
Hover or tap a row for full statistics (EUR / month on this chart).
Salary analysis
Compared with the selected benchmark ("Company in Tel Aviv, Israel"), this listing's salary midpoint is about 92% lower. The offer sits below the benchmark range (€7,921–€9,896). The offer's range width is broadly in line with the benchmark. This benchmark is based on 1 comparable listings.
| Market | Lower bound (25th percentile) | Median | Upper bound (75th percentile) |
|---|---|---|---|
| All roles in Tel Aviv, Israel | €7,921/per month | €8,909/per month | €9,896/per month |
| Company in Tel Aviv, Israel | €7,921/per month | €8,909/per month | €9,896/per month |
The role Nebius is looking for a Lead Detection Engineer.This is an individual contributor role with full technical ownership. You'll set the direction for detection engineering: the standards, the tooling, the coverage strategy, and the automation that operationalizes it all. You'll work closely with SOC analysts and Platform Engineering to make detection a first-class engineering discipline. You're welcome to work in our offices in Tel Aviv, Israel Your responsibilities will include: Detection coverage strategy across endpoint, identity, cloud, and infrastructure — how it's measured, prioritized, and continuously improved. Detection-as-Code pipeline: version control, testing, peer review, CI/CD, and deployment practices for all detection logic. Architecture connecting detections to enrichment, triage, and automated response workflows. Technical standards for how detections are designed, tested, documented, deployed, and retired. Detection quality: fidelity metrics, false positive reduction, coverage measurement, and continuous validation loops. Design and build high-fidelity behavioral detections across SIEM and EDR platforms. Research emerging attacker techniques and translate threat intelligence into scalable, evasion-resistant detections. Validate detections through threat simulations and continuous detection testing. Partner with SOC analysts to close the feedback loop between detections and real investigations. Define and track detection engineering metrics; communicate coverage posture and effectiveness to security leadership. Make architectural decisions that scale as the team and organization grow. We expect you to have: Minimum 3 years in detection engineering, security operations, or a hybrid offensive/defensive role — with demonstrated depth, not just breadth. Experience owning or leading detection engineering work as a senior technical contributor Strong understanding of attacker tradecraft and adversary behavior. Hands-on experience with at least one enterprise SIEM and EDR platform — Splunk, Microsoft Sentinel, CrowdStrike, or equivalent. Cloud security depth across Azure, AWS, or GCP. Strong query development skills in SPL, KQL, Sigma, or similar. Strong scripting skills (python, powershell etc) Solid engineering practices: Git, CI/CD, code review, Detection-as-Code workflows. Experience using MITRE ATT&CK to design, validate, and measure detection coverage It will be an added bonus if you have: Offensive security background or certifications. Experience with threat hunting and detection validation frameworks. Experience designing SOAR playbooks and automated response workflows. Experience building AI-assisted detection, investigation, or triage workflows. Benefits & Perks: Competitive compensation Career growth and learning opportunities Flexibility and ownership Collaborative and innovative culture Opportunity to work on impactful AI projects International environment and talented teams What's it like to work at Nebius: Fast moving - Bold thinking - Constant growth - Meaningful impact - Trust and real ownership - Opportunity to shape the future of AI Equal Opportunity Statement: Nebius is an equal opportunity employer. We are committed to fostering an inclusive and diverse workplace and to providing equal employment opportunities in all aspects of employment. We do not discriminate on the basis of race, color, religion, sex (including pregnancy), national origin, ancestry, age, disability, genetic information, marital status, veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by applicable law. Applicants must be authorized to work in the country in which they apply and will be required to provide proof of employment eligibility as a condition of hire. If you need accommodations during the application process, please let us know.
Job Details
Responsibilities
- Detection coverage strategy across endpoint, identity, cloud, and infrastructure
- Detection-as-Code pipeline: version control, testing, peer review, CI/CD, and deployment practices for all detection logic
- Architecture connecting detections to enrichment, triage, and automated response workflows
- Technical standards for how detections are designed, tested, documented, deployed, and retired
- Detection quality: fidelity metrics, false positive reduction, coverage measurement, and continuous validation loops
- Design and build high-fidelity behavioral detections across SIEM and EDR platforms
- Research emerging attacker techniques and translate threat intelligence into scalable, evasion-resistant detections
- Validate detections through threat simulations and continuous detection testing
- Partner with SOC analysts to close the feedback loop between detections and real investigations
- Define and track detection engineering metrics; communicate coverage posture and effectiveness to security leadership
- Make architectural decisions that scale as the team and organization grow
Requirements
- Minimum 3 years in detection engineering, security operations, or a hybrid offensive/defensive role.
- Experience owning or leading detection engineering work as a senior technical contributor
- Strong understanding of attacker tradecraft and adversary behavior
- Hands-on experience with at least one enterprise SIEM and EDR platform — Splunk, Microsoft Sentinel, CrowdStrike, or equivalent
- Cloud security depth across Azure, AWS, or GCP
- Strong query development skills in SPL, KQL, Sigma, or similar
- Strong scripting skills (python, powershell etc)
- Solid engineering practices: Git, CI/CD, code review, Detection-as-Code workflows
- Experience using MITRE ATT&CK to design, validate, and measure detection coverage
- Ability to make and defend technical decisions and establish standards others adopt
Skills & Technologies

| Location | Active listings |
|---|---|
| Remote - Global | 398 |
| Remote - Europe | 126 |
| Amsterdam, Netherlands | 57 |
| London, United Kingdom | 22 |
| Remote - United States | 20 |
| Remote - Finland | 18 |
| Berlin, Germany | 16 |
| Mäntsälä, Finland | 12 |
| Helsinki, Finland | 10 |
| Lappeenranta, Finland | 10 |
| Prague, Czech Republic | 8 |
| Israel | 6 |
| Amsterdam | 5 |
| United Kingdom | 5 |
| Canada | 4 |
| Tel Aviv, Israel | 3 |
| Singapore | 3 |
| Remote | 3 |
| Abu Dhabi | 2 |
| New York City, United States | 2 |
| London | 2 |
| Paris, France | 2 |
| Austin, United States | 2 |
| Dubai | 2 |
| France, Paris | 2 |
| Canada, Remote - United States | 1 |
| East London, United Kingdom | 1 |
| Singapore, Singapore | 1 |
| Minnesota, United States | 1 |
| Remote - Israel | 1 |
| Munich, Germany | 1 |
| UK | 1 |
| Berlin | 1 |
| New Jersey, United States | 1 |
| Remote - Germany | 1 |
| Abu Dhabi, Dubai | 1 |
| Prague | 1 |
| New Jersey, US | 1 |
| Remote - United Kingdom | 1 |
| Oklahoma, United States | 1 |
| Finland | 1 |
| California, United States | 1 |
| Abu Dhabi, United Arab Emirates | 1 |
| Czechia | 1 |
| Alabama, US | 1 |
| Béthune, France | 1 |
| Netherlands | 1 |
| Austin, Texas | 1 |
| San Francisco Bay Area, United States | 1 |
| Kansas City, United States | 1 |
| Béthune, Pas-de-Calais, France | 1 |
| Philadelphia, United States | 1 |
| Dallas, United States | 1 |
| London, UK | 1 |
| Israel, Israel | 1 |
| Remote - EU | 1 |
| Paris | 1 |
| Role type | Active listings |
|---|---|
| Backend Engineer | 308 |
| Software Engineer | 82 |
| Account Executive | 54 |
| Site Reliability Engineer | 6 |
| Technical Product Manager | 5 |
| Technical Project Manager | 5 |
| Technical Program Manager | 5 |
| Product Manager | 4 |
| Sales Representative | 4 |
| System Engineer | 4 |
| Data Center Technician | 3 |
| ML Engineer | 3 |
| Data Center Operations Technician | 3 |
| IT Technician | 2 |
| Product Designer | 2 |
| Hypervisor Engineer | 2 |
| Delivery Manager | 2 |
| Backend engineers, Frontend engineers, Site reliability engineers | 2 |
| Open Positions at Nebius | 2 |
| Applied AI Researcher | 2 |
| Head of Channel Marketing | 1 |
| Forward Deployment Engineer | 1 |
| Site Selection & Colocation Manager | 1 |
| Network Engineer | 1 |
| DC IT Support Manager | 1 |
| Application Security Engineer | 1 |
| MEP Engineer | 1 |
| Datacenter IT Technician | 1 |
| Partner Solutions Architect | 1 |
| Customer Engineer | 1 |
| Internal Control Business Partner | 1 |
| Solutions Partner | 1 |
| Senior System Engineer | 1 |
| Senior Technical Program Manager | 1 |
| Solutions Architecture Leader | 1 |
| Electrical Engineer | 1 |
| Data Scientist | 1 |
| Compensation Analyst | 1 |
| Network Planning Project Manager | 1 |
| Data Center IT Manager | 1 |
| Technical Account Manager | 1 |
| Security Solutions Engineer | 1 |
| Cloud Solution Architect | 1 |
| AI and ISV Partner Business Development Manager | 1 |
| Structured Cabling Design Engineer | 1 |
| ML Infrastructure Engineer | 1 |
| Senior Applied AI Solutions Engineer | 1 |
| VP of Developer Relations & Community | 1 |
| Senior Support Engineer | 1 |
| Operations Specialist | 1 |
| Project Development Manager | 1 |
| Backend Developer | 1 |
| Data Center Operations Manager | 1 |
| Data Center IT Technician | 1 |
| Mechanical Design Engineer | 1 |
| Generalist | 1 |
| HPC Engineer | 1 |
| Solutions Architect | 1 |
| Data Center Electrical Lead | 1 |
| Pricing Director | 1 |
| Manager, ML Solutions Architecture | 1 |
| Senior Technical Project Manager | 1 |
| Accountant | 1 |
| Product Growth Analytics Lead | 1 |
| Group Product Manager | 1 |
| Infrastructure Security Engineer | 1 |
| Senior Research Scientist | 1 |
| GTM Recruiting Manager | 1 |
| Technical Due Diligence Manager | 1 |
| Technical Support Engineer | 1 |
| Data Engineer | 1 |
| Machine Learning Engineer | 1 |
| Mechanical Data Center Technician | 1 |
| Sales Engineer | 1 |
| Senior Software Developer | 1 |
| AI/ML Specialist Solutions Architect | 1 |
| Instructional Designer | 1 |
| Vendor Security & Standards Manager | 1 |
| ML Solutions Architect | 1 |
| Physical Security Systems Technician | 1 |
| Mechanical Engineer | 1 |
| Vulnerability Operations Center Lead | 1 |
| IT Risk and Control Manager | 1 |
| VP of Strategic Sales | 1 |
| Human Resources Specialist | 1 |
| Educational Content Author | 1 |
| Offensive Security Lead | 1 |
| Data Center Logistics Specialist | 1 |
| Financial Controller | 1 |
| Applied ML Engineer | 1 |
| Field Technical Lead | 1 |
| Data Center Facilities Manager | 1 |
| Principal | 1 |
| Systems HPC Engineer | 1 |
| Backend Engineers | 1 |
| Role level | Active listings |
|---|---|
| Mid-Level | 387 |
| Senior | 67 |
| Manager | 14 |
| Executive | 3 |
Related Opportunities
Discover more opportunities that match your interests and skills