Lead Security Automation Engineer
- AI
- AI/ML
- SIEM
- EDR
- Incident Response
- REST API
- Webhooks
- Python
- triage
- Cortex
- Splunk
- Azure
- AWS
- GCP
- CrowdStrike
- CI/CD
- Devops
About Nebius:
Nebius is leading a new era in cloud infrastructure for the global AI economy. We are building a full-stack AI cloud platform that supports developers and enterprises from data and model training through to production deployment, without the cost and complexity of building large in-house AI/ML infrastructure.
Built by engineers, for engineers. From large-scale GPU orchestration to inference optimization, we own the hard problems across compute, storage, networking and applied AI.
Listed on Nasdaq (NBIS) and headquartered in Amsterdam, we have a global footprint with R&D hubs across Europe, the UK, North America and Israel. Our team of 1,500+ includes hundreds of engineers with deep expertise across hardware, software and AI R&D.
The role
We are looking for a skilled Lead Security Automation Engineer to join our SOC Automation team and play a key role in building and scaling automation across Security Operations. This is a hands-on role — you will design, develop, and integrate automation solutions across SIEM, EDR, and other security platforms, contributing to our SOAR capabilities from the ground up.Â
You will work in a technologically rich environment, integrating with a wide range of security and infrastructure systems across the network — a unique opportunity to build automation at scale in a greenfield setting, with real influence over the architecture and tooling decisions.Â
We are especially interested in candidates who are curious about leveraging AI and intelligent agents to help evolve next-generation automation and response workflows — and who want to be a driving voice in how we apply those technologies.Â
Your responsibilities will include:Â
Automation developmentÂ
- Design and develop automation workflows for incident response and SOC operationsÂ
- Identify and eliminate manual processes through scalable automationÂ
- Build reusable components and maintainable automation patternsÂ
Engineering & integrationÂ
- Develop integrations using REST APIs, webhooks, and event-driven architecturesÂ
- Write high-quality, maintainable Python for automation and orchestrationÂ
- Implement data parsing, enrichment, and transformation across multiple systemsÂ
SOAR & platform buildoutÂ
- Lead or actively contribute to the evaluation, selection, and implementation of SOAR/automation platformsÂ
- Design the automation architecture and integration strategy for the teamÂ
- Build automation capabilities in a greenfield environment — your decisions will shape the foundationÂ
SOC collaborationÂ
- Work closely with SOC analysts and incident responders to translate operational needs into automation solutionsÂ
- Improve end-to-end detection and response workflows through close partnership with the teamÂ
AI & innovationÂ
- Actively build and evaluate AI/LLM and agent-based workflows applied to security automationÂ
- Prototype AI-assisted enrichment, triage, and response solutions and drive them toward productionÂ
We expect you to have:Â
- Minimum 3 years of hands-on experience with SOAR platforms (e.g., Torq, Cortex XSOAR, Splunk SOAR, or similar)Â
- Strong hands-on experience with Python (or a comparable language)Â
- Experience designing or implementing automation frameworks or workflowsÂ
- Experience building integrations using REST APIs and web servicesÂ
- Experience working with security tools such as SIEM, EDR/XDR, or ticketing systemsÂ
- Experience with at least one cloud platform (Azure, AWS, or GCP)Â
- Solid understanding of incident response processes and SOC alert-handling workflowsÂ
- Experience with at least one SIEM platform (Splunk,Sentinel,Qradar,Crowdstrike)Â
Â
It will be an added bonus if you have:Â
- Experience with CI/CD pipelines and DevOps practicesÂ
- Familiarity with cloud-native services and architectureÂ
- Hands-on exposure to AI/ML, LLMs, or agent-based systems
- Has a strong hands-on engineering mindset — you build, not just adviseÂ
- Is proactive, solution-oriented, and detail-focusedÂ
- Is genuinely curious about AI and intelligent agents, not just aware of themÂ
- Collaborates well with both technical and operational teammatesÂ
Benefits & Perks:
- Competitive compensation
- Career growth and learning opportunities
- Flexibility and ownership
- Collaborative and innovative culture
- Opportunity to work on impactful AI projects
- International environment and talented teams
What's it like to work at Nebius:
Fast moving - Bold thinking - Constant growth - Meaningful impact - Trust and real ownership - Opportunity to shape the future of AIÂ
Equal Opportunity Statement:
Nebius is an equal opportunity employer. We are committed to fostering an inclusive and diverse workplace and to providing equal employment opportunities in all aspects of employment. We do not discriminate on the basis of race, color, religion, sex (including pregnancy), national origin, ancestry, age, disability, genetic information, marital status, veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by applicable law.
Applicants must be authorized to work in the country in which they apply and will be required to provide proof of employment eligibility as a condition of hire.Â
If you need accommodations during the application process, please let us know.
Lead Security Automation Engineer · Nebius