Vulnerability Operation Center Lead
Remote · Full-time
- Posted 1mo ago
- From Nebius’s careers page
- Work mode
- Remote
- Type
- Full-time
- Level
- Senior
- Experience
- 5+ years
- Department
- Information Technology
Opens the listing on careers.nebius.com
Let the right jobs find you
In your inbox every Wednesday and SaturdayPersonalised suggestions from verified career pages, matched to your role, location, level and skills.
About the role
The role
We're building a Vulnerability Operations Center from the ground up and need a senior practitioner to lead it. You'll own the full vulnerability management lifecycle - from detection through triage to remediation tracking and reporting - across Nebius' cloud infrastructure, product and hardware stack. This is a high-impact role with big ownership: you'll define processes, select tooling, work directly with engineering teams, and set the standard for how Nebius responds to vulnerabilities.
What You'll Do
- Improve and maintain automated vulnerability triaging capabilities and vulnerability data quality through data enrichment (internal and external intelligence feeds), quality metrics, AI-assisted triage, context-aware risk scoring, and vulnerability correlation/chaining.
- Hands-on validation and triaging of most critical/zero-days vulnerabilities
- Work closely with vulnerability data consumers and stakeholders across the organization to meet engineering, compliance, and regulatory requirements by delivering high-quality, actionable findings and driving effective remediation.
- Contribute to the development of internal platforms, including the Unified Vulnerability Management (UVM) system and the security orchestration platform, to automate core vulnerability management workflows and reduce manual effort.
- Identify current deficiencies in patch management, drive and oversee improvements across engineering teams and business units to improve remediation efficiency and reduce organizational risk
- Own vulnerability intake from all sources - scanners, bug bounty, threat intel feeds, and penetration tests
- Prioritize findings using risk-based frameworks (CVSS, EPSS, SSVC, asset criticality, exploitability context, business impact) and reduce false positive noise
- Drive remediation accountability across infrastructure, platform, and product engineering teams
- Identify, track and report vulnerability management metrics, present KPIs and trends to security leadership
- Coordinate response to critical/zero-day vulnerabilities, acting as the primary point of contact across security, engineering, and operations
- Define and maintain integration between VOC tooling and the broader security ecosystem.
What We're Looking For
- 5–8 years in information security with at least 3 years focused on vulnerability management or security operations
- Deep familiarity with vulnerability scanning tools and their strengths/limitations in cloud-native environments
- Strong grasp of CVE/NVD, CVSS scoring, EPSS, SSVC and how to apply them to real-world prioritization
- Experience managing vulnerabilities across IaaS/cloud infrastructure (AWS, GCP, Azure, or private cloud) - experience with GPU/HPC environments is a plus
- Deep understanding of vulnerability sources limitations and corner cases for different vulnerability classes
- Able to write and review code (ability or willingness to develop in Golang) - well enough to assess exploitability, validate fixes, and build lightweight automation (e.g., variant-detection scripts, triage tooling, data pipelines for trend analysis)
- Strong grasp of common vulnerability classes at the code and infrastructure level.
- Comfortable feeding well-documented vulnerability patterns into AI-assisted code review workflows and critically evaluating the output
- Track record of working cross-functionally with engineering teams and holding stakeholders accountable to timelines without being a bottleneck
- Strong written and verbal communication - able to translate technical risk into business impact for non-security audiences
Nice to Have
- Experience building vulnerability management program from scratch
- Familiarity with container and Kubernetes security
- Experience with supply chain security (SBOMs, dependency scanning)
- Bug bounty triage experience
- Public talks or research articles
Why this role at Nebius
- Build a Platform Security Vulnerability program from scratch and get to build and lead your own team while doing it
- The potential to evolve an in-house AI-powered vulnerability management platform into a cloud security offering for Nebius customers
- Work alongside world-class engineers on infrastructure that powers frontier AI.
- Competitive compensation with equity upside in a Nasdaq-listed, high-growth company.
- Flexible, remote-first culture
#LI-CP1
Benefits & Perks:
- Competitive compensation
- Career growth and learning opportunities
- Flexibility and ownership
- Collaborative and innovative culture
- Opportunity to work on impactful AI projects
- International environment and talented teams
What's it like to work at Nebius:
Fast moving – Bold thinking – Constant growth – Meaningful impact – Trust and real ownership – Opportunity to shape the future of AI
Skills they ask for
Pick one to see other roles that ask for it.
About Nebius
Cloud infrastructure for AINebius provides cloud infrastructure and services for building and scaling AI workloads.
See all 133 roles at NebiusMore roles at Nebius
See all 133- Principal ML Solutions Architect - Token FactoryUnited States · Principal · RemoteEngineering · Principal · RemoteUnited States12h
- Delivery Operations Manager - Token FactoryRemoteBusiness Operations · Remote12h
- Head of Strategic Partnerships, TavilyUnited States · Director · RemoteSales · Director · RemoteUnited States17h
- General Manager, Data Center (New Build)Independence · Director · On-siteInformation Technology · Director · On-siteIndependence, United States1d
Let the right jobs find you
In your inbox every Wednesday and SaturdayPersonalised suggestions from verified career pages, matched to your role, location, level and skills.