engagement with state and local health officials, translate biosurveillance findings into action, and shape response protocols. You will build trust...Remote jobLocal area
$75.04k - $112.56k
Ahold Delhaize USA is seeking a Major Incident Management Analyst responsible for leading the response to major incidents. This role supports communication and coordination between stakeholders and will ensure the swift resolution of incidents. The position includes a flexible...Remote workFlexible hours- Ascension is seeking a Lead Clinical Document Specialist - Rapid Response for a remote, full-time opportunity. You will address urgent CDI issues, drive rapid-cycle audits, and collaborate across departments to ensure documentation and coding integrity. The role emphasizes...Remote jobFull time
- TTEC is seeking an Incident Response Manager to lead the cybersecurity incident response team from a fully remote position in the United States. You will manage detection, containment, and remediation of threats while guiding analysts, developing IR playbooks, and coordinating...Remote job
- Hewlett Packard Enterprise is searching for a Principal Advanced Threat Response Analyst to lead cybersecurity efforts. The role involves extensive hands-on experience in incident response, threat hunting, and investigations of advanced persistent threats. You will collaborate...Remote jobFlexible hours
- Zurich North America is seeking a Senior Incident Response Consultant to deliver expert incident response services. The role involves leading cybersecurity investigations, providing 24/7 emergency response, and managing client relationships during security incidents. Candidates...Remote job
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Detection & Response Lead. Be the first to apply!


