
Job Description
About Us
Nebulock is an agentic threat hunting platform that autonomously surfaces behaviors, not just IOCs, from various data sources. Nebulock acts like a teammate: a 24/7 AI threat hunter that investigates hypotheses, reasons through telemetry, and learns from an environment. Today, threat hunting is broken. Security teams spend weeks chasing alerts, writing detections by hand, and manually validating findings often just to confirm what their existing tools already flagged. Meanwhile, attackers exploit credentials, move laterally, and operate in silence. Nebulock flips the model. We continuously and autonomously hunt across endpoint, identity, and cloud telemetry. We identify the subtle behavioral signals that point to credential misuse, lateral movement, insider threats, and post-access activity. Then we turn those hunts into hardened, behavior-based detections automatically.
About the Role
As a Sr. Onboarding Engineer, you will ensure seamless post-sale implementations by resolving complex database field mappings, configuring API integrations, and guiding customers on how to maximize our AI platform. You will work directly with enterprise security teams to transform their telemetry into actionable threat hunting and detection workflows, ensuring fast time-to-value and technical success.
Key Responsibilities
Scope and Ingest Data Pipelines: Scope customer environments and establish secure data ingestion pipelines via APIs, log shippers, and connectors.
Data intake solutions: Reviews and resolves complex ingestion and transformation pipelines to directly write code, resolve schema nuances, and deploy fixes.
Validate Telemetry Quality: Perform data quality assurance to verify log schema integrity and field alignment, ensuring the AI engine receives structured, actionable telemetry.
Guide & Tune AI Models: Assist customers in feeding hypotheses and threat intelligence into AI models, troubleshooting output anomalies, and tuning model parameters for optimal detection accuracy.
Automate Customer Workflows: Map customer operational workflows and build tailored automation using webhooks, APIs, and scripting tools to accelerate alert triage and incident response.
Deliver Technical Product Enablement: Lead interactive training sessions covering Findings (triaging AI outputs), Threat Hunting (executing AI hypothesis and retro-intel hunts), and Detection Engineering (drafting, backtesting, and deploying custom rules).
Define Technical Success Milestones: Design custom deployment plans and track technical milestones with customers to measure and validate success metrics throughout onboarding.
Partner with Customer Success Managers (CSMs): Collaborate closely with CSMs to manage project deliverables, scope technical requirements, and mitigate onboarding risks.
Drive Product Feedback Loops: Serve as the voice of the customer to Product and Engineering teams by translating field friction, feature asks, and bug reports into actionable development tickets.
Qualifications
Customer-Facing Technical Experience: 4 or more years in a technical onboarding, solutions engineering, or technical account management role working directly with enterprise IT or Security operations.
Project Management: Ability to manage a customer during an 8 week onboarding engagement, iterate on current onboarding tasks to improve the customer experience, and surface risk to CSM and Products teams.
Automation & Scripting: Strong knowledge of automation tools (SOAR platforms, Webhooks, CI/CD pipelines) and scripting languages (e.g., Python, Bash) to streamline customer workflows.
Data Engineering & Database Troubleshooting: Proven hands-on ability to troubleshoot database field mapping, JSON/SQL transformations, schema validations, and data pipelines.
Preferred Qualifications
Cybersecurity Domain Expertise: Experience with SIEM, XDR, EDR, Threat Hunting, or Detection Engineering frameworks (e.g., SIGMA, YARA, MITRE ATT&CK).
Enterprise Log Management: Familiarity with enterprise log management systems (e.g., Splunk, Snowflake, Elastic, Microsoft Sentinel).
Agile & CS Tools: Experience using Agile project management tools (e.g., Jira, Confluence) and Customer Success platforms.
Cloud Infrastructure & VPCs: Knowledge of cloud infrastructure and Virtual Private Cloud (VPC) architectures (AWS, Azure, GCP), security groups, and cloud network routing.
Optimize Your Resume for This Job
Get a match score and see exactly which keywords you're missing
Job Details
- Category
- Security
- Employment Type
- Full Time
- Location
- United States (Remote)
- Posted
About Nebulock
Nebulock is the first agentic threat hunting platform; autonomously surfacing behaviors, not just IOCs, from your existing data. Nebulock acts like a new teammate: a 24/7 AI threat hunter that investigates hypotheses, reasons through your telemetry, and learns from your environment. Whether you’re a two-person SOC or a global enterprise, we scale your threat hunting—and give your team superpowers. Today, threat hunting is broken. Security teams spend weeks chasing alerts, writing detections by hand, and manually validating findings—often just to confirm what their existing tools already flagged. Meanwhile, attackers exploit credentials, move laterally, and operate in silence. Nebulock flips the model. We continuously and autonomously hunt across endpoint, identity, and cloud telemetry—identifying the subtle behavioral signals that point to credential misuse, lateral movement, insider threats, and post-access activity. Then we turn those hunts into hardened, behavior-based detections—automatically. No new agents No alert regurgitation No workflow disruption Just high-fidelity, explainable findings—delivered directly to your SIEM, API, or Slack.
More Roles at Nebulock





Similar Security Roles



Found this role interesting?