About the job
Why choose Nebius?
Nebius is at the forefront of cloud computing, dedicated to empowering the global AI economy. We develop innovative tools and resources that help our clients tackle real-world challenges and revolutionize industries, all without incurring hefty infrastructure costs or requiring expansive in-house AI/ML teams. Our team works at the cutting edge of AI cloud infrastructure, collaborating with some of the most seasoned and inventive leaders and engineers in the industry.
Our Work Environment
With our headquarters in Amsterdam and a listing on Nasdaq, Nebius boasts a worldwide presence with R&D hubs throughout Europe, North America, and Israel. Our workforce of over 1400 includes more than 400 exceptional engineers with extensive expertise in both hardware and software engineering, complemented by an in-house AI R&D team.
The Role
We are on the lookout for a seasoned Data Protection Lead to become an integral part of our Cyber Security organization, reporting directly to the Head of Security Engineering under the CISO. This pivotal role will oversee the organization’s data protection domain, emphasizing data discovery, classification, and data loss prevention (DLP) across corporate and cloud environments. You will be tasked with shaping and driving the data protection strategy, executing controls to safeguard sensitive data throughout its lifecycle, and ensuring transparency regarding data locations and usage. Close collaboration with Security, IT, Engineering, Product, and GRC teams will be essential to mitigate data exposure risks and enforce robust data governance practices.
Key Responsibilities
- Steer and take ownership of the organization’s data protection domain, encompassing strategy, standards, and execution.
- Initiate data discovery projects to pinpoint sensitive data across databases, SaaS applications, endpoints, and cloud environments.
- Establish and implement frameworks for data classification, labeling standards, and data handling policies.
- Design and employ data loss prevention (DLP) measures across endpoints, email, SaaS, network, and cloud platforms.
- Ensure the protection of sensitive data throughout its lifecycle, covering storage, processing, and transfer.
- Lead the implementation and refinement of data security technologies (e.g., DLP, DSPM, CASB/SSE, data classification tools).
- Define and enforce data access governance practices, including least privilege principles and monitoring of sensitive data access and usage.
- Monitor and investigate data-related risks, exposures, and policy breaches in collaboration with SOC and Security teams.
- Conduct risk assessments to identify vulnerabilities in data protection.
