Security Engineer – DevSecOps & SecOps

Nebul

Leiden

Hybrid

EUR 90,000 - 130,000

Full time

24 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Nebul, based in the Netherlands, is building Europe’s sovereign AI cloud. We seek a Medior/Senior Security Engineer to join as our first dedicated security engineer and help mature our security posture with the CISO and engineering teams.

You’ll split your time around 70% DevSecOps and 30% SecOps, embedding security into CI/CD, Kubernetes, and our infrastructure, while strengthening vulnerability management, monitoring, and incident response as Nebul grows.

Qualifications

  • 3 to 6+ years of experience in security engineering, DevSecOps, or a highly technical SecOps role.
  • Hands-on experience integrating and managing security tooling within CI/CD pipelines.
  • Practical experience with Semgrep, Trivy, Gitleaks, Checkov, or comparable tools.
  • Experience working in self-hosted, bare-metal, private-cloud, or similarly infrastructure-heavy environments.
  • Strong Linux administration and operating-system level security knowledge.
  • Solid Kubernetes security knowledge (RBAC, Network Policies, Admission Controllers).
  • Experience securing container lifecycles (registries, image signing, verification).
  • Strong scripting and automation in Python, Bash, or Go.
  • Fluency with APIs, JSON, YAML, and security scanner outputs.
  • Knowledge of ISO 27001, SOC 2, or NIST frameworks.
  • Ability to explain root causes and impacts of vulnerabilities clearly.

Responsibilities

  • Integrate security into CI/CD pipelines and engineering workflows across Nebul.
  • Implement and maintain security scanning using Semgrep, Trivy, Gitleaks, Checkov, and similar tools.
  • Build automated security checks for code, dependencies, secrets, containers, and IaC.
  • Work with Cloud/Platform/AI/Infrastructure teams to identify vulnerabilities and remediate.
  • Secure Kubernetes environments with RBAC, Network Policies, and Admission Controllers.
  • Improve container lifecycle security: scanning, signing and verification.
  • Harden Linux OS using eBPF, SELinux/AppArmor, kernel hardening, and systemd security features.
  • Develop security automation with Python, Bash, and/or Go.
  • Create webhooks and security workflows for custom integrations.
  • Support vulnerability management processes and incident response.

Skills

Security Engineering
DevSecOps
SecOps
CI/CD
Kubernetes security
RBAC
Network Policies
Admission Controllers
eBPF
SELinux/AppArmor
kernel hardening
systemd security features
Python/Bash/Go
APIs/JSON/YAML
ISO 27001/SOC 2/NIST

Tools

Semgrep
Trivy
Gitleaks
Checkov

Job description

At Nebul, we’re building Europe’s sovereign AI cloud — trusted, secure, and purpose-built for the next generation of intelligent infrastructure.

Unlike traditional cloud providers, Nebul operates its own infrastructure end-to-end. From bare-metal servers and GPU infrastructure to networking, Kubernetes, platform services, and AI workloads, we build and operate the complete technology stack ourselves without relying on public cloud hyperscalers.

Security is therefore not something we add afterwards. It is a fundamental part of how we design, build, and operate our platform.

As Nebul continues to scale, we’re looking for a Medior / Senior Security Engineer to join as our first dedicated security engineer and help build our technical security capabilities together with our CISO and engineering teams.

What You’ll Be Doing

As a Medior / Senior Security Engineer, you’ll work directly with our CISO in a highly technical hybrid DevSecOps and SecOps role, with an approximate 70/30 split.

Roughly 70% of your time will focus on DevSecOps: working closely with our Cloud, AI, Platform, and Infrastructure teams to integrate security directly into development processes, CI/CD pipelines, Kubernetes environments, and our underlying infrastructure.

The remaining 30% will focus on SecOps: strengthening vulnerability management, security monitoring, detection capabilities, and incident response as Nebul’s environment continues to grow.

As the first dedicated engineer in this area, you’ll have significant ownership. You won’t simply operate an existing security stack — you’ll help decide what we build, how we build it, and how security becomes embedded into the way engineering teams work.

Key Responsibilities
  • Integrate security directly into CI/CD pipelines and engineering workflows across Nebul.
  • Implement and maintain security scanning using tools such as Semgrep, Trivy, Gitleaks, Checkov, and comparable open-source technologies.
  • Build automated security checks covering source code, dependencies, secrets, containers, and infrastructure-as-code.
  • Work closely with Cloud, Platform, AI, and Infrastructure engineers to identify vulnerabilities, explain root causes, and implement practical remediation.
  • Secure Kubernetes environments through RBAC, Network Policies, Admission Controllers, workload policies, and related controls.
  • Strengthen container lifecycle security, including image scanning, registry hardening, image signing, and verification.
  • Improve Linux security at operating-system level using technologies and controls such as eBPF, SELinux/AppArmor, kernel hardening, and systemd security features.
  • Build security automation and integrations using Python, Bash, and/or Go.
  • Interact with APIs and process JSON/YAML output from security scanners and infrastructure tooling.
  • Build custom webhooks, alerting mechanisms, and security workflows where off-the-shelf integrations are not sufficient.
  • Develop and mature vulnerability management processes and remediation workflows.
  • Improve security logging, monitoring, alerting, and detection capabilities.
  • Support investigation and handling of security incidents when they occur.
  • Help continuously mature Nebul’s Security Operations capabilities as the company and platform scale.
  • Contribute technical security expertise to broader initiatives around ISO 27001, SOC 2, NIST, and other relevant security frameworks.
  • Take ownership of security engineering initiatives and continuously improve our security architecture, tooling, and operational practices.
What Your Day Will Not Look Like

Spending most of your time completing compliance questionnaires or writing security policies.

Managing a collection of SaaS security products while someone else owns the underlying infrastructure.

Running security scanners, forwarding the findings to engineering, and considering the job done.

Working in an environment where security architecture and tooling have already been completely defined for you.

What You Bring

3 to 6+ years of experience in security engineering, DevSecOps, or a highly technical SecOps role.

Hands-on experience integrating and managing security tooling within CI/CD pipelines.

Practical experience with tools such as Semgrep, Trivy, Gitleaks, Checkov, or comparable open-source security technologies.

Experience working in self-hosted, bare-metal, private-cloud, or similarly infrastructure-heavy environments.

A strong understanding of Linux system administration and the ability to secure infrastructure at operating-system level.

Solid knowledge of Kubernetes security principles, including RBAC, Network Policies, and Admission Controllers.

Experience securing container lifecycle management, including registries, image scanning, signing, and verification.

Strong scripting and automation skills using Python, Bash, and/or Go.

Confidence working with APIs, JSON, YAML, security scanner output, webhooks, and custom integrations.

General knowledge of industry-standard frameworks such as ISO 27001, SOC 2, or NIST.

The ability to clearly explain the root cause and impact of a vulnerability to an engineer and collaborate on the appropriate fix.

A self-starting mindset and the ability to operate with autonomy, take ownership, and drive technical security projects forward.

Bonus Points If You Have

Experience securing large-scale Kubernetes or GPU infrastructure environments.

Hands-on experience with eBPF-based security, runtime detection, or workload observability.

Experience implementing software supply-chain security, SBOMs, artifact signing, or policy enforcement.

Experience with detection engineering, SIEM pipelines, or security automation.

Experience helping build a security engineering or Security Operations capability from an early stage.

Knowledge of AI infrastructure, HPC, OpenStack, or sovereign/private-cloud environments.

Eligibility & Application Information

We welcome non-native Dutch speakers to apply. However, to be eligible, you must:

  • Have a valid work permit in the Netherlands.
  • Reside in the Netherlands and be able to travel to the office near The Hague.
  • Be fluent in English (Dutch is not required).

Ready to help build security into the foundation of Europe’s sovereign AI cloud?

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Engineering Team Lead
Engineering Team Lead

Nebul • Leiden

On-site
EUR 90,000 - 120,000
Senior Security Engineer — DevSecOps & SecOps Lead
Senior Security Engineer — DevSecOps & SecOps Lead

Nebul • Leiden

Hybrid
EUR 90,000 - 130,000
Site Reliability Engineer – AI Cloud Platform
Site Reliability Engineer – AI Cloud Platform

Nebul • Leiden

On-site
EUR 70,000 - 110,000
Backend Engineer (GO)
Backend Engineer (GO)

Nebul • Leiden

On-site
EUR 90,000 - 130,000
DevOps Engineer – Go & Cloud Platform
DevOps Engineer – Go & Cloud Platform

Nebul • Leiden

On-site
EUR 75,000 - 110,000
Platform Engineer
Platform Engineer

Nebul • Leiden

On-site
EUR 60,000 - 100,000
Frontend Developer
Frontend Developer

Nebul • Leiden

On-site
EUR 60,000 - 80,000
Technical Project Manager - Security
Technical Project Manager - Security

Nebius • Amsterdam

On-site
EUR 75,000 - 95,000
Competitive compensation
Career growth and learning opportunities
Flexibility and work-life balance
+1
Go Development Team Lead
Go Development Team Lead

Nebul • Leiden

On-site
EUR 70,000 - 90,000
Senior Full-Stack AI Engineer (LLMs & Agentic Systems)
Senior Full-Stack AI Engineer (LLMs & Agentic Systems)

Nebul • Leiden

On-site
EUR 90,000 - 130,000
Office near The Hague