Incident Response Lead
Core
Build and lead a global incident response capability for a full-stack AI cloud platform, handling high-severity incidents and forensic investigations across cloud, infrastructure, and endpoint environments.
Role type
Senior Incident Response Lead (Digital Forensics & Incident Response)
Builds
Global IR tooling, playbooks, and a follow-the-sun responder team for Nebius' cloud and infrastructure environments.
Domain
Cloud Security / Digital Forensics / Incident Response
Deliverable
client delivery
Required skills
Incident response leadership, digital forensics (disk/memory), cloud-native security (Kubernetes, CI/CD, IAM), attacker TTPs knowledge (MITRE ATT&CK), forensic tooling (Velociraptor, Volatility, X-Ways/EnCase), scripting (Python, PowerShell, SQL/KQL), high-pressure decision making.
Preferred skills
Experience in highly regulated environments (SOC 2, ISO 27001, GDPR/NIS2), mentoring technical teams.
Technologies
Kubernetes, CI/CD, Velociraptor, Volatility, X-Ways, EnCase, Python, PowerShell, SQL, KQL
Responsibilities
Lead technical response to major incidents (escalation, containment, eradication, recovery); conduct end-to-end forensic investigations (log analysis, host/network forensics, memory analysis, malware triage); define investigation standards and evidence handling; partner with SOC and Threat Intelligence teams to improve detection; brief executives and legal on risk and root causes; mentor team and drive lessons-learned.
Seniority
Senior, hands-on IC with leadership responsibilities