Nebius B.V. logo

Incident Response Lead - Nebius B.V. - Tel Aviv, Israel

Posted: July 23, 2026
Posted today
Last seen in crawl: July 23, 2026 (today)
Estimated Expiry: August 27, 2026
Remoteness
Role & Management
Role Level:Senior
Management Tier:No People Management
Job Type
Experience
8 years

Job Description

Nebius is seeking a deeply technical Incident Response Lead to build and lead the company’s global incident response capability - its people, tooling, and methodology - while remaining the hands-on technical authority on the hardest investigations. Reporting into the CISO Office, the Lead grows and directs a follow-the-sun team of responders across EMEA, Asia, and APAC, owning response execution and quality across Nebius’ cloud, infrastructure, and platform environments. This is a hands-on role that balances deep technical work alongwith building and running the function: the Lead drives high-severity incidents end-to-end, serves as the escalation ceiling, and sets the standards and structure the team operates by. You’re welcome to work in our offices in Tel Aviv, Israel. Your responsibilities will include: - Build and lead Nebius’ global IR capability - select and mature DFIR tooling, and establish the playbooks and follow-the-sun operating model across EMEA, Asia, and APAC while hiring and developing a team of responders. - Lead the technical response to major incidents hands-on - from escalation through containment, eradication, and recovery - and act as the final technical authority on the most complex cases. - Personally conduct end-to-end forensic investigations across cloud, platform, and endpoint environments - log analysis at scale, host and network forensics, memory analysis, malware triage, and timeline reconstruction. - Define and enforce consistent investigation standards across the team: severity and escalation criteria, cross-region handoff quality, and evidence handling that meets legal, regulatory, and forensic requirements. - Partner with the SOC, SOC Automation, Threat Intelligence, Threat Hunting, and Platform Security teams to improve detection fidelity and reduce MTTD and MTTR. - Serve as the technical voice of incident response to executive leadership, Legal, and Privacy - delivering clear, risk-based briefings, regulatory-ready documentation, and root cause analyses (RCA). - Raise the team’s technical bar through case reviews and hands-on mentoring, and drive lessons-learned into measurable improvements in controls and readiness. We expect you to have: Experience - 8+ years of hands-on incident response and digital forensics, including technical leadership of large-scale, high-impact incidents (ransomware, nation-state / advanced threat actors, cloud intrusions, identity compromise). - Experience building or leading IR teams and capabilities in cloud or infrastructure-heavy environments, which are highly regulated (SOC 2, ISO 27001, GDPR/NIS2). Technical Expertise - Deep knowledge of Windows and Linux internals, with proven disk and memory forensics capability. - Strong cloud-native platform security: containers and Kubernetes, CI/CD, secrets management, cloud control planes, and IAM attack paths. - Fluency in attacker TTPs (MITRE ATT&CK, including the Cloud and Containers matrices), and hands-on experience with EDR, SIEM, and forensic tooling (e.g., Velociraptor, Volatility, X-Ways/EnCase). - Strong scripting and data-analysis skills (Python, PowerShell, SQL/KQL) for investigation at scale, with the ability to validate findings independently and challenge assumptions. Leadership & Communication - Proven ability to lead under pressure and make high-quality decisions with incomplete data; technical leadership through credibility across regions, without relying on direct authority. - Clear, concise communicator capable of briefing executives, Legal, Privacy, and non-technical stakeholders. - Working knowledge of spoken and written English

Company Information

Nebius B.V. logo
Technology
Headcount: 1,500
Current open roles at Nebius B.V. on JobCrawls
LocationActive listings
Remote - Global559
Remote - Europe57
Remote - Finland25
Remote - United States20
Amsterdam, Netherlands19
Berlin, Germany13
Mäntsälä, Finland11
Helsinki, Finland11
London, United Kingdom7
Amsterdam5
Canada4
Israel4
Remote3
Singapore3
Abu Dhabi2
France, Paris2
Dubai2
London2
Berlin1
Abu Dhabi, Dubai1
Singapore, Singapore1
Czechia1
Finland1
San Francisco Bay Area, United States1
Prague1
New York City, United States1
California, United States1
Remote - Asia1
Paris1
Kansas City, United States1
Minnesota, United States1
UK1
Béthune, France1
Remote - DACH1
East London, United Kingdom1
Austin, United States1
Austin, Texas1
Remote - Singapore1
Prague, Czech Republic1
Béthune, Pas-de-Calais, France1
Netherlands1
Remote - Benelux1
Remote - Middle East1
Paris, France1
United Kingdom1
Alabama, US1
Abu Dhabi, United Arab Emirates1
Tel Aviv, Israel1
Philadelphia, United States1
Remote - North America1
Dallas, United States1
New Jersey, US1
New Jersey, United States1
Oklahoma, United States1
London, UK1
Remote - France1
Canada, Remote - United States1
Current role mix at Nebius B.V. on JobCrawls
Role typeActive listings
Backend Engineer484
Software Engineer77
Account Executive76
Sales Representative4
Product Manager3
Backend engineers, Frontend engineers, Site reliability engineers2
Open Positions at Nebius2
Data Center Operations Technician2
Data Center Technician2
Head of Channel Marketing1
Data Scientist1
VP of Developer Relations & Community1
Human Resources Specialist1
Data Center IT Technician1
Generalist1
Operations Specialist1
System Engineer1
Backend Engineers1
Data Center IT Manager1
Accountant1
Data Center Logistics Specialist1
Data Engineer1
Current role-level mix at Nebius B.V. on JobCrawls
Role levelActive listings
Mid-Level561

Nebius B.V. appears in 788 indexed job postings in JobCrawls' Finland dataset since October 2023. In that historical index, the strongest location signals for this employer are Remote - Global, Remote - Europe, and Remote - Finland.

Data shown is based on historical job postings from our database.

Job Details

Responsibilities

  • Build and lead Nebius' global IR capability, including DFIR tooling and follow-the-sun operating models
  • Lead technical response to major incidents from escalation through recovery
  • Conduct end-to-end forensic investigations across cloud, platform, and endpoint environments
  • Define and enforce consistent investigation standards and evidence handling
  • Collaborate with SOC, Threat Intelligence, and Platform Security to reduce MTTD and MTTR
  • Provide risk-based briefings and root cause analyses (RCA) to executive leadership, Legal, and Privacy
  • Mentor the team through case reviews to raise the technical bar

Requirements

  • 8+ years of hands-on incident response and digital forensics experience
  • Technical leadership of large-scale, high-impact incidents (ransomware, nation-state actors, cloud intrusions)
  • Experience building or leading IR teams in highly regulated cloud or infrastructure environments (SOC 2, ISO 27001, GDPR/NIS2)
  • Deep knowledge of Windows and Linux internals
  • Proven disk and memory forensics capability
  • Expertise in containers, Kubernetes, CI/CD, secrets management, and IAM attack paths
  • Fluency in MITRE ATT&CK TTPs
  • Hands-on experience with EDR, SIEM, and forensic tools (e.g., Velociraptor, Volatility, X-Ways/EnCase)
  • Proficiency in Python, PowerShell, and SQL/KQL
  • Ability to lead under pressure and make decisions with incomplete data
  • Strong communication skills for briefing executives and non-technical stakeholders
  • Working knowledge of spoken and written English

Skills & Technologies

Windows InternalsLinux InternalsKubernetesContainersCI/CDIAMMITRE ATT&CKEDRSIEMVelociraptorVolatilityX-WaysEnCasePythonPowerShellSQLKQL
19 hours agoPartial Schema

Help us improve JobCrawls — sign in to sync saved jobs across devices, or send feedback anytime.