Offensive Security Lead

Nebius B.V.

Deutschland

Remote

EUR 150.000 - 190.000

Vollzeit

Vor 4 Tagen
Sei unter den ersten Bewerbenden

Erhalte mehr Antworten von Arbeitgebern

Versende in nur wenigen Minuten einen passgenauen Lebenslauf.

Benefits dieser Stelle

Equity upside
Remote-first culture
Flexible work
Nasdaq-listed company

Zusammenfassung

Nebius is hiring an Offensive Security Lead to build and run its red team capability within the Product Security Team. You will design adversarial simulations across our cloud platform, attack high-value assets, and translate findings into measurable security improvements.

This is a hands-on leadership role developing tooling and processes at scale. You will lead a team of offensive security engineers, drive purple team exercises with blue teams, and deliver senior-level reports with

Qualifikationen

  • 6+ years in offensive security with mentoring/leadership experience.
  • Deep experience attacking cloud-native environments (Kubernetes, IAM, virtualization).
  • Strong attack lifecycle knowledge: initial access to data exfiltration.
  • Proficient in developing custom tooling and post-exploitation capabilities (Python/Go).
  • Experience running purple team exercises and collaborating with blue teams.

Aufgaben

  • Build and lead a red team function within Product Security, hiring engineers.
  • Plan and execute red team engagements against Nebius cloud platform.
  • Automate routine validations and extend threat models in Secure SDLC.
  • Collaborate with Detection & Response to validate coverage and close gaps.
  • Deliver actionable reports with prioritized findings and remediation guidance.
  • Establish scalable red team processes, tooling, and methodologies.

Kenntnisse

Penetration testing
Red teaming
Offensive security leadership
Cloud-native security
Kubernetes security
Python
Go tooling
Threat modeling
Reporting to leadership

Tools

Python
Go

Jobbeschreibung

The Role

We're hiring an Offensive Security Lead to build and run Nebius' red team capability. You'll design and execute adversarial simulation across our cloud platform - attacking the same infrastructure our customers depend on - and translate findings into measurable security improvements. This is a hands-on leadership role within Product Security Team. You will build an internal red team, establish a penetration testing program, and conduct research to uncover sophisticated attack scenarios targeting high-value assets across the Nebius tech stack.

What you’ll do
  • Build and lead a red team function within Product Security Team, hiring and developing offensive security engineers.
  • Validate and extend early-stage Secure SDLC threat models via continuous penetration testing, assessing threat severity and mitigation status while challenging assumptions made during threat modeling and system development. Automate routine validations to keep pace with increasing feature flow, reserving manual analysis for genuinely complex cases.
  • Plan and execute full-scoped red team engagements against Nebius cloud platform - including compute, storage, inference, networking, orchestration layers, and internal tooling. Identify threats, which are able to impact an organization’s operations. Work closely with Detection & Response and other security engineering teams to run purple team exercises, validate detection coverage, and close gaps collaboratively.
  • Research novel attacks against GPU infrastructure (e.g., closed-source firmware and vendor driver binaries, device passthrough exploits, SR-IOV/IOMMU misconfigurations, RDMA/InfiniBand fabric attacks, etc.), the inference stack (e.g., vLLM, TRT-LLM), and AI platform managed services (e.g., managed Slurm). Assess tenant-isolation boundaries and how they can be broken at the low-level stack.
  • Conduct targeted assessments of new products and infrastructure changes before they ship.
  • Deliver clear, actionable reports for both technical audiences and leadership - with prioritized findings and remediation guidance.
  • Establish red team processes, tooling, and a methodology that scales as the platform grows.
What we’re looking for
  • 6+ years in offensive security - penetration testing, red teaming, or adversary simulation - with at least 1-2 years leading or mentoring a team.
  • Deep experience attacking cloud-native environments: Kubernetes privilege escalation, cloud IAM abuse, virtualization and container escapes.
  • Strong fundamentals across the attack lifecycle: initial access, persistence, lateral movement, data exfiltration.
  • Proficiency developing custom tooling and post-exploitation capabilities (Python, Go, or similar).
  • Experience running purple team exercises and working constructively with blue teams.
  • Ability to write clear, senior-level reports with business-contextualized risk (not just raw findings) that engineers can easily use.
Nice to have
  • Experience attacking ML infrastructure, model serving pipelines, or GPU clusters.
  • Reverse engineering and exploits development experience
  • Application security experience
  • Familiarity with eBPF bypass techniques or kernel-level exploitation.
  • Background in vulnerability research or CVE discovery.
  • Experience with cloud provider internals (hypervisor/networking layers).
  • Presenting your security research at conferences like BlackHat/DefCon, etc.
Why this role at Nebius
  • Build a red team from scratch at a company operating frontier AI infrastructure.
  • Attack surface that’s genuinely novel - GPU clusters, AI platforms, multi-tenant cloud at scale.
  • Work alongside world-class engineers on infrastructure that powers frontier AI.
  • Competitive compensation with equity upside in a Nasdaq-listed, high-growth company.
  • Flexible, remote-first culture
Hol dir deinen kostenlosen, vertraulichen Lebenslauf-Check.
oder ziehe deine Datei hierhin.
Similar jobs

Ähnliche Jobs, die dir auch gefallen könnten

Offensive Security Lead
Offensive Security Lead

Nebius • Deutschland

Remote
EUR 120.000 - 170.000
Competitive compensation
Equity options
Flexible, remote-first culture
+1
Vulnerability Operation Center Lead
Vulnerability Operation Center Lead

Embedded Shishya • Deutschland

Remote
EUR 110.000 - 170.000
Competitive compensation
Career growth and learningOpportunit
Flexibility and ownership
+3
Senior/Staff Infrastructure Security Engineer
Senior/Staff Infrastructure Security Engineer

Nebius B.V. • Deutschland

Remote
EUR 90.000 - 120.000
Competitive compensation
Career growth and learning
Flexibility and ownership
+2
Product Manager - Security
Product Manager - Security

Nebius B.V. • Deutschland

Remote
EUR 90.000 - 150.000
Vulnerability Operations Center Lead
Vulnerability Operations Center Lead

Nebius B.V. • Deutschland

Remote
EUR 90.000 - 120.000
Field CTO
Field CTO

Nebius B.V. • Deutschland

Remote
EUR 172.000 - 211.000
Health Insurance
401(k) Plan
Parental Leave
+2
Senior Software Engineer
Senior Software Engineer

Nebius B.V. • Deutschland

Hybrid
EUR 112.000 - 146.000
Health insurance
401(k) plan
Parental leave
+2
Customer Engineer
Customer Engineer

Nebius B.V. • Deutschland

Remote
EUR 155.000 - 193.000
Health Insurance
401(k) Plan
Parental Leave
+2
Senior Security Architect (Human)
Senior Security Architect (Human)

Neura Robotics GmbH • Deutschland

Vor Ort
EUR 90.000 - 130.000
Technical Account Manager
Technical Account Manager

Nebius B.V. • Deutschland

Remote
EUR 90.000 - 130.000
Competitive pay
Career growth
Flexibility
+3