Offensive Security Lead

3 weeks, 4 days ago
Full-time
Lead
DevOps and Infrastructure
Nebius

Nebius

Nebius enables B2B companies to build local hyperscaling cloud platforms with cost-effective GPUs, InfiniBand network, and 50% less compute cost. They offer managed Kubernetes and a launch-ready business model for innovative cloud solutions.

Internet Software & Services
51-250

Description

  • Build and lead a red team function within the Product Security Team, including hiring and developing offensive security engineers.
  • Validate and extend Secure SDLC threat models through continuous penetration testing and automated checks.
  • Plan and execute full-scoped red team engagements across compute, storage, inference, networking, orchestration layers, and internal tooling.
  • Research novel attacks against GPU infrastructure, the inference stack, and AI platform managed services.
  • Assess tenant-isolation boundaries and identify low-level paths to break them.
  • Conduct targeted assessments of new products and infrastructure changes before release.
  • Work with Detection & Response and other security engineering teams to run purple team exercises and close detection gaps.
  • Deliver clear, actionable reports for technical audiences and leadership with prioritized findings and remediation guidance.
  • Establish red team processes, tooling, and a scalable methodology as the platform grows.

Requirements

  • 6+ years of experience in offensive security, including penetration testing, red teaming, or adversary simulation.
  • At least 1-2 years of experience leading or mentoring a team.
  • Deep experience attacking cloud-native environments, including Kubernetes privilege escalation, cloud IAM abuse, virtualization, and container escapes.
  • Strong fundamentals across the attack lifecycle, including initial access, persistence, lateral movement, and data exfiltration.
  • Proficiency developing custom tooling and post-exploitation capabilities in Python, Go, or similar languages.
  • Experience running purple team exercises and collaborating constructively with blue teams.
  • Ability to write clear senior-level reports with business-contextualized risk that engineers can easily use.
  • Experience attacking ML infrastructure, model serving pipelines, or GPU clusters is preferred.
  • Reverse engineering and exploit development experience is preferred.
  • Application security experience is preferred.
  • Familiarity with eBPF bypass techniques or kernel-level exploitation is preferred.
  • Background in vulnerability research or CVE discovery is preferred.
  • Experience with cloud provider internals, such as hypervisor or networking layers, is preferred.
  • Experience presenting security research at conferences like BlackHat or DefCon is preferred.
  • Applicants must be authorized to work in the country in which they apply and provide proof of employment eligibility as a condition of hire.

Benefits

  • Competitive compensation with equity upside in a Nasdaq-listed, high-growth company.
  • Flexible, remote-first culture.
  • Career growth and learning opportunities.
  • Flexibility and ownership in day-to-day work.
  • Collaborative and innovative culture.
  • Opportunity to work on impactful AI projects.
  • International environment with talented teams.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Cyber Advisor, Post-Cyber Event Hardening

At-Bay 251-1K Insurance

At-Bay is hiring a Cyber Advisor for its Post-Cyber Event Hardening service to help insured customers strengthen their environments after a cyber incident and reduce the risk of future attacks.

Active Directory AWS Azure
1 day, 16 hours ago

IAM Product Owner Consultant

Kalles Group 11-50 Internet Software & Services

Kalles Group is hiring a remote IAM Product Owner Consultant to help drive a client’s CIAM program and coordinate delivery across a complex, cross-functional Agile environment.

Agile
2 days, 16 hours ago

Grupo QuintoAndar | Information Security Manager - GRC

QuintoAndar 1K-5K Real Estate

Grupo QuintoAndar is hiring a Manager of Information Security, GRC to lead cyber governance, risk, and compliance efforts that enable safe, scalable business growth across a cloud-native, multinational environment.

Cybersecurity
4 days, 16 hours ago

Vulnerability Researchers / Security Researchers

SevenPro 51-250 Internet Software & Services

Barcelona-based R&D center is hiring a Vulnerability Researcher / Security Researcher to perform hands-on research, exploitation, and validation of vulnerabilities in complex software systems.

Android Embedded Systems iOS Linux macOS
5 days, 16 hours ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers