Security Risk Lead - Nebius
- חברה: Nebius
- מיקום: תל אביב - יפו
- רמת ניסיון: סניור
- טכנולוגיות: Risk Management
תיאור המשרה
Lead security risk assessments for infrastructure, cloud environments, products, applications, business processes, and major technology changes. Conduct risk assessments for new initiatives, systems, and significant changes, including supporting M&A-related risk assessment work alongside the due diligence team. Evaluate the design and effectiveness of controls and identify residual risk following mitigation. Identify emerging and systemic risks that may affect multiple services, regions, or business functions. Maintain the security risk register: log new risks, update status, track owners, and follow items through to remediation or formal risk acceptance. Support the ongoing refinement of Nebius's risk assessment and risk register processes, contributing improvements as the practice matures. Coordinate with other GRC functions on findings and gap assessments that carry risk implications, and independently determine whether a given finding warrants a risk register entry. Maintain and improve security risk assessment, scoring, prioritization, and acceptance processes. Define and monitor meaningful Key Risk Indicators and risk trends. Translate complex technical risks into clear business impact for senior leadership and governance forums. Prepare risk reporting that supports security posture reviews, strategic decision-making, and Board-level reporting. Support auditors, customers, and internal stakeholders on security risk management matters. Work closely with other GRC functions to ensure risk assessments reflect current operating reality. Partner with engineering and business stakeholders to embed risk thinking into day-to-day decisions, building trust through clear, practical communication rather than formal authority. Build trusted relationships with risk and remediation owners while maintaining independent and objective judgment. 5-8 years of experience in security risk management, IT risk, GRC, or a closely related discipline. Hands-on experience running risk assessments and maintaining a risk register, including driving items through to remediation or formal risk acceptance. Solid understanding of risk scoring and prioritization approaches, and the judgment to apply them consistently and defensibly. Ability to define and track meaningful risk metrics/KRIs for leadership reporting. Strong organizational and analytical skills, with the ability to manage multiple concurrent risk items without losing accuracy or follow-through. Strong communication and stakeholder management skills; comfortable working across security, compliance, engineering, and business teams. Familiarity with cloud infrastructure and technology environments is an advantage. Relevant certifications (e.g., CRISC, CISSP) are an advantage, not a requirement. Bachelor's degree in information security, computer science, engineering, or a related field preferred; equivalent practical experience will be considered. Excellent written and verbal communication skills in English. Competitive compensation Career growth and learning opportunities Flexibility and ownership Collaborative and innovative culture Opportunity to work on impactful AI projects International environment and talented teams
תחומי אחריות
Risk Assessment Lead security risk assessments for infrastructure, cloud environments, products, applications, business processes, and major technology changes. Conduct risk assessments for new initiatives, systems, and significant changes, including supporting M&A-related risk assessment work alongside the due diligence team. Evaluate the design and effectiveness of controls and identify residual risk following mitigation. Identify emerging and systemic risks that may affect multiple services, regions, or business functions.
דרישות
Lead security risk assessments for infrastructure, cloud environments, products, applications, business processes, and major technology changes. Conduct risk assessments for new initiatives, systems, and significant changes, including supporting M&A-related risk assessment work alongside the due diligence team. Evaluate the design and effectiveness of controls and identify residual risk following mitigation. Identify emerging and systemic risks that may affect multiple services, regions, or business functions. Maintain the security risk register: log new risks, update status, track owners, and follow items through to remediation or formal risk acceptance. Support the ongoing refinement of Nebius's risk assessment and risk register processes, contributing improvements as the practice matures. Coordinate with other GRC functions on findings and gap assessments that carry risk implications, and independently determine whether a given finding warrants a risk register entry. Maintain and improve security risk assessment, scoring, prioritization, and acceptance processes. Define and monitor meaningful Key Risk Indicators and risk trends. Translate complex technical risks into clear business impact for senior leadership and governance forums. Prepare risk reporting that supports security posture reviews, strategic decision-making, and Board-level reporting. Support auditors, customers, and internal stakeholders on security risk management matters. Work closely with other GRC functions to ensure risk assessments reflect current operating reality. Partner with engineering and business stakeholders to embed risk thinking into day-to-day decisions, building trust through clear, practical communication rather than formal authority. Build trusted relationships with risk and remediation owners while maintaining independent and objective judgment. 5-8 years of experience in security risk management, IT risk, GRC, or a closely related discipline. Hands-on experience running risk assessments and maintaining a risk register, including driving items through to remediation or formal risk acceptance. Solid understanding of risk scoring and prioritization approaches, and the judgment to apply them consistently and defensibly. Ability to define and track meaningful risk metrics/KRIs for leadership reporting. Strong organizational and analytical skills, with the ability to manage multiple concurrent risk items without losing accuracy or follow-through. Strong communication and stakeholder management skills; comfortable working across security, compliance, engineering, and business teams. Familiarity with cloud infrastructure and technology environments is an advantage. Relevant certifications (e.g., CRISC, CISSP) are an advantage, not a requirement. Bachelor's degree in information security, computer science, engineering, or a related field preferred; equivalent practical experience will be considered. Excellent written and verbal communication skills in English. Competitive compensation Career growth and learning opportunities Flexibility and ownership Collaborative and innovative culture Opportunity to work on impactful AI projects International environment and talented teams
שאלות נפוצות על המשרה
איך מגישים מועמדות למשרת Security Risk Lead בNebius?
אפשר להגיש מועמדות למשרה זו ישירות מעמוד זה ב-HiTakeJob, ללא עלות וללא צורך במנוי. ההגשה נשלחת למערכת הגיוס של Nebius, ומעקב על הסטטוס זמין באזור המועמדויות שלכם.
איפה המשרה ממוקמת?
המשרה ממוקמת בתל אביב - יפו.
מה נדרש למשרת Security Risk Lead?
רמת ניסיון: סניור. טכנולוגיות מרכזיות: Risk Management. תחום: אבטחת מידע וסייבר. הדרישות המלאות מופיעות בתיאור המשרה שלמעלה, כפי שפורסמו על ידי Nebius.
האם המשרה עדיין פעילה?
כן. המשרה פורסמה ב7 בספטמבר 2026 ומופיעה כפעילה במערכת הגיוס של Nebius. HiTakeJob בודק את המשרות מול המקור מדי יום, ומשרה שנסגרת מוסרת מהאתר.
אילו עוד משרות פתוחות בNebius?
כל המשרות הפתוחות של Nebius מרוכזות בעמוד החברה, יחד עם מידע על החברה וחוות דעת של עובדים.