Head of Proactive Security
Nebius
Make my CV for this job, freeView job and applyYour CV, rewritten for this role using only your real experience. Sign in with Google and upload your CV. Nothing to install.
Skills named in this job
Read from the description itself, not inferred.
This role on the market
22 open proactive roles across 11 companies are on ApplySarthi right now, most of them in Hyderabad (3), Delhi NCR (1).
- Application Security Engineer, AWS Proactive SecurityAmazon.com Services LLC
- Patient Strategy Proactive Adherence Monitoring Busines Analyst - Pharma Medicines GPSRoche · hyderabad
- Product Development Engineer Proactive QualityCat
- Slack Proactive Monitoring EngineerSalesforce
- Program Manager – Proactive Customer EngagementBroadcom
What proactive roles keep asking for: Python (41%), AWS (32%), C++ (32%), Java (32%), Penetration testing (27%), Microservices (14%), Ruby (14%), Scala (14%) — counted across their open postings here.
Penetration testing jobs · SaaS jobs
Nebius has 382 open roles listed here.
- Senior Research Scientist (Architectures Research)
- Senior Hypervisor Engineer
- Senior HPC Cluster Engineer
- Senior Manager, SEO & GEO
- Sr. Technical Program Manager
Counted across 14 company job boards, updated as roles open and close.
Preparing for this interview
Interviews for proactive roles keep coming back to Python, AWS, C++, Java. Practise those questions before you sit with Nebius.
Questions you are likely to be asked
- Why do you want to join Nebius?
- What is your experience with Penetration testing? Tell me one thing you learned the hard way.
- How do you decide what to monitor, and what should wake someone up at night?
- How would you cut the cloud bill of a system without hurting it?
- How do you keep secrets and access safe in your infrastructure?
Prep Sarthi gives you a free mock interview: an AI interviewer asks you questions like these out loud, from your own CV and this job, and shows your score and your weakest answer.
Practise the Head of Proactive Security at Nebius interview free →About Nebius:
Nebius is leading a new era in cloud infrastructure for the global AI economy. We are building a full-stack AI cloud platform that supports developers and enterprises from data and model training through to production deployment, without the cost and complexity of building large in-house AI/ML infrastructure.
Built by engineers, for engineers. From large-scale GPU orchestration to inference optimization, we own the hard problems across compute, storage, networking and applied AI.
Listed on Nasdaq (NBIS) and headquartered in Amsterdam, we have a global footprint with R&D hubs across Europe, the UK, North America and Israel. Our team of 1,500+ includes hundreds of engineers with deep expertise across hardware, software and AI R&D.
The role
Nebius is looking for a Head of Proactive Security to establish and lead the Proactive Security pillar. Reporting directly to the CISO, this leader will manage the Red Team, Penetration Testing, Threat Hunting, and Threat Intelligence teams.
The role is responsible for anticipating relevant threats, challenging Nebius's defenses, identifying exploitable weaknesses, hunting for adversary activity that may evade existing controls, and converting findings into measurable security improvements.
This is a hands-on leadership position for someone who combines offensive-security depth, threat-led thinking, strong operational judgment, and the ability to influence product, engineering, infrastructure, and security stakeholders.
Your responsibilities will include:
-
Pillar strategy and leadership
- Define the Proactive Security strategy, operating model, roadmap, priorities, budget, and success measures in alignment with Nebius's business objectives and threat profile.
- Build, lead, and develop high-performing Red Team, Penetration Testing, Threat Hunting, and Threat Intelligence teams.
- Create a unified intelligence-led program in which threat intelligence informs testing and hunting, and findings continuously improve defensive controls.
- Prioritize work based on crown jewels, material attack paths, emerging threats, major technology changes, incidents, and business risk.
- Establish clear team charters, engagement models, escalation paths, quality standards, and career-development frameworks.
- Provide the CISO and senior leadership with clear visibility into adversary exposure, validated weaknesses, emerging threats, and remediation progress.
Red Team and adversary emulation
- Lead realistic, intelligence-led adversary simulations across cloud, identity, applications, infrastructure, endpoints, networks, and operational processes.
- Design campaigns that evaluate prevention, detection, response, escalation, and recovery capabilities against relevant threat scenarios.
- Develop and maintain adversary-emulation plans mapped to relevant threat actors, tactics, techniques, and procedures.
- Ensure every engagement operates under documented authorization, rules of engagement, safety controls, deconfliction procedures, and evidence-handling requirements.
- Deliver concise technical and executive reporting that explains demonstrated impact, attack paths, root causes, and prioritized improvements.
Penetration testing and continuous security validation
- Own the risk-based penetration-testing program for Nebius products, applications, APIs, cloud environments, infrastructure, and critical internal systems.
- Define testing standards, scoping criteria, methodologies, quality assurance, retesting, and reporting requirements.
- Coordinate internal testing and specialized external providers while maintaining consistent quality and risk prioritization.
- Partner with Product, Engineering, Infrastructure, and Security teams to integrate testing into major launches, architectural changes, and high-risk initiatives.
- Track findings through validation, remediation, exception, and closure, and identify systemic or recurring weakness patterns.
- Expand automation and continuous validation where it improves coverage without replacing expert-led testing and judgment.
Threat hunting
- Establish a hypothesis-driven threat-hunting program across endpoint, identity, cloud, network, workload, application, and SaaS telemetry.
- Prioritize hunts using threat intelligence, incidents, environmental changes, control gaps, and emerging adversary techniques.
- Search for active, historical, or previously undetected malicious behavior that may not trigger existing alerts.
- Turn validated hunt findings into new detections, telemetry requirements, response playbooks, hardening actions, and future hunt hypotheses.
- Define repeatable hunt methodology, documentation standards, evidence handling, and measurement of hunt effectiveness.
- Partner closely with Detection and Response, Incident Response, Security Engineering, and infrastructure teams during investigations and remediation.
Threat intelligence
- Own Nebius's threat-intelligence strategy, collection priorities, analysis standards, dissemination model, and intelligence lifecycle.
- Maintain a current view of threat actors, campaigns, vulnerabilities, geopolitical developments, and techniques relevant to Nebius, its customers, and its technology stack.
- Produce strategic intelligence for leadership, operational intelligence for defenders, and tactical intelligence that supports detections, investigations, hunting, and testing.
- Translate intelligence into clear changes to security priorities, control coverage, red-team scenarios, hunt hypotheses, and incident readiness.
- Establish reliable processes for source evaluation, confidence assessment, intelligence sharing, and secure handling of sensitive information.
- Build trusted relationships with industry peers, relevant communities, vendors, and information-sharing organizations.
Defensive improvement and governance
- Create a closed-loop process that converts proactive-security findings into owned, prioritized, and measurable remediation actions.
- Partner with Security Engineering, Detection and Response, Product Security, Cloud Security, IT, and Engineering to improve controls and reduce repeat findings.
- Ensure material findings are communicated promptly, tracked transparently, and escalated according to risk.
- Define reporting that distinguishes activity from outcomes and demonstrates improvements in resilience, coverage, and adversary readiness.
- Support major incidents with threat context, attack-path analysis, hunting, and specialist offensive expertise when required.
- Maintain strong legal, ethical, privacy, and operational-safety standards across all proactive-security activities.
We expect you to have:
- Extensive cybersecurity experience, including leadership responsibility in offensive security, penetration testing, threat hunting, threat intelligence, detection engineering, or incident response.
- Proven experience building or scaling multidisciplinary security teams and programs, including budgets, vendors, and external testing providers.
- Strong technical understanding of modern cloud environments, identity systems, applications, APIs, networks, endpoints, containers, and production infrastructure.
- Demonstrated experience planning and delivering red-team operations, penetration tests, or adversary-emulation exercises.
- Practical knowledge of threat-hunting methodology, telemetry, detection logic, and investigation workflows.
- Experience producing and operationalizing strategic, operational, and tactical threat intelligence.
- Strong understanding of adversary behavior and frameworks such as MITRE ATT&CK.
- Excellent communication and executive-presentation skills, with the ability to translate complex technical findings into clear business risks, decisions, and remediation actions.
- Sound judgment regarding authorization, operational safety, confidentiality, evidence handling, and responsible disclosure.
It will be an added bonus if you have:
- Experience in cloud, hyperscale, AI, or other highly distributed technology environments.
- Deep domain expertise, relevant certifications or equivalent practical experience, and a track record of responsible research or industry collaboration.
Benefits & Perks:
- Competitive compensation
- Career growth and learning opportunities
- Flexibility and ownership
- Collaborative and innovative culture
- Opportunity to work on impactful AI projects
- International environment and talented teams
What's it like to work at Nebius:
Fast moving - Bold thinking - Constant growth - Meaningful impact - Trust and real ownership - Opportunity to shape the future of AI
Equal Opportunity Statement:
Nebius is an equal opportunity employer. We are committed to fostering an inclusive and diverse workplace and to providing equal employment opportunities in all aspects of employment. We do not discriminate on the basis of race, color, religion, sex (including pregnancy), national origin, ancestry, age, disability, genetic information, marital status, veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by applicable law.
Applicants must be authorized to work in the country in which they apply and will be required to provide proof of employment eligibility as a condition of hire.
If you need accommodations during the application process, please let us know.
Match this job to your CV
ApplySarthi scores your CV against this role, shows the skills you are missing, and writes a tailored version for the application.
Check my match →Similar open roles
- Cloud Solution Architect - Educational Content Author, Nebius AcademyNebius
- Data Center Design LeadNebius
- Data Center - Electrical Design EngineerNebius
- Senior Data EngineerNebius
- Detection Engineering & Response EngineerNebius
- Director, PricingNebius
- Director, Solutions Architecture EMEANebius
- Educational Content Author - Cloud Solution Architect, Nebius AcademyNebius
Need answers during your interview? Try Live Sarthi.
Live Sarthi, an Interview Sarthi app, shows answer suggestions during the call.
- Hidden from supported screen sharingThe overlay stays out of supported Windows screen captures.
- Answers start in about 1.5 secondsResponse time varies with your connection and model.
- From your own CVYour projects and your experience, not a generic script.
- 30 minutes freeThen ₹99 for a 2-day pass with unlimited calls — you pay for the days you are interviewing, not a subscription.
A Windows app, from the same team as ApplySarthi.
Listed on greenhouse · posted 2026-08-28. ApplySarthi collects openings and links to application pages; the role is advertised by Nebius, not by us.