Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Detection & Response Lead

Full-time

Nebius

Role Description

We're hiring a Detection & Response Lead to build and run our D&R capability from the ground up. You'll own the detection engineering, threat intelligence, and incident response functions across Nebius Cloud and lead a small, growing team of analysts and engineers. This is a lead engineering role responsible for:

  • Detection development: achieve full MITRE coverage, maintain low false-positive and false-negative rates.
  • Working closely with alerts consumers (20+ teams) to keep noise low and signal high, ensuring they can act quickly without missing genuine threats.
  • Architecting and operating detection coverage across our cloud and bare-metal environments.
  • Building and extending our internal D&R tools and pipelines - onboarding new logs, building and automating response runbooks.
  • Integrating threat intelligence into detection logic and IR playbooks, tracking adversary TTPs relevant to Cloud infrastructure.
  • Leading incident response end-to-end: scoping, containment, root cause analysis, post-incident reviews, and controlling critical action items to prevent future incidents.
  • Partnering with Compliance and Engineering teams to detect real threats while meeting the needs of both engineers and regulators.
  • Defining and reporting on D&R metrics: MTTD, MTTR, detection coverage, false positive rates, etc.
  • Building and maintaining the Security Incident Response program: people, processes, tools.
  • Building tools, runbooks, and on-call processes that scale as the company grows.

Qualifications

  • 6+ years in security operations, detection engineering, or incident response — with at least 1–2 years leading or mentoring a team.
  • Deep hands-on experience with cloud-native environments (Kubernetes, Linux workloads, container-based infrastructure).
  • Strong detection engineering skills: writing and tuning rules/detections in SIEM platforms (e.g., Chronicle, Splunk, Elastic) and SQL.
  • Experience building or operating SOAR workflows and automating response at scale (ideally with Golang and Temporal).
  • Working knowledge of threat intelligence frameworks (MITRE ATT&CK, Pyramid of Pain, Kill Chain) and how to operationalize them in detections.
  • Solid IR fundamentals: memory forensics, log analysis, network traffic analysis, and post-incident reporting.
  • Stakeholder management: able to coordinate across engineers, compliance, legal, executives during active incident phase.

Requirements

  • Experience with AI/ML and GPU clusters related threats (nice to have).
  • Familiarity with eBPF-based detection or runtime security tooling (Falco, Tetragon) (nice to have).
  • Background in threat hunting (nice to have).

Benefits

  • Competitive compensation with equity upside in a Nasdaq-listed, high-growth company.
  • Flexible, remote-first culture.
  • Career growth and learning opportunities.
  • Flexibility and ownership.
  • Collaborative and innovative culture.
  • Opportunity to work on impactful AI projects.
  • International environment and talented teams.
Vacancy posted a month ago
Similar jobs that could be interesting for youBased on the Detection & Response Lead in Remote vacancy
  • $10k

     ...move and manage billions, Ramp is the place to do it.About the RoleJoin our growing security team and help drive security detection and response initiatives across Ramp. This will include a focus on maturing our security detection and alerting capabilities across our... 
    Suggested
    Full time
    Work experience placement
    Work at office
    Home office
    Flexible hours

    Ramp

    New York, NY
    23 hours ago
  •  ...technology and data-driven commercial MGA and insurance wholesaler leading innovation in the market. Backed by one of the leading...  ...is seeking a senior, hands‑on defender to build a detection and response function responsible for defensive security operations across... 
    Suggested

    Integrated Specialty Coverages, LLC

    New York, NY
    23 hours ago
  • $164.9k - $245k

     ...sharing the airspace is non-negotiable. Detect and Avoid (DAA) is how our aircraft sense...  ...by our dedicated radar team.As the DAA Lead, you own the DAA capability across that...  ...into a shipped, certifiable product. Responsibilities Own DAA as a portfolio, not a point solution... 
    Suggested
    Permanent employment
    Full time
    Temporary work
    Remote work

    Joby Aviation

    Santa Cruz, CA
    4 days ago
  • The Cybersecurity Security Operations Center (CSOC) Incident Response (IR) Lead is a cybersecurity professional responsible for overseeing...  ...knowledge of network security, malware analysis, intrusion detection, and related technologies.Excellent communication and interpersonal... 
    Suggested
    Contract work
    For contractors
    Local area
    Remote work

    Sherwin-Williams

    Cleveland, OH
    23 hours ago
  • $140k - $150k

    Job DescriptionEverforth ECS is seeking an Incident Response Lead to work in our Washington, DC office / remote. The role is contingent...  ...operations specialist consisting of hunting threats, developing detection mechanisms, refining processes, and elevating the... 
    Suggested
    Work at office
    Remote work

    ECS Federal

    Washington DC
    23 hours ago
  • $40 - $80 per hour

     ...Incident Response Lead, Cyber Security $40-80/hr Remote Freelance CODING About the Role What if your hard-won experience in the SOC trenches could directly strengthen how organizations detect, respond to, and contain real threats? We're looking for a seasoned... 
    Hourly pay
    Ongoing contract
    Contract work
    Freelance
    Remote work
    Flexible hours
    Night shift

    Alignerr

    United States
    4 days ago
  • $240k - $280k

     ...Your Responsibilities Will Include Obsidian Security is the leading SaaS security platform, trusted by global enterprises like Snowflake, T-Mobile, and Algolia. We...  ...a complete SaaS security platform to reduce risk, detect and respond to threats, and prevent breaches at the... 
    Work from home

    Obsidian Security

    Palo Alto, CA
    23 hours ago
  • $10k

     ...About The Role Join our growing security team and help drive security detection and response initiatives across Ramp. This will include a focus on maturing our security detection and alerting capabilities across our federal and public sector environments. Please note... 
    Full time
    Work experience placement
    Work at office
    Home office
    Relocation package
    Flexible hours
    2 days per week

    RAMP

    New York, NY
    23 hours ago
  •  ...Financial Group (MUFG), one of the world’s leading financial groups. Across the globe, we’...  ...actions based upon that analysis. Responsibilities include rapidly responding to potential...  ...the development of security operations detections, playbooks, and automations to ensure threat... 
    Full time
    Work at office
    Local area
    Remote work
    1 day per week

    MUFG

    Tempe, AZ
    23 hours ago
  • First Citizens Bank is seeking a Senior Incident Response Analyst for a remote role that can be hired in multiple U.S. markets. You will join the Cyber Incident Response team, detecting and responding to threats, interacting with business stakeholders, and restoring operations... 
    Remote job

    First Citizens Bank

    Phoenix, AZ
    3 days ago
  •  ...Expert (SME) to provide deep domain expertise supporting fraud detection and identity theft analytics initiatives. This role guides...  ...programs within government or financial institutions. Responsibilities include but are not limited to: Provide domain expertise in... 
    Full time
    Work at office
    Local area
    Remote work

    Elder Research Inc.

    Arlington, VA
    4 days ago
  • First Citizens Bank is seeking a Senior Incident Response Analyst to join the Cyber Incident Response team in a remote role across the United States. The candidate will detect and respond to threats, interact with business stakeholders, and restore operations while mentoring... 
    Remote job

    First Citizens Bank

    Scottsdale, AZ
    23 hours ago
  • ZKM Consulting is seeking a Lead SOC Analyst to support a client on a CNI project, focusing on maintaining compliance with...  ...during investigations. The role requires strong SOC operations experience, incident response and threat detection, #J-18808-Ljbffr ZKM Consulting
    Remote job

    ZKM Consulting

    New York, NY
    1 day ago
  •  ...Angeles, CA. Triskele Labs are one of the leading providers of cybersecurity services in...  ...Triskele Labs Digital Forensics and Incident Response (DFIR) team assists clients of all sizes...  ...SpectreOps - Adversary Tactics: Detection Application Process A cover letter addressed... 
    Remote job
    Work at office

    Triskele Labs

    Los Angeles, CA
    23 hours ago
  • $126k - $180k

     ...appropriate actions based on that analysis. Responsibilities include rapidly responding to potential...  .... Develop security operations detection playbooks, and automate threat detection...  ...processes align with policies and regulations. Lead and mentor junior analysts as needed.... 
    Work at office
    Local area
    Remote work
    1 day per week

    MUFG Bank, Ltd.

    Tempe, AZ
    2 days ago
  •  ...Position Title: Cyber Security Incident Response Lead Location: Texas (Teleworker) Clearance Requirements: Public Trust Clearance Pay Rate: Competitive salary based on experience Position Description: We are seeking a highly skilled and experienced Cyber... 
    For contractors
    Remote work

    Seneca

    United States
    4 days ago
  • $162.8k - $303k

     ...Job Number: R0247651 Global Incident Response Business Development Leader The Opportunity Serve as the Global Business Development Leader...  ...partners, and direct enterprise relationships with our IR retainer. Lead and develop a global team of business development, relationship,... 
    Full time
    Contract work
    Part time
    Work at office
    Local area
    Remote work

    Booz Allen Hamilton

    Crane, IN
    2 days ago
  • $100k - $120k

     ...This position requires a Bachelor's degree and a minimum of 8 years of IT experience, including 4 years specifically in incident response. An active Secret clearance is also essential. The role involves overseeing incident operations, ensuring compliance with standards... 
    Remote work

    SkyePoint Decisions

    New York, NY
    4 days ago
  •  ...Arrow Components is seeking an Information Technology Manager II to lead advanced cyber incident investigations across enterprise environments. You will direct end-to-end incident response, preserve evidence, and deliver executive summaries with remediation guidance.... 
    Remote work

    Arrow Components Corp

    Colorado Springs, CO
    1 day ago
  •  ...Senior Midmarket Account Executive: Detection & Response Antigen Security is a rapidly growing Technology Services Distributor specializing...  ...& Response, your role is to consistently generate qualified leads, carry and exceed quota, and help customers address their... 
    Work experience placement
    Remote work

    Antigen Security

    Royal Oak, MI
    1 day ago
  •  ...reporting to the Cyber Monitoring and Incident Response Team Director, you are responsible for...  ...team of analysts and associates who detect, investigate, and respond to cyber security...  ...DTCC.Utilize metrics, feedback from team leads, feedback from stakeholders, threat intelligence... 
    Remote work
    Flexible hours

    DTCC- The Depository Trust & Clearing Corporation

    Tampa, FL
    23 hours ago
  • $225.4k - $281.8k

     ...Apollo.io is the leading go-to-market solution for revenue teams, trusted by over 500,000 companies and millions of users globally...  ...a startup-minded Engineering Manager to lead our Security Detection & Response team. You’ll build and scale a team that ships detection... 
    Full time
    Remote work
    Worldwide
    Flexible hours

    Apollo.io

    Remote
    3 days ago
  • $151k - $208k

     ...Palo Alto Networks, Inc. is looking for a Principal Consultant in Burbank, California, responsible for leading incident response and digital forensics services. This role involves serving as a technical leader on investigations and guiding clients through security incidents... 
    Remote job

    Jobleads-US

    Burbank, CA
    1 day ago
  • Runway is seeking a seasoned GRC professional to lead governance, risk, and compliance across the US, with remote options. You will shape frameworks that balance security and responsible AI, working closely with product, engineering, and legal teams. Responsibilities include... 
    Remote job

    Runway Financial

    New York, NY
    4 days ago
  • SecureBio is seeking a Public Health Response Manager in Cambridge, MA (or DC or remote for outstanding candidates) to lead engagement with state and local health officials, translate biosurveillance findings into action, and shape response protocols. You will build trust... 
    Remote job
    Local area

    SecureBio, LLC

    Cambridge, MA
    23 hours ago
  • $75.04k - $112.56k

    Ahold Delhaize USA is seeking a Major Incident Management Analyst responsible for leading the response to major incidents. This role supports communication and coordination between stakeholders and will ensure the swift resolution of incidents. The position includes a flexible... 
    Remote work
    Flexible hours

    ViziRecruiter,LLC.

    Salisbury, NC
    2 days ago
  • Ascension is seeking a Lead Clinical Document Specialist - Rapid Response for a remote, full-time opportunity. You will address urgent CDI issues, drive rapid-cycle audits, and collaborate across departments to ensure documentation and coding integrity. The role emphasizes... 
    Remote job
    Full time

    Ascension

    New York, NY
    4 days ago
  • TTEC is seeking an Incident Response Manager to lead the cybersecurity incident response team from a fully remote position in the United States. You will manage detection, containment, and remediation of threats while guiding analysts, developing IR playbooks, and coordinating... 
    Remote job

    TTEC

    Austin, TX
    23 hours ago
  • Hewlett Packard Enterprise is searching for a Principal Advanced Threat Response Analyst to lead cybersecurity efforts. The role involves extensive hands-on experience in incident response, threat hunting, and investigations of advanced persistent threats. You will collaborate... 
    Remote job
    Flexible hours

    Hewlett Packard Enterprise

    Spring, Montgomery County, TX
    1 day ago
  • Zurich North America is seeking a Senior Incident Response Consultant to deliver expert incident response services. The role involves leading cybersecurity investigations, providing 24/7 emergency response, and managing client relationships during security incidents. Candidates... 
    Remote job

    Zurich North America

    Kansas City, MO
    23 hours ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Detection & Response Lead. Be the first to apply!