Risk Manager, Trust and Security
Listed on 2026-03-15
-
IT/Tech
Cybersecurity, Information Security
About the Role
Veeam is the Data and AI Trust Company, specializing in helping organizations ensure their data and AI are fully understood, secured, and resilient to enable the acceleration of safe AI the market leader in both data resilience and data security posture management, Veeam is built for the convergence of identity, data, security, and AI risk. Headquartered in Seattle with offices in more than 30 countries, Veeam protects over 550,000 customers worldwide, who trust Veeam to keep their businesses running.
Join us as we go fearlessly forward together, growing, learning, and making a real impact for some of the world’s biggest brands.
We’re looking for a Risk Manager to build, own, and mature the security risk management program for our cloud-native Veeam Data Cloud (VDC) platform. Our SaaS products run on Microsoft Azure and related cloud services, delivering high-trust, secure data protection to customers across regulated and enterprise environments.
In this role, you will be responsible for turning raw security findings into a clear, prioritized, and business-relevant risk story. You will design and run the core processes for identifying, assessing, and tracking security risks, own the VDC Security risk register, and help leadership understand where to invest for the biggest risk reduction. You’ll partner directly with engineering, SRE, Global Information Security (GIS), and other security teams to ensure our SaaS environment remains secure, resilient, and aligned with Veeam’s risk appetite.
What You’ll Do- Build and operate a formal security risk management process for Veeam Data Cloud, including risk identification, assessment, prioritization, and tracking
- Own and maintain the VDC Security risk register, ensuring risks are clearly defined, consistently scored, and mapped to underlying evidence (e.g., Jira issues, penetration test reports, vulnerability scans, cloud configuration findings)
- Define and apply a consistent methodology for likelihood and impact, translating technical issues into business‑relevant risk ratings and treatment recommendations
- Aggregate and normalize findings from multiple sources (cloud security tools, penetration tests, audits, engineering reviews) into coherent risks and mitigation initiatives
- Partner with engineering, SRE, and security teams to convert high‑priority risks into actionable work items and projects, and track remediation progress over time
- Collaborate with GIS to align VDC’s risk taxonomy, thresholds, and reporting with enterprise security and compliance requirements
- Prepare and support quarterly executive risk reporting for the VP of VDC Engineering, the CTO, and the President of VDC, highlighting top risks, trends, and progress on mitigation
- Provide risk insights and data to support roadmap planning, investment decisions, and risk acceptance discussions
- Continuously evaluate and improve the effectiveness of risk processes, metrics, and tooling to ensure that VDC’s security investments deliver measurable risk reduction
- Cloud platforms and services:
Microsoft Azure (e.g., Entra , App Service, AKS, Storage, Networking, Key Vault, Defender, Monitor) - Identity and access management: cloud identity models, roles and permissions, privileged access, and secure configuration baselines
- Security & risk tooling: vulnerability management, cloud security posture management (CSPM/CNAPP), SIEM, logging and monitoring platforms, and workflow tools (e.g., Jira)
- Reporting & analytics: dashboards and reports that surface security posture, risk trends, and remediation progress to technical and executive stakeholders
- 5+ years of experience in security risk management, security governance, or a closely related role within cloud or SaaS environments.
- Hands-on experience building or operating risk registers and assessment processes (including scoring, prioritization, and risk treatment tracking), and working with security findings from tools such as vulnerability scanners, cloud security posture tools, and penetration tests.
- Strong understanding of cloud security concepts and risks, ideally including Microsoft Azure and modern…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).