Vulnerability Operation Center Lead
Nebius
See how well this job matches your profile
Sign up to get an AI match score and generate a tailored application in seconds.
Get your match scoreTags
About the role
Role: Vulnerability Operations Center (VOC) Lead
Nebius is building a Vulnerability Operations Center from the ground up and is seeking a senior practitioner to lead end-to-end vulnerability operations across its cloud infrastructure, product, and hardware stack.
What you’ll do
- Own the full vulnerability management lifecycle: detection → triage → remediation tracking → reporting.
- Improve automated vulnerability triage and data quality using:
- internal/external intelligence feeds and data enrichment
- quality metrics
- AI-assisted triage
- context-aware risk scoring
- vulnerability correlation/chaining
- Hands-on triage of the most critical zero-days.
- Partner with internal stakeholders (engineering, compliance, regulatory) to deliver high-quality, actionable findings and drive effective remediation.
- Build and improve internal platforms, including:
- Unified Vulnerability Management (UVM)
- security orchestration platform to automate workflows and reduce manual effort.
- Assess and fix patch/remediation deficiencies across engineering teams and business units to improve remediation efficiency and reduce organizational risk.
- Own vulnerability intake from multiple sources: scanners, bug bounty, threat intel feeds, and penetration tests.
- Prioritize using risk-based frameworks such as CVSS, EPSS, SSVC, asset criticality, exploitability context, and business impact.
- Drive remediation accountability across infrastructure, platform, and product engineering teams.
- Track and report metrics/KPIs and trends to security leadership.
- Coordinate response to critical/zero-day vulnerabilities as the primary point of contact across security, engineering, and operations.
- Define and maintain tooling integrations between VOC tooling and the broader security ecosystem.
What we’re looking for
- 5–8 years in information security, with at least 3 years focused on vulnerability management or security operations.
- Strong practical knowledge of vulnerability scanning tools and their strengths/limitations in cloud-native environments.
- Solid understanding of CVE/NVD, CVSS, EPSS, and SSVC and how to apply them to real-world prioritization.
- Experience managing vulnerabilities across IaaS/cloud infrastructure (AWS, GCP, Azure, or private cloud). GPU/HPC environment experience is a plus.
- Deep understanding of vulnerability sources and limitations (requirements text appears truncated at the end of the posting).
About Nebius
Nebius builds a full-stack AI cloud infrastructure platform for the global AI economy, spanning compute, storage, networking, and applied AI. The company supports developers and enterprises from data/model training to production deployment, aiming to reduce the cost and complexity of building large in-house AI/ML infrastructure. Nebius is publicly listed on Nasdaq (NBIS) and is headquartered in Amsterdam with global R&D hubs.
Scraped 8/17/2026