Nebius logo

Nebius

Vulnerability Operation Center Lead

Region Restricted

Remote work allowed only within certain countries or regions.

Europe

Employer listed it 3 weeks ago · Added 4 days ago

Been open since 3 weeks ago, still being checked, but it has been live a while.

Salary

Not stated

Location

Europe

Timezone

CET ±2

Contract

Full-time

Experience

Lead

Category

Software

This employer didn't state pay. Jobs like this usually pay around $200k–$275k a year, a typical range taken from 597 lead-level software roles on Nomaders that do state pay. It's a guide, not an offer.

Remote flexibility

Region Restricted

Remote work is allowed, but only for candidates based in Europe.

What the employer says

  • Source listing states candidate location: "Remote - Europe, Netherlands"
  • Job description states: "authorized to work in the country in which they apply an"

What Nomaders makes of it

  • Timezone overlap with the listed area is often expected

The quotes above are the employer's own words; the reading is ours. Always check the original listing and employment terms before working from another country.

About the role

About Nebius:

Nebius is leading a new era in cloud infrastructure for the global AI economy. We are building a full-stack AI cloud platform that supports developers and enterprises from data and model training through to production deployment, without the cost and complexity of building large in-house AI/ML infrastructure.

Built by engineers, for engineers. From large-scale GPU orchestration to inference optimization, we own the hard problems across compute, storage, networking and applied AI.

Listed on Nasdaq (NBIS) and headquartered in Amsterdam, we have a global footprint with R&D hubs across Europe, the UK, North America and Israel. Our team of 1,500+ includes hundreds of engineers with deep expertise across hardware, software and AI R&D.

Vulnerability Operation Center

The team maintains the full vulnerability management lifecycle - from detection and triage through remediation tracking and reporting - across Nebius's cloud infrastructure, product, and hardware stack. The team's focus is on improving vulnerability triaging capabilities and vulnerability data quality, driving effective remediation, and serving as the first line of response for the most critical zero-day vulnerabilities.

The role

We're building a Vulnerability Operations Center from the ground up and need a senior practitioner to lead it. You'll own the full vulnerability management lifecycle - from detection through triage to remediation tracking and reporting - across Nebius' cloud infrastructure, product and hardware stack. This is a high-impact role with big ownership: you'll define processes, select tooling, work directly with engineering teams, and set the standard for how Nebius responds to vulnerabilities.

What You'll Do

Improve and maintain automated vulnerability triaging capabilities and vulnerability data quality through data enrichment (internal and external intelligence feeds), quality metrics, AI-assisted triage, context-aware risk scoring, and vulnerability correlation/chaining.

Hands-on validation and triaging of most critical/zero-days vulnerabilities

Work closely with vulnerability data consumers and stakeholders across the organization to meet engineering, compliance, and regulatory requirements by delivering high-quality, actionable findings and driving effective remediation.

Contribute to the development of internal platforms, including the Unified Vulnerability Management (UVM) system and the security orchestration platform, to automate core vulnerability management workflows and reduce manual effort.

Identify current deficiencies in patch management, drive and oversee improvements across engineering teams and business units to improve remediation efficiency and reduce organizational risk

Own vulnerability intake from all sources - scanners, bug bounty, threat intel feeds, and penetration tests

Prioritize findings using risk-based frameworks (CVSS, EPSS, SSVC, asset criticality, exploitability context, business impact) and reduce false positive noise

Drive remediation accountability across infrastructure, platform, and product engineering teams

Identify, track and report vulnerability management metrics, present KPIs and trends to security leadership

Coordinate response to critical/zero-day vulnerabilities, acting as the primary point of contact across security, engineering, and operations

Define and maintain integration between VOC tooling and the broader security ecosystem.

What We're Looking For

5–8 years in information security with at least 3 years focused on vulnerability management or security operations

Deep familiarity with vulnerability scanning tools and their strengths/limitations in cloud-native environments

Strong grasp of CVE/NVD, CVSS scoring, EPSS, SSVC and how to apply them to real-world prioritization

Requirements

The employer hasn't listed requirements separately, they're described in the role summary above and on the original listing.

Benefits

  • ·Competitive compensation
  • ·Career growth and learning opportunities
  • ·Flexibility and ownership
  • ·Collaborative and innovative culture
  • ·Opportunity to work on impactful AI projects

How to apply

  1. 1Check the flexibility label above, region restricted, matches where you plan to live and work.
  2. 2Tailor your CV to the role at Nebius, mentioning your remote working experience and working hours (CET ±2).
  3. 3Apply directly on the employer's careers page using the button below. Nomaders never handles your application.

Found 5d ago. Last checked 23 Sept. Always confirm the details on the original posting, salary and location can change after publication.

Listing sourced from Company boards.

Similar roles

Other open software roles with comparable remote rules.

Browse all open roles

Free to apply, no account needed.

Typically $200k to $275k per year · You'll be taken to the employer's careers page.