Get more replies from employers
Send a job-specific resume in minutes.
Nebul, based in the Netherlands, is building Europe’s sovereign AI cloud. We seek a Medior/Senior Security Engineer to join as our first dedicated security engineer and help mature our security posture with the CISO and engineering teams.
You’ll split your time around 70% DevSecOps and 30% SecOps, embedding security into CI/CD, Kubernetes, and our infrastructure, while strengthening vulnerability management, monitoring, and incident response as Nebul grows.
At Nebul, we’re building Europe’s sovereign AI cloud — trusted, secure, and purpose-built for the next generation of intelligent infrastructure.
Unlike traditional cloud providers, Nebul operates its own infrastructure end-to-end. From bare-metal servers and GPU infrastructure to networking, Kubernetes, platform services, and AI workloads, we build and operate the complete technology stack ourselves without relying on public cloud hyperscalers.
Security is therefore not something we add afterwards. It is a fundamental part of how we design, build, and operate our platform.
As Nebul continues to scale, we’re looking for a Medior / Senior Security Engineer to join as our first dedicated security engineer and help build our technical security capabilities together with our CISO and engineering teams.
As a Medior / Senior Security Engineer, you’ll work directly with our CISO in a highly technical hybrid DevSecOps and SecOps role, with an approximate 70/30 split.
Roughly 70% of your time will focus on DevSecOps: working closely with our Cloud, AI, Platform, and Infrastructure teams to integrate security directly into development processes, CI/CD pipelines, Kubernetes environments, and our underlying infrastructure.
The remaining 30% will focus on SecOps: strengthening vulnerability management, security monitoring, detection capabilities, and incident response as Nebul’s environment continues to grow.
As the first dedicated engineer in this area, you’ll have significant ownership. You won’t simply operate an existing security stack — you’ll help decide what we build, how we build it, and how security becomes embedded into the way engineering teams work.
Spending most of your time completing compliance questionnaires or writing security policies.
Managing a collection of SaaS security products while someone else owns the underlying infrastructure.
Running security scanners, forwarding the findings to engineering, and considering the job done.
Working in an environment where security architecture and tooling have already been completely defined for you.
3 to 6+ years of experience in security engineering, DevSecOps, or a highly technical SecOps role.
Hands-on experience integrating and managing security tooling within CI/CD pipelines.
Practical experience with tools such as Semgrep, Trivy, Gitleaks, Checkov, or comparable open-source security technologies.
Experience working in self-hosted, bare-metal, private-cloud, or similarly infrastructure-heavy environments.
A strong understanding of Linux system administration and the ability to secure infrastructure at operating-system level.
Solid knowledge of Kubernetes security principles, including RBAC, Network Policies, and Admission Controllers.
Experience securing container lifecycle management, including registries, image scanning, signing, and verification.
Strong scripting and automation skills using Python, Bash, and/or Go.
Confidence working with APIs, JSON, YAML, security scanner output, webhooks, and custom integrations.
General knowledge of industry-standard frameworks such as ISO 27001, SOC 2, or NIST.
The ability to clearly explain the root cause and impact of a vulnerability to an engineer and collaborate on the appropriate fix.
A self-starting mindset and the ability to operate with autonomy, take ownership, and drive technical security projects forward.
Experience securing large-scale Kubernetes or GPU infrastructure environments.
Hands-on experience with eBPF-based security, runtime detection, or workload observability.
Experience implementing software supply-chain security, SBOMs, artifact signing, or policy enforcement.
Experience with detection engineering, SIEM pipelines, or security automation.
Experience helping build a security engineering or Security Operations capability from an early stage.
Knowledge of AI infrastructure, HPC, OpenStack, or sovereign/private-cloud environments.
We welcome non-native Dutch speakers to apply. However, to be eligible, you must:
Ready to help build security into the foundation of Europe’s sovereign AI cloud?