Vulnerability Operations Center Lead

Nebius B.V.

Deutschland

Remote

EUR 90.000 - 120.000

Vollzeit

Vor 5 Tagen
Sei unter den ersten Bewerbenden

Erhalte mehr Antworten von Arbeitgebern

Versende in nur wenigen Minuten einen passgenauen Lebenslauf.

Zusammenfassung

Nebius B.V. is seeking a Vulnerability Operations Center Lead to build and lead our VOC from scratch, owning the full vulnerability management lifecycle across cloud, product, and hardware stacks.

You will define processes, select tooling, work directly with engineering, and set the standard for vulnerability response across Nebius. This role requires strong collaboration and hands-on leadership in a fast-moving security program.

Qualifikationen

  • 5–8 years in information security with at least 3 years focused on vulnerability management or security operations.
  • Deep familiarity with vulnerability scanning tools and their strengths/limitations in cloud-native environments.
  • Strong grasp of CVE/NVD, CVSS scoring, EPSS, SSVC and how to apply them to real-world prioritization.
  • Experience managing vulnerabilities across IaaS/cloud infrastructure (AWS, GCP, Azure, or private cloud). GPU/HPC experience is a plus.
  • Able to write and review code (Golang) for automation.
  • Strong grasp of common vulnerability classes at code/infrastructure level.
  • Experience with AI-assisted code review workflows is a plus.
  • Track record of cross-functional collaboration with engineering teams

Aufgaben

  • Lead the Vulnerability Operations Center from the ground up and own the full vulnerability management lifecycle.
  • Improve and maintain automated vulnerability triaging and data quality.
  • Validate and triage critical/zero-day vulnerabilities.
  • Deliver high-quality findings and drive remediation with engineering teams.
  • Develop internal platforms to automate core vulnerability workflows.
  • Oversee patch management improvements to reduce remediation time and risk.
  • Own vulnerability intake from scanners, bug bounty, threat intel, and tests.
  • Prioritize findings using risk-based frameworks and reduce false positives.
  • Coordinate response to critical vulnerabilities as primary security contact.
  • Define integration between VOC tooling and the broader security ecosystem.

Kenntnisse

Vulnerability management
Security operations
Risk prioritization
Cross-functional collaboration
Automation scripting (Golang)
AI-assisted triage
Cloud security (IaaS)

Tools

Vulnerability scanning tools

Jobbeschreibung

Role

The Vulnerability Operations Center Lead will build and lead the Vulnerability Operations Center from the ground up. You will own the full vulnerability management lifecycle from detection through triage to remediation tracking and reporting across Nebius' cloud infrastructure, product and hardware stack. This is a high-impact role with big ownership: define processes, select tooling, work directly with engineering teams, and set the standard for how Nebius responds to vulnerabilities.

What You’ll Do
  • Improve and maintain automated vulnerability triaging capabilities and vulnerability data quality through data enrichment, quality metrics, AI-assisted triage, context‑aware risk scoring, and vulnerability correlation/chaining.
  • Hands‑on validation and triaging of most critical/zero-days vulnerabilities.
  • Work closely with vulnerability data consumers and stakeholders across the organization to meet engineering, compliance, and regulatory requirements by delivering high‑quality, actionable findings and driving effective remediation.
  • Contribute to the development of internal platforms, including the Unified Vulnerability Management (UVM) system and the security orchestration platform, to automate core vulnerability management workflows and reduce manual effort.
  • Identify current deficiencies in patch management, drive and oversee improvements across engineering teams and business units to improve remediation efficiency and reduce organizational risk.
  • Own vulnerability intake from all sources - scanners, bug bounty, threat intel feeds, and penetration tests.
  • Prioritize findings using risk‑based frameworks (CVSS, EPSS, SSVC, asset criticality, exploitability context, business impact) and reduce false positive noise.
  • Drive remediation accountability across infrastructure, platform, and product engineering teams.
  • Identify, track and report vulnerability management metrics, present KPIs and trends to security leadership.
  • Coordinate response to critical/zero‑day vulnerabilities, acting as the primary point of contact across security, engineering, and operations.
  • Define and maintain integration between VOC tooling and the broader security ecosystem.
Requirements
  • 5–8 years in information security with at least 3 years focused on vulnerability management or security operations,
  • Deep familiarity with vulnerability scanning tools and their strengths/limitations in cloud-native environments,
  • Strong grasp of CVE/NVD, CVSS scoring, EPSS, SSVC and how to apply them to real-world prioritization,
  • Experience managing vulnerabilities across IaaS/cloud infrastructure (AWS, GCP, Azure, or private cloud) - GPU/HPC is a plus,
  • Able to write and review code (Golang) for automation,
  • Strong grasp of common vulnerability classes at code/infrastructure level,
  • Experience with AI-assisted code review workflows is a plus,
  • Track record of cross-functional collaboration with engineering teams
Hol dir deinen kostenlosen, vertraulichen Lebenslauf-Check.
oder ziehe deine Datei hierhin.
Similar jobs

Ähnliche Jobs, die dir auch gefallen könnten

Vulnerability Operation Center Lead
Vulnerability Operation Center Lead

Embedded Shishya • Deutschland

Remote
EUR 110.000 - 170.000
Competitive compensation
Career growth and learningOpportunit
Flexibility and ownership
+3
Offensive Security Lead
Offensive Security Lead

Nebius B.V. • Deutschland

Remote
EUR 150.000 - 190.000
Equity upside
Remote-first culture
Flexible work
+1
Senior/Staff Infrastructure Security Engineer
Senior/Staff Infrastructure Security Engineer

Nebius B.V. • Deutschland

Remote
EUR 90.000 - 120.000
Competitive compensation
Career growth and learning
Flexibility and ownership
+2
Offensive Security Lead
Offensive Security Lead

Nebius • Deutschland

Remote
EUR 120.000 - 170.000
Competitive compensation
Equity options
Flexible, remote-first culture
+1
Product Manager - Security
Product Manager - Security

Nebius B.V. • Deutschland

Remote
EUR 90.000 - 150.000
Application Security & VIPR Expert
Application Security & VIPR Expert

Armis • Deutschland

Vor Ort
EUR 120.000 - 160.000
Senior Security Architect (Human)
Senior Security Architect (Human)

Neura Robotics GmbH • Deutschland

Vor Ort
EUR 90.000 - 130.000
Senior Software Engineer
Senior Software Engineer

Nebius B.V. • Deutschland

Hybrid
EUR 112.000 - 146.000
Health insurance
401(k) plan
Parental leave
+2
Software Engineer in Hardware Infrastructure Observability
Software Engineer in Hardware Infrastructure Observability

Nebius B.V. • Deutschland

Remote
EUR 90.000 - 130.000
Competitive compensation
Career growth opportunities
Flexibility and ownership
+3
Frontend Engineer - User Interface
Frontend Engineer - User Interface

Nebius B.V. • Deutschland

Remote
EUR 70.000 - 110.000