EU remote
Network Security Engineer
About this role
About Nebius : Nebius is leading a new era in cloud infrastructure for the global AI economy. We are building a full-stack AI cloud platform that supports developers and enterprises from data and model training through to production deployment, without the cost and complexity of building large in-house AI/ML infrastructure. Built by engineers, for engineers. From large-scale GPU orchestration to inference optimization, we own the hard problems across compute, storage, networking and applied AI.
Listed on Nasdaq (NBIS) and headquartered in Amsterdam, we have a global footprint with R&D hubs across Europe, the UK, North America and Israel. Our team of 1,500+ includes hundreds of engineers with deep expertise across hardware, software and AI R&D. Role Summary We are looking for a Network Security Engineer to join our Network team. This role combines deep expertise in network engineering and cybersecurity. You will help implement end-to-end network security architectures for enterprise and data center backbone/fabric environments, work with network architects and the management team to guide these designs through review and approval with the Security team, and operate and maintain the implemented solutions day-to-day.
You are expected to be hands-on with leading firewall platforms (Palo Alto, Check Point, etc.), understand complex routing and switching designs, and be comfortable implementing and troubleshooting these networks. Responsibilities Implement and maintain Zero Trust-aligned security architectures for both enterprise and data center networks. Configure Layer 3/4 & Multi-VRF Segmentation, Security Policies, Secure Remote access.
Implement and test large hyper scale DC Security solutions : IPS/NDR solutions , AntiDDOS solutions. Integrate NGFW platforms with modern identity providers such as Microsoft Entra ID and Okta, maintain NGFW management, automation, and logging capabilities required by the Security team. Implement and maintain Security Capabilities, including Layer 7 application inspection, IPS, user identification, ZTNA, and SASE integrations.
Integrate and operate monitoring tools such as Zabbix, Grafana, and Akvorado. Regularly perform security hardening, vulnerability management, and patching and upgrades on network and infrastructure devices, and verify the effectiveness of these procedures. Required Qualifications Experience in networking and security protocols (TCP/IP, HTTP(S), DNS, TLS, IPsec, Routing protocols ) Experience and Knowledge of Backbone & Datacenter technologies (EVPN, L3VPN MPLS, MPBGP, L2VPN..) Hands-on experience with next-generation firewalls (Palo Alto Networks, Check Point, or similar).