
Incident Response Lead
Hover or tap a row for full statistics (EUR / month on this chart).
Salary analysis
Compared with the selected benchmark ("Company in Tel Aviv, Israel"), this listing's salary midpoint is about 92% lower. The offer sits below the benchmark range (€7,921–€9,896). The offer's range width is broadly in line with the benchmark. This benchmark is based on 1 comparable listings.
| Market | Lower bound (25th percentile) | Median | Upper bound (75th percentile) |
|---|---|---|---|
| All roles in Tel Aviv, Israel | €7,921/per month | €8,909/per month | €9,896/per month |
| Company in Tel Aviv, Israel | €7,921/per month | €8,909/per month | €9,896/per month |
Nebius is seeking a deeply technical Incident Response Lead to build and lead the company’s global incident response capability - its people, tooling, and methodology - while remaining the hands-on technical authority on the hardest investigations. Reporting into the CISO Office, the Lead grows and directs a follow-the-sun team of responders across EMEA, Asia, and APAC, owning response execution and quality across Nebius’ cloud, infrastructure, and platform environments. This is a hands-on role that balances deep technical work alongwith building and running the function: the Lead drives high-severity incidents end-to-end, serves as the escalation ceiling, and sets the standards and structure the team operates by. You’re welcome to work in our offices in Tel Aviv, Israel. Your responsibilities will include: Build and lead Nebius’ global IR capability - select and mature DFIR tooling, and establish the playbooks and follow-the-sun operating model across EMEA, Asia, and APAC while hiring and developing a team of responders. Lead the technical response to major incidents hands-on - from escalation through containment, eradication, and recovery - and act as the final technical authority on the most complex cases. Personally conduct end-to-end forensic investigations across cloud, platform, and endpoint environments - log analysis at scale, host and network forensics, memory analysis, malware triage, and timeline reconstruction. Define and enforce consistent investigation standards across the team: severity and escalation criteria, cross-region handoff quality, and evidence handling that meets legal, regulatory, and forensic requirements. Partner with the SOC, SOC Automation, Threat Intelligence, Threat Hunting, and Platform Security teams to improve detection fidelity and reduce MTTD and MTTR. Serve as the technical voice of incident response to executive leadership, Legal, and Privacy - delivering clear, risk-based briefings, regulatory-ready documentation, and root cause analyses (RCA). Raise the team’s technical bar through case reviews and hands-on mentoring, and drive lessons-learned into measurable improvements in controls and readiness. We expect you to have: Experience 8+ years of hands-on incident response and digital forensics, including technical leadership of large-scale, high-impact incidents (ransomware, nation-state / advanced threat actors, cloud intrusions, identity compromise). Experience building or leading IR teams and capabilities in cloud or infrastructure-heavy environments, which are highly regulated (SOC 2, ISO 27001, GDPR/NIS2). Technical Expertise Deep knowledge of Windows and Linux internals, with proven disk and memory forensics capability. Strong cloud-native platform security: containers and Kubernetes, CI/CD, secrets management, cloud control planes, and IAM attack paths. Fluency in attacker TTPs (MITRE ATT&CK, including the Cloud and Containers matrices), and hands-on experience with EDR, SIEM, and forensic tooling (e.g., Velociraptor, Volatility, X-Ways/EnCase). Strong scripting and data-analysis skills (Python, PowerShell, SQL/KQL) for investigation at scale, with the ability to validate findings independently and challenge assumptions. Leadership & Communication Proven ability to lead under pressure and make high-quality decisions with incomplete data; technical leadership through credibility across regions, without relying on direct authority. Clear, concise communicator capable of briefing executives, Legal, Privacy, and non-technical stakeholders. Working knowledge of spoken and written English Benefits & Perks: Competitive compensation Career growth and learning opportunities Flexibility and ownership Collaborative and innovative culture Opportunity to work on impactful AI projects International environment and talented teams What Nebius is like to work at: Fast moving - Bold thinking - Constant growth - Meaningful impact - Trust and real ownership - Opportunity to shape the future of AI Equal Opportunity Statement: Nebius is an equal opportunity employer. We are committed to fostering an inclusive and diverse workplace and to providing equal employment opportunities in all aspects of employment. We do not discriminate on the basis of race, color, religion, sex (including pregnancy), national origin, ancestry, age, disability, genetic information, marital status, veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by applicable law. Applicants must be authorized to work in the country in which they apply and will be required to provide proof of employment eligibility as a condition of hire. If you need accommodations during the application process, please let us know.
Job Details
Responsibilities
- Build and lead Nebius’ global IR capability
- Lead the technical response to major incidents hands-on
- Conduct end-to-end forensic investigations across cloud, platform, and endpoints
- Define and enforce consistent investigation standards across the team
- Partner with SOC, Threat Intelligence, and Platform Security teams
- Serve as the technical voice of incident response to leadership
- Mentor team and drive lessons-learned into improvements
Requirements
- 8+ years of hands-on incident response and digital forensics
- experience building or leading IR teams in cloud or infrastructure-heavy environments
- deep knowledge of Windows and Linux internals
- strong cloud-native security focus with containers and Kubernetes
- MITRE ATT&CK fluency and tooling experience
- strong scripting and data-analysis skills
- proven leadership and communication abilities
- English proficiency
Skills & Technologies

| Location | Active listings |
|---|---|
| Remote - Global | 423 |
| Remote - Europe | 119 |
| Amsterdam, Netherlands | 56 |
| London, United Kingdom | 22 |
| Remote - United States | 20 |
| Remote - Finland | 18 |
| Berlin, Germany | 15 |
| Mäntsälä, Finland | 12 |
| Helsinki, Finland | 10 |
| Lappeenranta, Finland | 9 |
| Prague, Czech Republic | 6 |
| Amsterdam | 5 |
| Israel | 5 |
| United Kingdom | 4 |
| Canada | 4 |
| Remote | 3 |
| Tel Aviv, Israel | 3 |
| Singapore | 3 |
| Remote - United Kingdom | 2 |
| Abu Dhabi | 2 |
| Dubai | 2 |
| Paris, France | 2 |
| Remote - France | 2 |
| New York City, United States | 2 |
| Austin, United States | 2 |
| France, Paris | 2 |
| Remote - Germany | 2 |
| London | 2 |
| Remote - Netherlands | 2 |
| Philadelphia, United States | 1 |
| Béthune, France | 1 |
| Abu Dhabi, Dubai | 1 |
| Singapore, Singapore | 1 |
| California, United States | 1 |
| Abu Dhabi, United Arab Emirates | 1 |
| Remote - EU | 1 |
| Munich, Germany | 1 |
| Minnesota, United States | 1 |
| Alabama, US | 1 |
| Prague, Czechia | 1 |
| East London, United Kingdom | 1 |
| Canada, Remote - United States | 1 |
| Berlin | 1 |
| Dallas, United States | 1 |
| London, UK | 1 |
| Oklahoma, United States | 1 |
| New Jersey, US | 1 |
| Austin, Texas | 1 |
| Kansas City, United States | 1 |
| San Francisco Bay Area, United States | 1 |
| Czechia | 1 |
| Finland | 1 |
| Remote - Sweden | 1 |
| UK | 1 |
| Prague | 1 |
| New Jersey, United States | 1 |
| Remote - Czech Republic | 1 |
| Netherlands | 1 |
| Paris | 1 |
| Béthune, Pas-de-Calais, France | 1 |
| Role type | Active listings |
|---|---|
| Backend Engineer | 331 |
| Software Engineer | 82 |
| Account Executive | 58 |
| Technical Project Manager | 6 |
| Site Reliability Engineer | 4 |
| Technical Product Manager | 4 |
| System Engineer | 4 |
| Sales Representative | 4 |
| Product Manager | 3 |
| Data Center Operations Technician | 3 |
| Data Center Technician | 3 |
| ML Engineer | 3 |
| Technical Program Manager | 3 |
| Delivery Manager | 2 |
| Applied AI Researcher | 2 |
| Hypervisor Engineer | 2 |
| Product Designer | 2 |
| IT Technician | 2 |
| Backend engineers, Frontend engineers, Site reliability engineers | 2 |
| Open Positions at Nebius | 2 |
| VP of Strategic Sales | 1 |
| Generalist | 1 |
| Offensive Security Lead | 1 |
| Head of Channel Marketing | 1 |
| Principal | 1 |
| Applied AI Solutions Engineer | 1 |
| Field Technical Lead | 1 |
| Compensation Analyst | 1 |
| Solutions Architecture Leader | 1 |
| Application Security Engineer | 1 |
| Human Resources Specialist | 1 |
| Solutions Architect | 1 |
| Mechanical Data Center Technician | 1 |
| Backend Developer | 1 |
| Senior Research Scientist | 1 |
| Cloud Solution Architect | 1 |
| Data Center IT Technician | 1 |
| Manager, ML Solutions Architecture | 1 |
| ML Solutions Architect | 1 |
| Network Planning Project Manager | 1 |
| Data Center Logistics Specialist | 1 |
| Technical Due Diligence Manager | 1 |
| Data Center Operations Manager | 1 |
| Senior Site Reliability Engineer | 1 |
| IT Support Manager | 1 |
| Technical Support Engineer | 1 |
| Data Engineer | 1 |
| Mechanical Engineer | 1 |
| Data Center IT Manager | 1 |
| Security Product Manager | 1 |
| Data Center Electrical Lead | 1 |
| GTM Recruiting Manager | 1 |
| Security Solutions Engineer | 1 |
| Physical Security Systems Technician | 1 |
| Senior HPC Engineer | 1 |
| Educational Content Author | 1 |
| Customer Engineer | 1 |
| Pricing Director | 1 |
| MEP Engineer | 1 |
| Instructional Designer | 1 |
| Partner Solutions Architect | 1 |
| Senior Software Developer | 1 |
| Forward Deployment Engineer | 1 |
| Financial Controller | 1 |
| Internal Control Business Partner | 1 |
| Data Center Facilities Manager | 1 |
| Group Product Manager | 1 |
| Structured Cabling Design Engineer | 1 |
| Site Selection & Colocation Manager | 1 |
| Product Growth Analytics Lead | 1 |
| IT Risk and Control Manager | 1 |
| Vulnerability Operations Center Lead | 1 |
| Electrical Engineer | 1 |
| Senior System Engineer | 1 |
| Machine Learning Engineer | 1 |
| ML Infrastructure Engineer | 1 |
| Data Scientist | 1 |
| Mechanical Design Engineer | 1 |
| Applied ML Engineer | 1 |
| Deal Initiation and Activation Manager | 1 |
| Operations Specialist | 1 |
| AI/ML Specialist Solutions Architect | 1 |
| HPC Engineer | 1 |
| Accountant | 1 |
| VP of Developer Relations & Community | 1 |
| Solutions Partner | 1 |
| Senior Support Engineer | 1 |
| Network Engineer | 1 |
| Project Development Manager | 1 |
| Backend Engineers | 1 |
| Role level | Active listings |
|---|---|
| Mid-Level | 410 |
| Senior | 63 |
| Manager | 12 |
| Executive | 2 |
| Director | 1 |
Related Opportunities
Discover more opportunities that match your interests and skills