Security Analyst- Tier 2
Nebius
- Location
- Tel Aviv, Israel
- Work model
- On-Site
- Level
- Mid
- Posted
- 2h ago
Skills
About this role
About Nebius
Nebius is leading a new era in cloud infrastructure for the global AI economy. We are building a full-stack AI cloud platform that supports developers and enterprises from data and model training through to production deployment, without the cost and complexity of building large in-house AI/ML infrastructure.
Built by engineers, for engineers. From large-scale GPU orchestration to inference optimization, we own the hard problems across compute, storage, networking and applied AI.
Listed on Nasdaq (NBIS) and headquartered in Amsterdam, we have a global footprint with R&D hubs across Europe, the UK, North America and Israel. Our team of 1,500+ includes hundreds of engineers with deep expertise across hardware, software and AI R&D.
Role Overview
Nebius is seeking an experienced Security Analyst - Tier 2 for its Security Operations Center (SOC). This role is a hands-on position built for depth, serving as the investigative core of the SOC, focused on evidence and grounded conclusions. This role reports to the SOC Manager, under the Detection and Response function within the CISO Office.
You are welcome to work in our offices in Tel Aviv, Israel.
Key Responsibilities
• Investigate escalated security alerts across endpoint, identity, cloud, email, and network layers.
• Determine scope, impact, and root cause using EDR, SIEM, and supporting telemetry.
• Escalate suspected incidents to the Incident Response team and complex investigations to Tier 3.
• Provide structured feedback to relevant stakeholders on detection or prevention quality, false-positive patterns, and coverage gaps discovered during investigations.
• Contribute to and refine SOC runbooks, triage guides, and investigation procedures.
• Review Tier 1 escalations, coach on handoff quality, and act as the analytical reference during triage.
• Document investigations to a standard that supports handoff, quality review, and lessons learned.
• Participate in the on-call rotation, acting as the investigative point of contact outside business hours.
Experience
• Around 5-7 years of hands-on security operations experience, with proven depth in alert investigation.
• Experience taking investigations to a clear verdict, including confirmed incidents.
Technical Expertise
• Strong working command of EDR platforms and SIEM-based investigation, including writing and adapting queries independently.
• Solid understanding of attacker techniques, with the ability to map findings to MITRE ATT&CK in analysis and reporting.
• Investigation capability across at least two of: endpoint, identity, cloud, email, or network domains.
• Windows and Linux internals at the depth required for log and artifact analysis: processes, authentication flows, and persistence mechanisms.
• Solid networking fundamentals: TCP/IP, DNS, HTTP/S, and the ability to interpret network telemetry.
• Scripting ability (Python or similar) for analysis at scale, and familiarity with SOAR platforms.
• Certifications such as BTL2, OSDA, or CDSA are an advantage.
Leadership & Communication
• Intellectual honesty, clearly distinguishing important and vague data, what is known, what is assumed, and what is still unknown.
• Collaborative escalation habits, hands off with context and stays available to support what comes next.
• Structured written communication, writing investigation notes that tell the story on their own.
• Fluent in English, written and verbal, comfortable working with international teams and stakeholders.
<div