Nebius B.V. logo

Lead Detection Engineer - Nebius B.V. - Tel Aviv, Israel

Detection Engineer

Posted: July 24, 2026
Posted today
Last seen in crawl: July 23, 2026 (today)
Estimated Expiry: August 28, 2026
Remoteness
Role & Management
Role Level:Senior
Management Tier:No People Management
Job Type
Experience
3 years

Job Description

Nebius is looking for a Lead Detection Engineer. This is an individual contributor role with full technical ownership. You'll set the direction for detection engineering: the standards, the tooling, the coverage strategy, and the automation that operationalizes it all. You'll work closely with SOC analysts and Platform Engineering to make detection a first-class engineering discipline. You’re welcome to work in our offices in Tel Aviv, Israel Your responsibilities will include: - Detection coverage strategy across endpoint, identity, cloud, and infrastructure — how it's measured, prioritized, and continuously improved. - Detection-as-Code pipeline: version control, testing, peer review, CI/CD, and deployment practices for all detection logic. - Architecture connecting detections to enrichment, triage, and automated response workflows. - Technical standards for how detections are designed, tested, documented, deployed, and retired. - Detection quality: fidelity metrics, false positive reduction, coverage measurement, and continuous validation loops. - Design and build high-fidelity behavioral detections across SIEM and EDR platforms. - Research emerging attacker techniques and translate threat intelligence into scalable, evasion-resistant detections. - Validate detections through threat simulations and continuous detection testing. - Partner with SOC analysts to close the feedback loop between detections and real investigations. - Define and track detection engineering metrics; communicate coverage posture and effectiveness to security leadership. - Make architectural decisions that scale as the team and organization grow. We expect you to have: - Minimum 3 years in detection engineering, security operations, or a hybrid offensive/defensive role — with demonstrated depth, not just breadth. - Experience owning or leading detection engineering work as a senior technical contributor - Strong understanding of attacker tradecraft and adversary behavior. - Hands-on experience with at least one enterprise SIEM and EDR platform — Splunk, Microsoft Sentinel, CrowdStrike, or equivalent. - Strong query development skills in SPL, KQL, Sigma, or similar. - Solid engineering practices: Git, CI/CD, code review, Detection-as-Code workflows. - Experience using MITRE ATT&CK to design, validate, and measure detection coverage - Ability to make and defend technical decisions and establish standards others adopt. It will be an added bonus if you have: - Offensive security background or certifications. - Experience with threat hunting and detection validation frameworks. - Experience designing SOAR playbooks and automated response workflows. - Cloud security depth across Azure, AWS, or GCP. - Experience building AI-assisted detection, investigation, or triage workflows.

Company Information

Nebius B.V. logo
Technology
Headcount: 1,500
Current open roles at Nebius B.V. on JobCrawls
LocationActive listings
Remote - Global559
Remote - Europe57
Remote - Finland25
Remote - United States20
Amsterdam, Netherlands19
Berlin, Germany13
Helsinki, Finland11
Mäntsälä, Finland11
London, United Kingdom7
Amsterdam5
Canada4
Israel4
Singapore3
Remote3
London2
Abu Dhabi2
France, Paris2
Dubai2
Remote - France1
Remote - DACH1
United Kingdom1
Singapore, Singapore1
Alabama, US1
East London, United Kingdom1
Austin, Texas1
Minnesota, United States1
Philadelphia, United States1
Remote - Middle East1
Remote - North America1
Abu Dhabi, Dubai1
Prague, Czech Republic1
Prague1
Kansas City, United States1
Berlin1
Czechia1
Austin, United States1
Remote - Benelux1
Remote - Asia1
Canada, Remote - United States1
New York City, United States1
Netherlands1
Dallas, United States1
Abu Dhabi, United Arab Emirates1
New Jersey, United States1
Finland1
California, United States1
San Francisco Bay Area, United States1
Béthune, Pas-de-Calais, France1
UK1
Oklahoma, United States1
Remote - Singapore1
Tel Aviv, Israel1
London, UK1
Béthune, France1
Paris, France1
Paris1
New Jersey, US1
Current role mix at Nebius B.V. on JobCrawls
Role typeActive listings
Backend Engineer484
Software Engineer77
Account Executive76
Sales Representative4
Product Manager3
Backend engineers, Frontend engineers, Site reliability engineers2
Data Center Operations Technician2
Data Center Technician2
Open Positions at Nebius2
Data Engineer1
Data Center Logistics Specialist1
Backend Engineers1
Data Scientist1
Head of Channel Marketing1
Data Center IT Technician1
Human Resources Specialist1
Generalist1
Accountant1
VP of Developer Relations & Community1
System Engineer1
Operations Specialist1
Data Center IT Manager1
Current role-level mix at Nebius B.V. on JobCrawls
Role levelActive listings
Mid-Level561

Nebius B.V. appears in 788 indexed job postings in JobCrawls' Finland dataset since October 2023. In that historical index, the strongest location signals for this employer are Remote - Global, Remote - Europe, and Remote - Finland.

Data shown is based on historical job postings from our database.

Job Details

Responsibilities

  • Develop detection coverage strategy across endpoint, identity, cloud, and infrastructure
  • Implement and manage Detection-as-Code pipeline (version control, testing, CI/CD)
  • Design architecture connecting detections to enrichment, triage, and automated response
  • Establish technical standards for detection design, testing, and deployment
  • Manage detection quality through fidelity metrics and false positive reduction
  • Build high-fidelity behavioral detections across SIEM and EDR platforms
  • Translate threat intelligence into scalable, evasion-resistant detections
  • Validate detections via threat simulations and continuous testing
  • Collaborate with SOC analysts to improve investigation feedback loops
  • Define and track detection engineering metrics for security leadership
  • Make scalable architectural decisions for the organization

Requirements

  • Minimum 3 years in detection engineering, security operations, or a hybrid offensive/defensive role
  • Experience owning or leading detection engineering work as a senior technical contributor
  • Strong understanding of attacker tradecraft and adversary behavior
  • Hands-on experience with at least one enterprise SIEM and EDR platform (e.g., Splunk, Microsoft Sentinel, CrowdStrike)
  • Strong query development skills in SPL, KQL, Sigma, or similar
  • Proficiency in Git, CI/CD, code review, and Detection-as-Code workflows
  • Experience using MITRE ATT&CK to design, validate, and measure detection coverage
  • Ability to make and defend technical decisions and establish standards

Skills & Technologies

SIEMEDRSplunkMicrosoft SentinelCrowdStrikeSPLKQLSigmaGitCI/CDMITRE ATT&CKAzureAWSGCPSOAR
19 hours agoPartial Schema

Help us improve JobCrawls — sign in to sync saved jobs across devices, or send feedback anytime.