Security Risk Lead
The role
Nebius is looking for a Security Risk Lead to strengthen security risk management across our global AI cloud infrastructure, products, business operations, and strategic programs.
This is a senior, hands-on individual-contributor role with end-to-end ownership of security risk assessments, the security risk register, remediation tracking, risk acceptance, and risk reporting. The successful candidate will work closely with engineering, cloud infrastructure, product, security, compliance, legal, and business teams to ensure that material risks are identified early, assessed consistently, and driven toward clear treatment decisions.
The role requires strong judgment, technical understanding, and the ability to influence stakeholders without relying on formal authority.
Your responsibilities will include
Risk Assessment
Lead security risk assessments for infrastructure, cloud environments, products, applications, business processes, and major technology changes.
Conduct risk assessments for new initiatives, systems, and significant changes, including supporting M&A-related risk assessment work alongside the due diligence team.
Evaluate the design and effectiveness of controls and identify residual risk following mitigation.
Identify emerging and systemic risks that may affect multiple services, regions, or business functions.
Risk Register & Tracking
Maintain the security risk register: log new risks, update status, track owners, and follow items through to remediation or formal risk acceptance.
Support the ongoing refinement of Nebius's risk assessment and risk register processes, contributing improvements as the practice matures.
Coordinate with other GRC functions on findings and gap assessments that carry risk implications, and independently determine whether a given finding warrants a risk register entry.
Metrics & Reporting
Maintain and improve security risk assessment, scoring, prioritization, and acceptance processes.
Define and monitor meaningful Key Risk Indicators and risk trends.
Translate complex technical risks into clear business impact for senior leadership and governance forums.
Prepare risk reporting that supports security posture reviews, strategic decision-making, and Board-level reporting.
Support auditors, customers, and internal stakeholders on security risk management matters.
Cross-Functional Coordination
Work closely with other GRC functions to ensure risk assessments reflect current operating reality.
Partner with engineering and business stakeholders to embed risk thinking into day-to-day decisions, building trust through clear, practical communication rather than formal authority.
Build trusted relationships with risk and remediation owners while maintaining independent and objective judgment.
We expect you to have
5-8 years of experience in security risk management, IT risk, GRC, or a closely related discipline.
Hands-on experience running risk assessments and maintaining a risk register, including driving items through to remediation or formal risk acceptance.
Solid understanding of risk scoring and prioritization approaches, and the judgment to apply them consistently and defensibly.
Ability to define and track meaningful risk metrics/KRIs for leadership reporting.
Strong organizational and analytical skills, with the ability to manage multiple concurrent risk items without losing accuracy or follow-through.
Strong communication and stakeholder management skills; comfortable working across security, compliance, engineering, and business teams.
Familiarity with cloud infrastructure and technology environments is an advantage.
Relevant certifications (e.g., CRISC, CISSP) are an advantage, not a requirement.
Bachelor's degree in information security, computer science, engineering, or a related field preferred; equivalent practical experience will be considered.
Excellent written and verbal communication skills in English.