
Lead Detection Engineer - Nebius B.V. - Tel Aviv, Israel
Detection Engineer
Job Description
Nebius is looking for a Lead Detection Engineer. This is an individual contributor role with full technical ownership. You'll set the direction for detection engineering: the standards, the tooling, the coverage strategy, and the automation that operationalizes it all. You'll work closely with SOC analysts and Platform Engineering to make detection a first-class engineering discipline. You’re welcome to work in our offices in Tel Aviv, Israel Your responsibilities will include: - Detection coverage strategy across endpoint, identity, cloud, and infrastructure — how it's measured, prioritized, and continuously improved. - Detection-as-Code pipeline: version control, testing, peer review, CI/CD, and deployment practices for all detection logic. - Architecture connecting detections to enrichment, triage, and automated response workflows. - Technical standards for how detections are designed, tested, documented, deployed, and retired. - Detection quality: fidelity metrics, false positive reduction, coverage measurement, and continuous validation loops. - Design and build high-fidelity behavioral detections across SIEM and EDR platforms. - Research emerging attacker techniques and translate threat intelligence into scalable, evasion-resistant detections. - Validate detections through threat simulations and continuous detection testing. - Partner with SOC analysts to close the feedback loop between detections and real investigations. - Define and track detection engineering metrics; communicate coverage posture and effectiveness to security leadership. - Make architectural decisions that scale as the team and organization grow. We expect you to have: - Minimum 3 years in detection engineering, security operations, or a hybrid offensive/defensive role — with demonstrated depth, not just breadth. - Experience owning or leading detection engineering work as a senior technical contributor - Strong understanding of attacker tradecraft and adversary behavior. - Hands-on experience with at least one enterprise SIEM and EDR platform — Splunk, Microsoft Sentinel, CrowdStrike, or equivalent. - Strong query development skills in SPL, KQL, Sigma, or similar. - Solid engineering practices: Git, CI/CD, code review, Detection-as-Code workflows. - Experience using MITRE ATT&CK to design, validate, and measure detection coverage - Ability to make and defend technical decisions and establish standards others adopt. It will be an added bonus if you have: - Offensive security background or certifications. - Experience with threat hunting and detection validation frameworks. - Experience designing SOAR playbooks and automated response workflows. - Cloud security depth across Azure, AWS, or GCP. - Experience building AI-assisted detection, investigation, or triage workflows.
Company Information
| Location | Active listings |
|---|---|
| Remote - Global | 559 |
| Remote - Europe | 57 |
| Remote - Finland | 25 |
| Remote - United States | 20 |
| Amsterdam, Netherlands | 19 |
| Berlin, Germany | 13 |
| Helsinki, Finland | 11 |
| Mäntsälä, Finland | 11 |
| London, United Kingdom | 7 |
| Amsterdam | 5 |
| Canada | 4 |
| Israel | 4 |
| Singapore | 3 |
| Remote | 3 |
| London | 2 |
| Abu Dhabi | 2 |
| France, Paris | 2 |
| Dubai | 2 |
| Remote - France | 1 |
| Remote - DACH | 1 |
| United Kingdom | 1 |
| Singapore, Singapore | 1 |
| Alabama, US | 1 |
| East London, United Kingdom | 1 |
| Austin, Texas | 1 |
| Minnesota, United States | 1 |
| Philadelphia, United States | 1 |
| Remote - Middle East | 1 |
| Remote - North America | 1 |
| Abu Dhabi, Dubai | 1 |
| Prague, Czech Republic | 1 |
| Prague | 1 |
| Kansas City, United States | 1 |
| Berlin | 1 |
| Czechia | 1 |
| Austin, United States | 1 |
| Remote - Benelux | 1 |
| Remote - Asia | 1 |
| Canada, Remote - United States | 1 |
| New York City, United States | 1 |
| Netherlands | 1 |
| Dallas, United States | 1 |
| Abu Dhabi, United Arab Emirates | 1 |
| New Jersey, United States | 1 |
| Finland | 1 |
| California, United States | 1 |
| San Francisco Bay Area, United States | 1 |
| Béthune, Pas-de-Calais, France | 1 |
| UK | 1 |
| Oklahoma, United States | 1 |
| Remote - Singapore | 1 |
| Tel Aviv, Israel | 1 |
| London, UK | 1 |
| Béthune, France | 1 |
| Paris, France | 1 |
| Paris | 1 |
| New Jersey, US | 1 |
| Role type | Active listings |
|---|---|
| Backend Engineer | 484 |
| Software Engineer | 77 |
| Account Executive | 76 |
| Sales Representative | 4 |
| Product Manager | 3 |
| Backend engineers, Frontend engineers, Site reliability engineers | 2 |
| Data Center Operations Technician | 2 |
| Data Center Technician | 2 |
| Open Positions at Nebius | 2 |
| Data Engineer | 1 |
| Data Center Logistics Specialist | 1 |
| Backend Engineers | 1 |
| Data Scientist | 1 |
| Head of Channel Marketing | 1 |
| Data Center IT Technician | 1 |
| Human Resources Specialist | 1 |
| Generalist | 1 |
| Accountant | 1 |
| VP of Developer Relations & Community | 1 |
| System Engineer | 1 |
| Operations Specialist | 1 |
| Data Center IT Manager | 1 |
| Role level | Active listings |
|---|---|
| Mid-Level | 561 |
Nebius B.V. appears in 788 indexed job postings in JobCrawls' Finland dataset since October 2023. In that historical index, the strongest location signals for this employer are Remote - Global, Remote - Europe, and Remote - Finland.
Data shown is based on historical job postings from our database.
Job Details
Responsibilities
- Develop detection coverage strategy across endpoint, identity, cloud, and infrastructure
- Implement and manage Detection-as-Code pipeline (version control, testing, CI/CD)
- Design architecture connecting detections to enrichment, triage, and automated response
- Establish technical standards for detection design, testing, and deployment
- Manage detection quality through fidelity metrics and false positive reduction
- Build high-fidelity behavioral detections across SIEM and EDR platforms
- Translate threat intelligence into scalable, evasion-resistant detections
- Validate detections via threat simulations and continuous testing
- Collaborate with SOC analysts to improve investigation feedback loops
- Define and track detection engineering metrics for security leadership
- Make scalable architectural decisions for the organization
Requirements
- Minimum 3 years in detection engineering, security operations, or a hybrid offensive/defensive role
- Experience owning or leading detection engineering work as a senior technical contributor
- Strong understanding of attacker tradecraft and adversary behavior
- Hands-on experience with at least one enterprise SIEM and EDR platform (e.g., Splunk, Microsoft Sentinel, CrowdStrike)
- Strong query development skills in SPL, KQL, Sigma, or similar
- Proficiency in Git, CI/CD, code review, and Detection-as-Code workflows
- Experience using MITRE ATT&CK to design, validate, and measure detection coverage
- Ability to make and defend technical decisions and establish standards
Skills & Technologies
