
Job Description
About Us
Nebulock is an agentic threat hunting platform that autonomously surfaces behaviors, not just IOCs, from various data sources. Nebulock acts like a teammate: a 24/7 AI threat hunter that investigates hypotheses, reasons through telemetry, and learns from an environment. Today, threat hunting is broken. Security teams spend weeks chasing alerts, writing detections by hand, and manually validating findings often just to confirm what their existing tools already flagged. Meanwhile, attackers exploit credentials, move laterally, and operate in silence. Nebulock flips the model. We continuously and autonomously hunt across endpoint, identity, and cloud telemetry. We identify the subtle behavioral signals that point to credential misuse, lateral movement, insider threats, and post-access activity. Then we turn those hunts into hardened, behavior-based detections automatically.
Position Overview
The Data Platform team is responsible for ingesting security telemetry data from our customers’ environments, transforming the data, and making it available to AI agents that continuously scan this data to look for malicious activities. We also tackle hard problems such as correlating entities across events from disparate sources and generating a queryable baseline view of activities that will allow agents to detect anomalies.
As a Senior Data Engineer on this team, you will own the core systems that form the foundation upon which Nebulock is built. You’ll co-own the data ingestion, transformation, and search layers that power agentic threat hunting workflows. We currently ingest terabytes of data per day and are growing fast. This role is ideal for engineers who love bringing clarity and order to messy, disparate, and large-scale datasets.
Expected Impact
Design, build, and maintain scalable data pipelines that ingest and process large volumes of security telemetry (TBs / day)
Own API and event stream integrations across a wide range of third-party data sources (EDR, IAM, Cloud, SaaS)
Develop and maintain the transformation layer that turns disparate data into a normalized, enriched, and queryable model
Build an engine that correlates entities across disparate data sources
Work on core search capabilities across vast amounts of data
Collaborate with our internal detection engineers, threat hunters, and product engineers to ensure the data needs of Nebulock’s agentic threat hunting platform is met
Set and promote data engineering standards and best practices, including observability, monitoring and automated testing
Help drive the architecture and technical direction of Neublock’s platform
Qualifications
4+ years of experience building data pipelines supporting customer-facing products
Experience with data warehousing technologies
Proficiency in Python, Java, Go, Rust, or similar
Hands-on experience with large-scale event streaming systems such as Kafka or similar
Experience with either AWS or GCP
Strong systems thinking and understanding of performance, cost and complexity trade-offs
Ability to adapt, iterate, and ship quickly
Hunger for growth and the desire to work in a low-ego environment
Nice to Haves
Experience with Clickhouse
Experience building or working with search systems over large datasets
DevOps or platform engineering experience
Cybersecurity experience
Startup experience
What We Offer
A dynamic startup environment with opportunities for rapid career growth
A collaborative culture that values innovation and creativity
Competitive salary and equity options
Comprehensive benefits package (including 401K)
Opportunities to travel for conferences, workshops, and team-building events
Optimize Your Resume for This Job
Get a match score and see exactly which keywords you're missing
Job Details
- Category
- Software
- Employment Type
- Full Time
- Location
- United States (Remote)
- Posted
About Nebulock
Nebulock is the first agentic threat hunting platform; autonomously surfacing behaviors, not just IOCs, from your existing data. Nebulock acts like a new teammate: a 24/7 AI threat hunter that investigates hypotheses, reasons through your telemetry, and learns from your environment. Whether you’re a two-person SOC or a global enterprise, we scale your threat hunting—and give your team superpowers. Today, threat hunting is broken. Security teams spend weeks chasing alerts, writing detections by hand, and manually validating findings—often just to confirm what their existing tools already flagged. Meanwhile, attackers exploit credentials, move laterally, and operate in silence. Nebulock flips the model. We continuously and autonomously hunt across endpoint, identity, and cloud telemetry—identifying the subtle behavioral signals that point to credential misuse, lateral movement, insider threats, and post-access activity. Then we turn those hunts into hardened, behavior-based detections—automatically. No new agents No alert regurgitation No workflow disruption Just high-fidelity, explainable findings—delivered directly to your SIEM, API, or Slack.
More Roles at Nebulock





Similar Software Roles



Found this role interesting?