xelys jobs xelys jobs

Vulnerability Operation Center Lead

Nebius

leadpermanentsecurityengineering-management Europe 37 days ago via Jobicy

See how well this job matches your profile

Sign up to get an AI match score and generate a tailored application in seconds.

Get your match score

Tags

Vulnerability ManagementVulnerability ScanningCVE/NVDCVSSEPSSSSVCRisk-Based PrioritizationSecurity OperationsRemediation TrackingCloud Security

About the role

Role: Vulnerability Operations Center (VOC) Lead

Nebius is building a Vulnerability Operations Center from the ground up and is seeking a senior practitioner to lead end-to-end vulnerability operations across its cloud infrastructure, product, and hardware stack.

What you’ll do

  • Own the full vulnerability management lifecycle: detection → triage → remediation tracking → reporting.
  • Improve automated vulnerability triage and data quality using:
    • internal/external intelligence feeds and data enrichment
    • quality metrics
    • AI-assisted triage
    • context-aware risk scoring
    • vulnerability correlation/chaining
  • Hands-on triage of the most critical zero-days.
  • Partner with internal stakeholders (engineering, compliance, regulatory) to deliver high-quality, actionable findings and drive effective remediation.
  • Build and improve internal platforms, including:
    • Unified Vulnerability Management (UVM)
    • security orchestration platform to automate workflows and reduce manual effort.
  • Assess and fix patch/remediation deficiencies across engineering teams and business units to improve remediation efficiency and reduce organizational risk.
  • Own vulnerability intake from multiple sources: scanners, bug bounty, threat intel feeds, and penetration tests.
  • Prioritize using risk-based frameworks such as CVSS, EPSS, SSVC, asset criticality, exploitability context, and business impact.
  • Drive remediation accountability across infrastructure, platform, and product engineering teams.
  • Track and report metrics/KPIs and trends to security leadership.
  • Coordinate response to critical/zero-day vulnerabilities as the primary point of contact across security, engineering, and operations.
  • Define and maintain tooling integrations between VOC tooling and the broader security ecosystem.

What we’re looking for

  • 5–8 years in information security, with at least 3 years focused on vulnerability management or security operations.
  • Strong practical knowledge of vulnerability scanning tools and their strengths/limitations in cloud-native environments.
  • Solid understanding of CVE/NVD, CVSS, EPSS, and SSVC and how to apply them to real-world prioritization.
  • Experience managing vulnerabilities across IaaS/cloud infrastructure (AWS, GCP, Azure, or private cloud). GPU/HPC environment experience is a plus.
  • Deep understanding of vulnerability sources and limitations (requirements text appears truncated at the end of the posting).

About Nebius

Nebius builds a full-stack AI cloud infrastructure platform for the global AI economy, spanning compute, storage, networking, and applied AI. The company supports developers and enterprises from data/model training to production deployment, aiming to reduce the cost and complexity of building large in-house AI/ML infrastructure. Nebius is publicly listed on Nasdaq (NBIS) and is headquartered in Amsterdam with global R&D hubs.

Scraped 8/17/2026