
Incident Response Lead - Nebius B.V. - Tel Aviv, Israel
Job Description
Nebius is seeking a deeply technical Incident Response Lead to build and lead the company’s global incident response capability - its people, tooling, and methodology - while remaining the hands-on technical authority on the hardest investigations. Reporting into the CISO Office, the Lead grows and directs a follow-the-sun team of responders across EMEA, Asia, and APAC, owning response execution and quality across Nebius’ cloud, infrastructure, and platform environments. This is a hands-on role that balances deep technical work alongwith building and running the function: the Lead drives high-severity incidents end-to-end, serves as the escalation ceiling, and sets the standards and structure the team operates by. You’re welcome to work in our offices in Tel Aviv, Israel. Your responsibilities will include: - Build and lead Nebius’ global IR capability - select and mature DFIR tooling, and establish the playbooks and follow-the-sun operating model across EMEA, Asia, and APAC while hiring and developing a team of responders. - Lead the technical response to major incidents hands-on - from escalation through containment, eradication, and recovery - and act as the final technical authority on the most complex cases. - Personally conduct end-to-end forensic investigations across cloud, platform, and endpoint environments - log analysis at scale, host and network forensics, memory analysis, malware triage, and timeline reconstruction. - Define and enforce consistent investigation standards across the team: severity and escalation criteria, cross-region handoff quality, and evidence handling that meets legal, regulatory, and forensic requirements. - Partner with the SOC, SOC Automation, Threat Intelligence, Threat Hunting, and Platform Security teams to improve detection fidelity and reduce MTTD and MTTR. - Serve as the technical voice of incident response to executive leadership, Legal, and Privacy - delivering clear, risk-based briefings, regulatory-ready documentation, and root cause analyses (RCA). - Raise the team’s technical bar through case reviews and hands-on mentoring, and drive lessons-learned into measurable improvements in controls and readiness. We expect you to have: Experience - 8+ years of hands-on incident response and digital forensics, including technical leadership of large-scale, high-impact incidents (ransomware, nation-state / advanced threat actors, cloud intrusions, identity compromise). - Experience building or leading IR teams and capabilities in cloud or infrastructure-heavy environments, which are highly regulated (SOC 2, ISO 27001, GDPR/NIS2). Technical Expertise - Deep knowledge of Windows and Linux internals, with proven disk and memory forensics capability. - Strong cloud-native platform security: containers and Kubernetes, CI/CD, secrets management, cloud control planes, and IAM attack paths. - Fluency in attacker TTPs (MITRE ATT&CK, including the Cloud and Containers matrices), and hands-on experience with EDR, SIEM, and forensic tooling (e.g., Velociraptor, Volatility, X-Ways/EnCase). - Strong scripting and data-analysis skills (Python, PowerShell, SQL/KQL) for investigation at scale, with the ability to validate findings independently and challenge assumptions. Leadership & Communication - Proven ability to lead under pressure and make high-quality decisions with incomplete data; technical leadership through credibility across regions, without relying on direct authority. - Clear, concise communicator capable of briefing executives, Legal, Privacy, and non-technical stakeholders. - Working knowledge of spoken and written English
Company Information
| Location | Active listings |
|---|---|
| Remote - Global | 559 |
| Remote - Europe | 57 |
| Remote - Finland | 25 |
| Remote - United States | 20 |
| Amsterdam, Netherlands | 19 |
| Berlin, Germany | 13 |
| Mäntsälä, Finland | 11 |
| Helsinki, Finland | 11 |
| London, United Kingdom | 7 |
| Amsterdam | 5 |
| Canada | 4 |
| Israel | 4 |
| Remote | 3 |
| Singapore | 3 |
| Abu Dhabi | 2 |
| France, Paris | 2 |
| Dubai | 2 |
| London | 2 |
| Berlin | 1 |
| Abu Dhabi, Dubai | 1 |
| Singapore, Singapore | 1 |
| Czechia | 1 |
| Finland | 1 |
| San Francisco Bay Area, United States | 1 |
| Prague | 1 |
| New York City, United States | 1 |
| California, United States | 1 |
| Remote - Asia | 1 |
| Paris | 1 |
| Kansas City, United States | 1 |
| Minnesota, United States | 1 |
| UK | 1 |
| Béthune, France | 1 |
| Remote - DACH | 1 |
| East London, United Kingdom | 1 |
| Austin, United States | 1 |
| Austin, Texas | 1 |
| Remote - Singapore | 1 |
| Prague, Czech Republic | 1 |
| Béthune, Pas-de-Calais, France | 1 |
| Netherlands | 1 |
| Remote - Benelux | 1 |
| Remote - Middle East | 1 |
| Paris, France | 1 |
| United Kingdom | 1 |
| Alabama, US | 1 |
| Abu Dhabi, United Arab Emirates | 1 |
| Tel Aviv, Israel | 1 |
| Philadelphia, United States | 1 |
| Remote - North America | 1 |
| Dallas, United States | 1 |
| New Jersey, US | 1 |
| New Jersey, United States | 1 |
| Oklahoma, United States | 1 |
| London, UK | 1 |
| Remote - France | 1 |
| Canada, Remote - United States | 1 |
| Role type | Active listings |
|---|---|
| Backend Engineer | 484 |
| Software Engineer | 77 |
| Account Executive | 76 |
| Sales Representative | 4 |
| Product Manager | 3 |
| Backend engineers, Frontend engineers, Site reliability engineers | 2 |
| Open Positions at Nebius | 2 |
| Data Center Operations Technician | 2 |
| Data Center Technician | 2 |
| Head of Channel Marketing | 1 |
| Data Scientist | 1 |
| VP of Developer Relations & Community | 1 |
| Human Resources Specialist | 1 |
| Data Center IT Technician | 1 |
| Generalist | 1 |
| Operations Specialist | 1 |
| System Engineer | 1 |
| Backend Engineers | 1 |
| Data Center IT Manager | 1 |
| Accountant | 1 |
| Data Center Logistics Specialist | 1 |
| Data Engineer | 1 |
| Role level | Active listings |
|---|---|
| Mid-Level | 561 |
Nebius B.V. appears in 788 indexed job postings in JobCrawls' Finland dataset since October 2023. In that historical index, the strongest location signals for this employer are Remote - Global, Remote - Europe, and Remote - Finland.
Data shown is based on historical job postings from our database.
Job Details
Responsibilities
- Build and lead Nebius' global IR capability, including DFIR tooling and follow-the-sun operating models
- Lead technical response to major incidents from escalation through recovery
- Conduct end-to-end forensic investigations across cloud, platform, and endpoint environments
- Define and enforce consistent investigation standards and evidence handling
- Collaborate with SOC, Threat Intelligence, and Platform Security to reduce MTTD and MTTR
- Provide risk-based briefings and root cause analyses (RCA) to executive leadership, Legal, and Privacy
- Mentor the team through case reviews to raise the technical bar
Requirements
- 8+ years of hands-on incident response and digital forensics experience
- Technical leadership of large-scale, high-impact incidents (ransomware, nation-state actors, cloud intrusions)
- Experience building or leading IR teams in highly regulated cloud or infrastructure environments (SOC 2, ISO 27001, GDPR/NIS2)
- Deep knowledge of Windows and Linux internals
- Proven disk and memory forensics capability
- Expertise in containers, Kubernetes, CI/CD, secrets management, and IAM attack paths
- Fluency in MITRE ATT&CK TTPs
- Hands-on experience with EDR, SIEM, and forensic tools (e.g., Velociraptor, Volatility, X-Ways/EnCase)
- Proficiency in Python, PowerShell, and SQL/KQL
- Ability to lead under pressure and make decisions with incomplete data
- Strong communication skills for briefing executives and non-technical stakeholders
- Working knowledge of spoken and written English
Skills & Technologies
