Remotery

Offensive Security Lead

Posted Jul 18

This is a fully remote position, open to applicants in Europe.

📋 Description

• Lead the development and management of a red team function within the Product Security Team, focusing on hiring and nurturing offensive security engineers.

• Validate and enhance early-stage Secure SDLC threat models through ongoing penetration testing, evaluating threat severity and mitigation status while questioning assumptions made during threat modeling and system development. Automate routine validations to maintain pace with the increasing feature flow, reserving manual analysis for genuinely complex scenarios.

• Strategically plan and conduct comprehensive red team engagements against the Nebius cloud platform, encompassing compute, storage, inference, networking, orchestration layers, and internal tools. Identify threats capable of impacting organizational operations. Collaborate with Detection & Response and other security engineering teams to perform purple team exercises, validate detection coverage, and address gaps collectively.

• Investigate novel attack vectors targeting GPU infrastructure (e.g., closed-source firmware, vendor driver binaries, device passthrough exploits, SR-IOV/IOMMU misconfigurations, RDMA/InfiniBand fabric attacks, etc.), the inference stack (e.g., vLLM, TRT-LLM), and AI platform managed services (e.g., managed Slurm). Evaluate tenant-isolation boundaries and their potential vulnerabilities at the low-level stack.

• Perform targeted assessments of new products and infrastructure changes prior to deployment.

• Produce clear, actionable reports aimed at both technical audiences and leadership, including prioritized findings and remediation recommendations.

• Develop red team processes, tools, and methodologies that can scale as the platform evolves.


⛳️ Requirements

• Over 6 years of experience in offensive security, including penetration testing, red teaming, or adversary simulation, with a minimum of 1-2 years in a leadership or mentoring role.

• Extensive experience in attacking cloud-native environments: Kubernetes privilege escalation, cloud IAM abuse, virtualization, and container escapes.

• Strong foundational knowledge of the attack lifecycle: initial access, persistence, lateral movement, and data exfiltration.

• Expertise in developing custom tools and post-exploitation capabilities (using Python, Go, or similar languages).

• Experience facilitating purple team exercises and collaborating effectively with blue teams.

• Capability to compose clear, senior-level reports that contextualize risks for business relevance (beyond mere findings) that engineers can readily utilize.


🏝️ Benefits

• Competitive compensation

• Opportunities for career growth and learning

• Flexibility and ownership

• A collaborative and innovative culture

• Chance to work on impactful AI projects

• International environment with talented teams

People also viewed

LimeJul 26

Senior Security Engineer

CA flagCanada OnlyFull-timeCybersecurity / Security Engineer$120k/year
ApplyView job
ThreatscapeJul 26

Associate Consultant – Microsoft Security, Purview, Data Security and Governance, AI

GB flagUnited Kingdom OnlyFull-timeCybersecurity / Security Engineer£35k – £47k/year
ApplyView job
GFT TechnologiesJul 26

Senior IT Security Project Manager

CR flagCosta Rica OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
BeyondTrustJul 26

VP, Product Management, AI Security – Strategy

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
QuisitiveJul 26

Digital Security Coach

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
GEICOJul 25

Senior Field Security Investigator

US flagFlorida OnlyFull-timeCybersecurity / Security Engineer$3,200 – $5,000/year
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers