Offensive Security Lead

2 months ago
Full-time
Lead
DevOps and Infrastructure
Nebius

Nebius

Nebius enables B2B companies to build local hyperscaling cloud platforms with cost-effective GPUs, InfiniBand network, and 50% less compute cost. They offer managed Kubernetes and a launch-ready business model for innovative cloud solutions.

Internet Software & Services
51-250

Description

  • Build and lead a red team function within the Product Security Team, including hiring and developing offensive security engineers.
  • Validate and extend Secure SDLC threat models through continuous penetration testing and automated checks.
  • Plan and execute full-scoped red team engagements across compute, storage, inference, networking, orchestration layers, and internal tooling.
  • Research novel attacks against GPU infrastructure, the inference stack, and AI platform managed services.
  • Assess tenant-isolation boundaries and identify low-level paths to break them.
  • Conduct targeted assessments of new products and infrastructure changes before release.
  • Work with Detection & Response and other security engineering teams to run purple team exercises and close detection gaps.
  • Deliver clear, actionable reports for technical audiences and leadership with prioritized findings and remediation guidance.
  • Establish red team processes, tooling, and a scalable methodology as the platform grows.

Requirements

  • 6+ years of experience in offensive security, including penetration testing, red teaming, or adversary simulation.
  • At least 1-2 years of experience leading or mentoring a team.
  • Deep experience attacking cloud-native environments, including Kubernetes privilege escalation, cloud IAM abuse, virtualization, and container escapes.
  • Strong fundamentals across the attack lifecycle, including initial access, persistence, lateral movement, and data exfiltration.
  • Proficiency developing custom tooling and post-exploitation capabilities in Python, Go, or similar languages.
  • Experience running purple team exercises and collaborating constructively with blue teams.
  • Ability to write clear senior-level reports with business-contextualized risk that engineers can easily use.
  • Experience attacking ML infrastructure, model serving pipelines, or GPU clusters is preferred.
  • Reverse engineering and exploit development experience is preferred.
  • Application security experience is preferred.
  • Familiarity with eBPF bypass techniques or kernel-level exploitation is preferred.
  • Background in vulnerability research or CVE discovery is preferred.
  • Experience with cloud provider internals, such as hypervisor or networking layers, is preferred.
  • Experience presenting security research at conferences like BlackHat or DefCon is preferred.
  • Applicants must be authorized to work in the country in which they apply and provide proof of employment eligibility as a condition of hire.

Benefits

  • Competitive compensation with equity upside in a Nasdaq-listed, high-growth company.
  • Flexible, remote-first culture.
  • Career growth and learning opportunities.
  • Flexibility and ownership in day-to-day work.
  • Collaborative and innovative culture.
  • Opportunity to work on impactful AI projects.
  • International environment with talented teams.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

IT Systems Audit SME (SAP WMS)

C5MI 11-50 Internet Software & Services

C5MI is seeking an IT Systems Audit SME to lead audit readiness, internal-control evaluation, risk management, and compliance activities for mission-critical DoD/DLA warehouse management and SAP environments.

Cybersecurity
4 days ago

Principal Technical Consultant - Network & Security Solution Architect

AHEAD 1K-5K IT Services

AHEAD is seeking a Solution Architect – Network & Network Security to lead the design and delivery of enterprise-scale network and security solutions for a complex Fortune 10 client environment.

Azure Cisco Network Security
5 days ago

Technical Consultant

AHEAD 1K-5K IT Services

AHEAD is seeking a Technical Consultant to help enterprise clients improve cloud security and compliance through consulting delivery, business development, and security practice development.

AWS Azure Bash CI/CD Docker Kubernetes PowerShell Python SIEM Splunk Terraform
1 week ago

Senior Professional Services Technical Architect - Security

GitLab 1K-5K Internet Software & Services

GitLab is hiring a Senior Professional Services Technical Architect, Security to design and lead secure enterprise DevSecOps solutions for Professional Services clients across AMER, from pre-sales scoping through implementation and enablement.

Ansible CI/CD DevSecOps GitLab Jenkins SonarQube Terraform
1 week, 1 day ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers