Nebius B.V. logo
Est. Monthly
Estimated €3,828 - €6,000
Posted August 26, 2026 · 0 days agoLast seen August 26, 2026Est. expiry September 30, 2026

Offensive Security Lead

Remote - Europe
Remote · Technology
Full-time · Senior
English
No People Management
6 years experience
How this salary compares
Salary Context: Offensive Security Lead

Hover or tap a row for full statistics (EUR / month on this chart).

Salary analysis

Compared with the selected benchmark ("Company in Remote - Europe"), this listing's salary midpoint is about 89% lower. The offer sits below the benchmark range (€1,667–€6,000). The listed pay band (€319–€500) is tighter than the benchmark, which suggests lower salary variability. This benchmark is based on 6 comparable listings.

Monthly salary comparison for Offensive Security Lead
MarketLower bound (25th percentile)MedianUpper bound (75th percentile)
All roles in Remote - Europe€1,978/per month€4,914/per month€13,713/per month
Company in Remote - Europe€1,667/per month€2,056/per month€6,000/per month
Pay in our data — not quoted in ad (Senior)€319/per month€410/per month€500/per month
About the role

The Role\nWe're hiring an Offensive Security Lead to build and run Nebius' red team capability. You'll design and execute adversarial simulation across our cloud platform - attacking the same infrastructure our customers depend on - and translate findings into measurable security improvements. This is a hands-on leadership role within Product Security Team. You will build an internal red team, establish a penetration testing program, and conduct research to uncover sophisticated attack scenarios targeting high-value assets across the Nebius tech stack.\nWhat you’ll do\nBuild and lead a red team function within Product Security Team, hiring and developing offensive security engineers.\nValidate and extend early-stage Secure SDLC threat models via continuous penetration testing, assessing threat severity and mitigation status while challenging assumptions made during threat modeling and system development. Automate routine validations to keep pace with increasing feature flow, reserving manual analysis for genuinely complex cases.\nPlan and execute full-scoped red team engagements against Nebius cloud platform - including compute, storage, inference, networking, orchestration layers, and internal tooling. Identify threats, which are able to impact an organization's operations. Work closely with Detection & Response and other security engineering teams to run purple team exercises, validate detection coverage, and close gaps collaboratively.\nResearch novel attacks against GPU infrastructure (e.g., closed-source firmware and vendor driver binaries, device passthrough exploits, SR-IOV/IOMMU misconfigurations, RDMA/InfiniBand fabric attacks, etc.), the inference stack (e.g., vLLM, TRT-LLM), and AI platform managed services (e.g., managed Slurm). Assess tenant-isolation boundaries and how they can be broken at the low-level stack\nConduct targeted assessments of new products and infrastructure changes before they ship.\nDeliver clear, actionable reports for both technical audiences and leadership - with prioritized findings and remediation guidance.\nEstablish red team processes, tooling, and a methodology that scales as the platform grows.

Job Details

Responsibilities

  • Build and lead a red team function within Product Security Team, hiring and developing offensive security engineers.
  • Validate and extend early-stage Secure SDLC threat models via continuous penetration testing, assessing threat severity and mitigation status while challenging assumptions made during threat modeling and system development.
  • Plan and execute full-scoped red team engagements against Nebius cloud platform - including compute, storage, inference, networking, orchestration layers, and internal tooling.
  • Identify threats, which are able to impact an organization's operations.
  • Work closely with Detection & Response and other security engineering teams to run purple team exercises, validate detection coverage, and close gaps collaboratively.
  • Research novel attacks against GPU infrastructure, the inference stack, and AI platform managed services.
  • Conduct targeted assessments of new products and infrastructure changes before they ship.
  • Deliver clear, actionable reports for both technical audiences and leadership - with prioritized findings and remediation guidance.
  • Establish red team processes, tooling, and a methodology that scales as the platform grows.

Requirements

  • 6+ years in offensive security - penetration testing, red teaming, or adversary simulation - with at least 1-2 years leading or mentoring a team.
  • Deep experience attacking cloud-native environments: Kubernetes privilege escalation, cloud IAM abuse, virtualization and container escapes.
  • Strong fundamentals across the attack lifecycle: initial access, persistence, lateral movement, data exfiltration.
  • Proficiency developing custom tooling and post-exploitation capabilities (Python, Go, or similar).
  • Experience running purple team exercises and working constructively with blue teams.
  • Ability to write clear, senior-level reports with business-contextualized risk (not just raw findings) that engineers can easily use.

Skills & Technologies

PythonGoCloud toolingPenetration testingKubernetesSR-IOV/IOMMUeBPF (nice to have)
Seen 73 minutes agoOpen ApplicationPartial Schema
Nebius B.V. logo
Nebius B.V. · 841 open roles
Top locations: Remote - Global · 567 · Remote - Europe · 81 · Amsterdam, Netherlands · 29+55 other locations
View company
Most-hired roles
Backend Engineer
484
Software Engineer
79
Account Executive
76
Sales Representative
4
Data Center Technician
3
Role-level mix
Mid-Level (572)Senior (16)Manager (7)Executive (1)

Help us improve JobCrawls — sign in to sync saved jobs across devices, or send feedback anytime.