Head of Security Reliability

Nebius · Israel · Engineering

Posted 2026-08-25

Apply for this role →

About the role

Nebius is looking for a Head of Security Reliability to establish and lead the Security Reliability pillar. Reporting directly to the CISO, this leader will be accountable for the ongoing effectiveness, resilience, and operational maturity of Nebius security products after implementation.

The role ensures that security platforms remain properly configured, maintained, integrated, monitored, adopted, and optimized to deliver measurable risk reduction. It also owns Nebius's Third-Party Risk Management (TPRM) program and the security-review process for new products, services, and technologies introduced across the company.

This is a hands-on leadership position for someone who combines security expertise, operational discipline, vendor-management experience, and a strong product mindset. The role partners closely with Security, IT, Engineering, Product, Procurement, Legal, Privacy, Compliance, and business stakeholders.

Key responsibilities

Security product reliability and lifecycle ownership

Own security products and platforms after implementation, from operational handover through optimization, renewal, replacement, or retirement.

Ensure security tools are correctly configured, maintained, integrated, monitored, and aligned with Nebius's risk profile and technical environment.

Define ownership, service levels, operating procedures, support models, and escalation paths for every security platform.

Monitor platform availability, data quality, control coverage, integration health, licensing, capacity, and performance.

Establish disciplined processes for upgrades, configuration changes, testing, exception management, and end-of-life planning.

Continuously assess whether security products deliver their intended outcomes, and improve utilization, coverage, automation, and return on investment.

Reduce overlapping capabilities, configuration drift, operational gaps, and underused tooling across the security stack.

Manage vendor performance, technical escalations, product-roadmap discussions, renewals, and service reviews.

Ensure newly implemented security products transition into operations with clear documentation, ownership, monitoring, and success criteria.

Security configuration and control assurance

Define and maintain secure configuration baselines for security platforms.

Establish continuous control-health monitoring to identify disabled, degraded, misconfigured, or incomplete controls.

Validate that integrations and telemetry remain complete, accurate, and reliable as Nebius's environment evolves.

Coordinate remediation of control gaps with Security, IT, Engineering, and platform owners.

Maintain evidence demonstrating the operational effectiveness of security controls for audits, certifications, and customer-assurance activities.

Security reviews for new products and technologies

Lead the security-review process for new products, services, platforms, and technologies being introduced at Nebius.

Engage early with Product, Engineering, IT, Procurement, and business teams to identify security requirements and risks.

Review proposed solutions across architecture, identity and access, data protection, logging, integrations, cloud configuration, resilience, and third-party dependencies.

Provide pragmatic, risk-based recommendations that enable teams to move forward securely.

Define approval criteria and ensure identified risks have clear owners, remediation plans, compensating controls, or formally documented acceptance.

Establish reusable standards, questionnaires, patterns, and workflows to improve review consistency and turnaround time.

Ensure approved products transition into the appropriate operational, monitoring, and risk-management processes.

Leadership and governance

Build, lead, and develop a high-performing Security Reliability team.

Define the pillar's strategy, roadmap, operating model, priorities, budget, and success measures.

Create clear accountability across internal teams and external service providers.

Give the CISO and senior leadership clear visibility into control health, tooling effectiveness, third-party exposure, and material risks.

Support incident response when failures, misconfigurations, or third-party services contribute to an incident.

Drive automation and data-informed decision-making across security operations and risk-management processes.

Promote a culture of operational ownership, continuous improvement, and measurable security outcomes.

Success measures

Success in this role will be measured through outcomes such as:

Availability, reliability, and coverage of security platforms.

Reduction in configuration drift and degraded or ineffective controls.

Improved utilization and measurable value from security investments.

Timely completion of upgrades, renewals, remediation actions, and lifecycle activities.

Coverage, quality, and turnaround time of third-party assessments and security reviews.

Reduction in overdue third-party findings and unmanaged vendor risks.

Quality and timeliness of risk decisions and stakeholder support.

Successful audit, certification, and control-effectiveness outcomes.

Stakeholder satisfaction with the Security Reliability, TPRM, and review processes.

Experience and qualifications

Significant cybersecurity experience, including leadership responsibility in security engineering, security operations, platform security, security architecture, or technology risk.

Proven experience owning security products in production, including configuration, maintenance, integration, optimization, and lifecycle management.

Strong understanding of enterprise and cloud security technologies, architectures, and operating models.

Experience establishing or managing a Third-Party Risk Management program.

Experience performing security architecture, technology, vendor, or product reviews.

Demonstrated ability to translate technical findings into clear business risks and actionable recommendations.

Experience managing teams, budgets, vendors, service providers, and cross-functional programs.

Strong knowledge of security control frameworks and risk-management principles.

Ability to operate effectively in a complex, fast-moving, and highly technical organization.

Excellent communication and stakeholder-management skills, including presenting risks and recommendations to senior leadership.

A pragmatic approach that balances security, reliability, business needs, and delivery speed.

Preferred qualifications

Experience in cloud infrastructure, large-scale technology platforms, or AI infrastructure environments.

Familiarity with security platforms across cloud security, endpoint security, identity, vulnerability management, data protection, application security, SIEM, and detection and response.

Experience automating security operations, control monitoring, vendor assessments, or evidence collection.

Relevant certifications such as CISSP, CISM, CRISC, CCSP, or equivalent practical experience.

Experience supporting regulatory, certification, or customer-assurance programs.

Apply for this role →

← Back to all jobs