The posting, in Nebius Group's own words
archived Sep 14, 2026About Nebius:
Nebius is leading a new era in cloud infrastructure for the global AI economy. We are building a full-stack AI cloud platform that supports developers and enterprises from data and model training through to production deployment, without the cost and complexity of building large in-house AI/ML infrastructure. Built by engineers, for engineers. From large-scale GPU orchestration to inference optimization, we own the hard problems across compute, storage, networking and applied AI. Listed on Nasdaq (NBIS) and headquartered in Amsterdam, we have a global footprint with R&D hubs across Europe, the UK, North America and Israel. Our team of 1,500+ includes hundreds of engineers with deep expertise across hardware, software and AI R&D. Application Security The team is responsible for the security of Nebius's main public offerings : Compute, VPC, Managed K8s, Marketplace, Managed Soperator, and others. This includes building out the Secure SDLC , threat modeling, and vulnerability management platforms.
The Role
We are looking for an Senior/Staff Application Security Engineer who will ensure the security of our software by identifying and mitigating vulnerabilities, implementing best security practices, and collaborating with development teams. The ideal candidate will have a strong background in secure coding, threat modeling and building Secure SDLC.
Read the full posting ↓
What you will do
Build and maintain Application Security Posture Management (ASPM) at the Company scale. Automate and support SAST, SCA tools, etc as part of CI/CD pipelines. Improving SAST, secrets detection rules. Keeping false positive rate low. Identify, analyze, and remediate application security vulnerabilities. Collaborate with development teams to integrate security best practices into the software development lifecycle (SDLC). Develop and maintain secure coding guidelines for development teams. Conduct, run threat modeling and risk assessments for new and existing applications. Provide development teams with instruments that facilitate security-related work like threat modelling, vulnerability detection, etc. Stay updated on the latest security threats, vulnerabilities, and mitigation techniques. Serve as an application security subject matter expert to other teams.