Back to all jobs
Nebius logo

Security & GRC Analyst (Agentic Search)

Nebius
Israel2d ago

About the role

<div class="content-intro"><p><strong>About Nebius:</strong></p> <p>Nebius is leading a new era in cloud infrastructure for the global AI economy. We are building a full-stack AI cloud platform that supports developers and enterprises from data and model training through to production deployment, without the cost and complexity of building large in-house AI/ML infrastructure.</p> <p>Built by engineers, for engineers. From large-scale GPU orchestration to inference optimization, we own the hard problems across compute, storage, networking and applied AI.</p> <p>Listed on Nasdaq (NBIS) and headquartered in Amsterdam, we have a global footprint with R&amp;D hubs across Europe, the UK, North America and Israel. Our team of 1,500+ includes hundreds of engineers with deep expertise across hardware, software and AI R&amp;D.</p></div><h3 id="The-product" data-local-id="fad1110b8813" data-renderer-start-pos="25">The product</h3> <p data-renderer-start-pos="38" data-local-id="56c74b978287">In a rapidly evolving world, trust in AI depends on AI agents being grounded in fresh, verified real-world data. Search is the foundation that makes this possible.</p> <p data-renderer-start-pos="203" data-local-id="06b1dce4c26a">We are building an agent-native search platform designed specifically for AI systems rather than human users. Our product provides programmatic, low-latency, and observable search APIs that AI agents use to retrieve, filter, and reason over real-world information at scale.</p> <p data-renderer-start-pos="478" data-local-id="cae7b52f0d5d">Security is a key part of earning trust with customers, partners, and internal teams. As Tavily grows, we need security to move fast with the business: supporting enterprise customers, reviewing vendors, improving internal controls, and strengthening the technical security posture of our cloud and SaaS environment.</p> <h3 id="The-role" data-local-id="f9cc5cbf93aa" data-renderer-start-pos="796">The role</h3> <p data-renderer-start-pos="806" data-local-id="54f7b1aa8235">We are looking for a <strong data-renderer-mark="true">Security &amp; <span data-highlighted="true" data-vc="highlighted-text">GRC</span> Analyst</strong> to join Tavily’s Security team and report to the Information Security Manager.</p> <p data-renderer-start-pos="930" data-local-id="2476987b0bc4">This is a hands-on hybrid role for someone who can operate across <span data-highlighted="true" data-vc="highlighted-text">GRC</span>, customer assurance, vendor risk, and technical security operations. You will help us move faster with customers, approve vendors more efficiently, reduce single-person dependency in Security, and improve our security posture through practical technical execution.</p> <p data-renderer-start-pos="1266" data-local-id="80d452a85131">This role is a good fit for someone who enjoys both sides of security: answering customer and audit questions clearly, while also getting into tools, logs, access reviews, vulnerabilities, SaaS controls, and security workflows.</p> <h3><strong>What You’ll Do</strong></h3> <ul class="ak-ul" data-local-id="09a239db09ed" data-indent-level="1"> <li> <p data-renderer-start-pos="1673" data-local-id="9a044f2e6139">Support customer security questionnaires,&nbsp;<span data-highlighted="true" data-vc="highlighted-text"><span class="_kqswh2mm"><span class="_5pioz8co _189e1dm9 _1il9buyh _19lc184f _d0altlke" data-testid="definition-highlighter">RFP</span></span></span> security sections, trust portal requests, and customer security reviews, helping Security move at the speed of commercial deals.</p> </li> <li> <p data-renderer-start-pos="1851" data-local-id="a1665ed42d3f">Review security-related customer agreement requirements together with Legal and Sales, ensuring responses are accurate, practical, and aligned with Tavily’s actual controls.</p> </li> <li> <p data-renderer-start-pos="2028" data-local-id="bda24ef7a182">Perform third-party and vendor risk reviews, including SOC 2 / ISO 27001 evidence, DPAs, subprocessors, data flows, and residual risk recommendations.</p> </li> <li> <p data-renderer-start-pos="2182" data-local-id="9b6544cd9716">Support Tavily’s <span data-highlighted="true" data-vc="highlighted-text">GRC</span> program, including audit evidence, control tracking, risk register updates, access reviews, policy maintenance, and readiness for frameworks such as SOC 2, ISO 27001, <span data-highlighted="true" data-vc="highlighted-text"><span class="_kqswh2mm"><span class="_5pioz8co _189e1dm9 _1il9buyh _19lc184f _d0altlke" data-testid="definition-highlighter">GDPR</span></span></span>, and <span data-highlighted="true" data-vc="highlighted-text"><span class="_kqswh2mm"><span class="_5pioz8co _189e1dm9 _1il9buyh _19lc184f _d0altlke" data-testid="definition-highlighter">NIST</span></span></span>.</p> </li> <li> <p data-renderer-start-pos="2389" data-local-id="3be1ed9773ee">Implement and operationalize security tools and workflows across cloud, SaaS, identity, endpoint, vulnerability management, monitoring, and alerting.</p> </li> <li> <p data-renderer-start-pos="2542" data-local-id="cd23e82ae028">Partner with Engineering, DevOps, IT, Legal, <span data-highlighted="true" data-vc="highlighted-text"><span class="_kqswh2mm"><span class="_5pioz8co _189e1dm9 _1il9buyh _19lc184f _d0altlke" data-testid="definition-highlighter">GTM</span></span></span>, and Customer Success to turn security requirements into practical processes that work in a fast-growing company.</p> </li> </ul> <h3>What You Bring</h3> <ul class="ak-ul" data-local-id="76870069991c" data-indent-level="1"> <li> <p data-renderer-start-pos="2985" data-local-id="7d4e5af8cd18">3+ years of experience in information security, security engineering,&nbsp;<span data-highlighted="true" data-vc="highlighted-text">GRC</span>, security operations, security consulting, vCISO work, or a similar hybrid security role.</p> </li> <li> <p data-renderer-start-pos="3157" data-local-id="a112d87203b3">Hands-on experience with customer security questionnaires, RFPs, trust portals, customer security reviews, audit evidence, or enterprise security assessments.</p> </li> <li> <p data-renderer-start-pos="3324" data-local-id="38a0a34f6e92">Experience implementing or operating security tools such as Wiz, Snyk, Orca, AWS Inspector, GuardDuty, GitHub Advanced Security, Dependabot, Semgrep, Trivy, CrowdStrike, SentinelOne, Okta, Auth0, Google Workspace security controls, <span data-highlighted="true" data-vc="highlighted-text"><span class="_kqswh2mm"><span class="_5pioz8co _189e1dm9 _1il9buyh _19lc184f _d0altlke" data-testid="definition-highlighter">SIEM</span></span></span>/logging tools, or similar.</p> </li> <li> <p data-renderer-start-pos="3596" data-local-id="2116d17ee641">Understand cloud and SaaS security basics, including <span data-highlighted="true" data-vc="highlighted-text"><span class="_kqswh2mm"><span class="_5pioz8co _189e1dm9 _1il9buyh _19lc184f _d0altlke" data-testid="definition-highlighter">IAM</span></span></span>, <span data-highlighted="true" data-vc="highlighted-text"><span class="_kqswh2mm"><span class="_5pioz8co _189e1dm9 _1il9buyh _19lc184f _d0altlke" data-testid="definition-highlighter">SSO</span></span></span>/<span data-highlighted="true" data-vc="highlighted-text"><span class="_kqswh2mm"><span class="_5pioz8co _189e1dm9 _1il9buyh _19lc184f _d0altlke" data-testid="definition-highlighter">MFA</span></span></span>, access reviews, logging, endpoint security, vulnerability management, and security monitoring.</p> </li> <li> <p data-renderer-start-pos="3761" data-local-id="c0ae80ab12ef">Are comfortable working in a small security team where you need to be independent, practical, hands-on, and able to switch between customer, compliance, vendor, and technical work.</p> </li> <li> <p data-renderer-start-pos="3945" data-local-id="325b9db6389f">Have supported audits or assessments against frameworks such as SOC 2, ISO 27001 / ISO 27002, <span data-highlighted="true" data-vc="highlighted-text">GDPR</span>, <span data-highlighted="true" data-vc="highlighted-text">NIST</span> <span data-highlighted="true" data-vc="highlighted-text"><span class="_kqswh2mm"><span class="_5pioz8co _189e1dm9 _1il9buyh _19lc184f _d0altlke" data-testid="definition-highlighter">CSF</span></span></span>, <span data-highlighted="true" data-vc="highlighted-text"><span class="_kqswh2mm"><span class="_5pioz8co _189e1dm9 _1il9buyh _19lc184f _d0altlke" data-testid="definition-highlighter">CIS</span></span></span> Controls, or similar security/privacy standards.</p> </li> </ul> <h3 id="Nice-to-have" data-local-id="1789d8b7c222" data-renderer-start-pos="4111">Nice to have</h3> <ul class="ak-ul" data-local-id="a5fd61b3b5e3" data-indent-level="1"> <li> <p data-renderer-start-pos="4248" data-local-id="45b02abeb2c9">Experience in a startup, scale-up, B2B SaaS company, security company, <span data-highlighted="true" data-vc="highlighted-text">GRC</span> consulting firm, or audit/security advisory environment.</p> </li> <li> <p data-renderer-start-pos="4383" data-local-id="50f6680030f7">Experience with AI security, LLM security, prompt injection, data leakage, privacy/security controls for AI products, or AI governance.</p> </li> <li> <p data-renderer-start-pos="4522" data-local-id="d90187030ff8">Experience improving security workflows end-to-end, such as vulnerability management, SaaS monitoring, access reviews, endpoint security, security alerting, or cloud security posture management.</p> </li> </ul><div class="content-conclusion"><p><strong>Benefits &amp; Perks:</strong></p> <ul> <li>Competitive compensation</li> <li>Career growth and learning opportunities</li> <li>Flexibility and ownership</li> <li>Collaborative and innovative culture</li> <li>Opportunity to work on impactful AI projects</li> <li>International environment and talented teams</li> </ul> <p><strong>What's it like to work at Nebius:</strong></p> <p>Fast moving&nbsp;- Bold thinking&nbsp;- Constant growth&nbsp;- Meaningful impact&nbsp;- Trust and real ownership&nbsp;- Opportunity to shape the future of AI&nbsp;</p> <p><strong>Equal Opportunity Statement:</strong></p> <p>Nebius is an equal opportunity employer. We are committed to fostering an inclusive and diverse workplace and to providing equal employment opportunities in all aspects of employment. We do not discriminate on the basis of race, color, religion, sex (including pregnancy), national origin, ancestry, age, disability, genetic information, marital status, veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by applicable law.</p> <p>Applicants must be authorized to work in the country in which they apply and will be required to provide proof of employment eligibility as a condition of hire.&nbsp;</p> <p>If you need accommodations during the application process, please let us know.</p></div>

731,000+ hidden jobs like this

Nebius and thousands of companies post here first — often days before LinkedIn or Indeed. Your first 5 applications are free; go Pro to apply without limits.

Everything Pro unlocks:

  • Unlimited applications — free stops at 5
  • Track every application in one place
  • Apply straight to the source, one click
  • Save & organize roles you love
  • Roles pulled from company boards before the big sites

Weekly

$9.99
$4.99/week

For an active search. Cancel anytime.

Most popular

Monthly

$24.99
$12.99/month

The smart pick. Save 35% vs weekly.

Lifetime

$99
$49.99once

Pay once. Every future feature, forever.