Senior Data Engineer
About Us
Nebulock builds hunt-first, behavior-first security operations. Enterprise security teams use us to find attackers already inside their environment by spotting behavior that's abnormal for that organization, rather than by matching signatures of attacks someone has already seen. Attackers rotate tooling constantly and it costs them almost nothing; changing how they behave is much harder.
Series A, $34M total raised led by FirstMark, with Bain Capital Ventures, Decibel, Zetta, Step Function, and In-Q-Tel. Founding team out of CrowdStrike, Palo Alto Networks, and Arctic Wolf.
The platform is a closed loop:
A per-customer behavioral system of record that learns what normal looks like in a specific environment and gets more useful the longer it runs
Detections built from that context, re-baselining as environments shift, maintained by a detection engineering team rather than shipped and forgotten
Autonomous hunting agents that work from a hypothesis instead of an alert, and write the detection when they establish root cause
Detection engineering agents that take the context of threat hunts run to build, test, validate and deploy behavioral detections for Nebulock customers.
Position Overview
The Data Platform team is responsible for ingesting security telemetry data from our customers’ environments, transforming the data, and making it available to AI agents that continuously scan this data to look for malicious activities. We also tackle hard problems such as correlating entities across events from disparate sources and generating a queryable baseline view of activities that will allow agents to detect anomalies.
As a Senior Data Engineer on this team, you will own the core systems that form the foundation upon which Nebulock is built. You’ll co-own the data ingestion, transformation, and search layers that power agentic threat hunting workflows. We currently ingest terabytes of data per day and are growing fast. This role is ideal for engineers who love bringing clarity and order to messy, disparate, and large-scale datasets.
Expected Impact
Design, build, and maintain scalable data pipelines that ingest and process large volumes of security telemetry (TBs / day)
Own API and event stream integrations across a wide range of third-party data sources (EDR, IAM, Cloud, SaaS)
Develop and maintain the transformation layer that turns disparate data into a normalized, enriched, and queryable model
Build an engine that correlates entities across disparate data sources
Work on core search capabilities across vast amounts of data
Collaborate with our internal detection engineers, threat hunters, and product engineers to ensure the data needs of Nebulock’s agentic threat hunting platform is met
Set and promote data engineering standards and best practices, including observability, monitoring and automated testing
Help drive the architecture and technical direction of Neublock’s platform
Qualifications
4+ years of experience building data pipelines supporting customer-facing products
Experience with data warehousing technologies
Proficiency in Python, Java, Go, Rust, or similar
Hands-on experience with large-scale event streaming systems such as Kafka or similar
Experience with either AWS or GCP
Strong systems thinking and understanding of performance, cost and complexity trade-offs
Ability to adapt, iterate, and ship quickly
Hunger for growth and the desire to work in a low-ego environment
Nice to Haves
Experience with Clickhouse
Experience building or working with search systems over large datasets
DevOps or platform engineering experience
Cybersecurity experience
Startup experience
Compensation
We offer a competitive compensation package comprised of a base salary, equity and comprehensive benefits. The base salary for this role is $160,000 - $200,000. Compensation packages are determined based on a number of factors including but not limited to, role related experience, skillset, and geographic location.
Benefits
Health, dental, and vision coverage
Unlimited PTO
Remote working flexibility
Life Insurance
401k
As published by ashby
Name, Email, Resume
- Do you now or in the future require visa sponsorship? yes / no
- Where do you currently reside? optional
- Which event streaming technologies have you used hands-on in production?
- Can you please provide details of a large-scale data pipeline you have built recently? written answer