- Home
- Jobs
- VDC - Engineering 1009422
- Senior Data Security & Privacy Engineer

Senior Data Security & Privacy Engineer at Veeam Software
Prague, CzechiaFull-timeVDC - Engineering 1009422Posted 26 days ago
Apply with PipelineAbout the Role
<div class="content-intro"><div class="elementToProof">
<p>Veeam is the Data and AI Trust Company, specializing in helping organizations ensure their data and AI are fully understood, secured, and resilient to enable the acceleration of safe AI at scale. As the market leader in both data resilience and data security posture management, Veeam is built for the convergence of identity, data, security, and AI risk. Headquartered in Seattle with offices in more than 30 countries, Veeam protects over 550,000 customers worldwide, who trust Veeam to keep their businesses running. Join us as we go fearlessly forward together, growing, learning, and making a real impact for some of the world’s biggest brands.</p>
</div></div><p><strong>About the Role</strong></p>
<p><span class="TextRun SCXW115243330 BCX8" lang="EN-US" data-contrast="auto"><span class="NormalTextRun SCXW115243330 BCX8">Veeam is looking for a </span></span><span class="TextRun SCXW115243330 BCX8" lang="EN-US" data-contrast="auto"><span class="NormalTextRun SCXW115243330 BCX8">Senior Data Security & Privacy Engineer</span></span><span class="TextRun SCXW115243330 BCX8" lang="EN-US" data-contrast="auto"><span class="NormalTextRun SCXW115243330 BCX8"> to own </span></span><span class="TextRun SCXW115243330 BCX8" lang="EN-US" data-contrast="auto"><span class="NormalTextRun SCXW115243330 BCX8">privacy-by-design</span></span><span class="TextRun SCXW115243330 BCX8" lang="EN-US" data-contrast="auto"><span class="NormalTextRun SCXW115243330 BCX8"> and </span></span><span class="TextRun SCXW115243330 BCX8" lang="EN-US" data-contrast="auto"><span class="NormalTextRun SCXW115243330 BCX8">data protection engineering</span></span><span class="TextRun SCXW115243330 BCX8" lang="EN-US" data-contrast="auto"><span class="NormalTextRun SCXW115243330 BCX8"> for the </span></span><span class="TextRun SCXW115243330 BCX8" lang="EN-US" data-contrast="auto"><span class="NormalTextRun SCXW115243330 BCX8"><a href="https://www.veeam.com/products/veeam-data-cloud.html">Veeam Data Cloud (VDC)</a> data plane</span></span><span class="TextRun SCXW115243330 BCX8" lang="EN-US" data-contrast="auto"><span class="NormalTextRun SCXW115243330 BCX8"> on </span></span><span class="TextRun SCXW115243330 BCX8" lang="EN-US" data-contrast="auto"><span class="NormalTextRun SCXW115243330 BCX8">Microsoft Azure</span></span><span class="TextRun SCXW115243330 BCX8" lang="EN-US" data-contrast="auto"><span class="NormalTextRun SCXW115243330 BCX8"> </span><span class="NormalTextRun SCXW115243330 BCX8">and </span></span><span class="TextRun SCXW115243330 BCX8" lang="EN-US" data-contrast="auto"><span class="NormalTextRun SCXW115243330 BCX8">AWS</span><span class="NormalTextRun SCXW115243330 BCX8">.</span></span><span class="TextRun SCXW115243330 BCX8" lang="EN-US" data-contrast="auto"><span class="NormalTextRun SCXW115243330 BCX8"> You will be the dedicated security and privacy engineering partner for VDC, responsible for how customer data is </span></span><span class="TextRun SCXW115243330 BCX8" lang="EN-US" data-contrast="auto"><span class="NormalTextRun SCXW115243330 BCX8">classified, ingested, encrypted, stored, processed, accessed, </span><span class="NormalTextRun SCXW115243330 BCX8">monitored</span><span class="NormalTextRun SCXW115243330 BCX8">, retained, and </span><span class="NormalTextRun SCXW115243330 BCX8">deleted</span></span><span class="TextRun SCXW115243330 BCX8" lang="EN-US" data-contrast="auto"><span class="NormalTextRun SCXW115243330 BCX8"> across VDC workloads.</span></span><span class="LineBreakBlob BlobObject DragDrop SCXW115243330 BCX8"><span class="SCXW115243330 BCX8"> </span><br class="SCXW115243330 BCX8"></span><span class="LineBreakBlob BlobObject DragDrop SCXW115243330 BCX8"><span class="SCXW115243330 BCX8"> </span><br class="SCXW115243330 BCX8"></span><span class="TextRun SCXW115243330 BCX8" lang="EN-US" data-contrast="auto"><span class="NormalTextRun SCXW115243330 BCX8">This is a </span></span><span class="TextRun SCXW115243330 BCX8" lang="EN-US" data-contrast="auto"><span class="NormalTextRun SCXW115243330 BCX8">product</span><span class="NormalTextRun SCXW115243330 BCX8"> security</span><span class="NormalTextRun SCXW115243330 BCX8"> and enablement</span></span><span class="TextRun SCXW115243330 BCX8" lang="EN-US" data-contrast="auto"><span class="NormalTextRun SCXW115243330 BCX8"> role: you will build </span></span><span class="TextRun SCXW115243330 BCX8" lang="EN-US" data-contrast="auto"><span class="NormalTextRun SCXW115243330 BCX8">shared security/privacy services</span></span><span class="TextRun SCXW115243330 BCX8" lang="EN-US" data-contrast="auto"><span class="NormalTextRun SCXW115243330 BCX8">, </span></span><span class="TextRun SCXW115243330 BCX8" lang="EN-US" data-contrast="auto"><span class="NormalTextRun SCXW115243330 BCX8">guardrails</span></span><span class="TextRun SCXW115243330 BCX8" lang="EN-US" data-contrast="auto"><span class="NormalTextRun SCXW115243330 BCX8">, and </span></span><span class="TextRun SCXW115243330 BCX8" lang="EN-US" data-contrast="auto"><span class="NormalTextRun SCXW115243330 BCX8">paved roads</span></span><span class="TextRun SCXW115243330 BCX8" lang="EN-US" data-contrast="auto"><span class="NormalTextRun SCXW115243330 BCX8"> that make secure, compliant defaults easy for product teams to adopt. You will ship code via </span></span><span class="TextRun SCXW115243330 BCX8" lang="EN-US" data-contrast="auto"><span class="NormalTextRun SCXW115243330 BCX8">pull requests</span></span><span class="TextRun SCXW115243330 BCX8" lang="EN-US" data-contrast="auto"><span class="NormalTextRun SCXW115243330 BCX8">, provide </span></span><span class="TextRun SCXW115243330 BCX8" lang="EN-US" data-contrast="auto"><span class="NormalTextRun SCXW115243330 BCX8">reference implementations</span></span><span class="TextRun SCXW115243330 BCX8" lang="EN-US" data-contrast="auto"><span class="NormalTextRun SCXW115243330 BCX8"> and </span></span><span class="TextRun SCXW115243330 BCX8" lang="EN-US" data-contrast="auto"><span class="NormalTextRun SCXW115243330 BCX8">self-service tooling</span></span><span class="TextRun SCXW115243330 BCX8" lang="EN-US" data-contrast="auto"><span class="NormalTextRun SCXW115243330 BCX8">, and measure adoption to drive consistent protections across the data plane.</span></span><span class="LineBreakBlob BlobObject DragDrop SCXW115243330 BCX8"><span class="SCXW115243330 BCX8"> </span><br class="SCXW115243330 BCX8"></span><span class="LineBreakBlob BlobObject DragDrop SCXW115243330 BCX8"><span class="SCXW115243330 BCX8"> </span><br class="SCXW115243330 BCX8"></span></p>
<p><strong>What You’ll Do</strong></p>
<ul>
<li><span data-contrast="auto">Build and maintain </span><span data-contrast="auto">shared platform capabilities</span><span data-contrast="auto"> that enable product teams to securely access Veeam Data Cloud and services (humans, services, agents) with secure-by-default patterns.</span></li>
<li><span data-contrast="auto">Set standard patterns for </span><span data-contrast="auto">authentication, authorization, and least-privilege access</span><span data-contrast="auto"> in a </span><span data-contrast="auto">multi-tenant SaaS</span><span data-contrast="auto"> environment, with explicit focus on </span><span data-contrast="auto">customer data access</span><span data-contrast="auto"> (humans, services, automation, break-glass).</span><span data-ccp-props="{"201341983":0,"335559739":0,"335559740":276}"> </span></li>
<li><span data-contrast="auto">Engineer and operationalize </span><span data-contrast="auto">privacy-by-design</span><span data-contrast="auto"> controls: data minimization, purpose limitation, and safe-by-default handling of personal/sensitive data (incl. data discovery and classification).</span></li>
<li><span data-contrast="auto">Build and maintain </span><span data-contrast="auto">data lifecycle</span><span data-contrast="auto"> mechanisms (retention policies, legal hold support where applicable, secure deletion, export/erasure workflows) that scale across tenants and regions.</span></li>
<li><span data-contrast="auto">Own the </span><span data-contrast="auto">encryption and key management strategy</span><span data-contrast="auto"> for customer data (in transit and at rest), including key rotation, access policies, and integrations with platform KMS (e.g., Azure Key Vault / managed HSM where used).</span></li>
<li><span data-contrast="auto">Define and build a shared </span><span data-contrast="auto">security + privacy control plane</span><span data-contrast="auto"> with </span><span data-contrast="auto">internal APIs/SDKs</span><span data-contrast="auto"> and </span><span data-contrast="auto">self-service workflows</span><span data-contrast="auto"> (tenant isolation, policy-as-code, consistent enforcement, abuse/rate limiting, and guardrails that reduce the chance of data exposure).</span></li>
<li><span data-contrast="auto">Define </span><span data-contrast="auto">secure logging, audit trails, and telemetry libraries</span><span data-contrast="auto"> (what we log, how we </span><span data-contrast="auto">avoid/ redact sensitive data</span><span data-contrast="auto">, how logs support detection, incident response, and privacy investigations).</span><span data-ccp-props="{"201341983":0,"335559739":0,"335559740":276}"> </span></li>
<li><span data-contrast="auto">Ship production-quality code (services, SDKs, templates, lint rules, CI/CD checks, infrastructure-as-code guardrails) that creates </span><span data-contrast="auto">paved roads</span><span data-contrast="auto"> and makes the secure path the default path for product teams.</span></li>
<li><span data-contrast="auto">Create </span><span data-contrast="auto">reference architectures</span><span data-contrast="auto">, reusable patterns, and developer documentation; run enablement (onboarding, office hours) and define </span><span data-contrast="auto">adoption metrics</span><span data-contrast="auto"> to drive consistent rollout across teams.</span><span data-ccp-props="{"201341983":0,"335559739":0,"335559740":276}"> </span></li>
<li><span data-contrast="auto">Build scalable </span><span data-contrast="auto">data-flow mapping</span><span data-contrast="auto"> and </span><span data-contrast="auto">threat modeling</span><span data-contrast="auto"> mechanisms (templates, tooling, review checklists) for features that touch customer data; translate findings into platform backlog items and reusable controls.</span><span data-ccp-props="{"201341983":0,"335559739":0,"335559740":276}"> </span></li>
<li><span data-contrast="auto">Partner with </span><span data-contrast="auto">Engineering, SRE, AI Security, Platform Security, Product Security, and Compliance/Privacy stakeholders</span><span data-contrast="auto"> to improve security and privacy baselines for our services.</span><span data-ccp-props="{"201341983":0,"335559740":276}"> </span></li>
<li><span data-contrast="auto">Turn repeat security issues (dependencies/SBOM, container/VM findings, secrets exposure, pentest items) into </span><span data-contrast="auto">automated fixes and guardrails</span><span data-contrast="auto"> (policies, pipelines, templates) that prevent regressions.</span></li>
<li><span data-contrast="auto">Help meet external security and privacy requirements (e.g., </span><span data-contrast="auto">SOC 2 / ISO / FedRAMP-style / IRAP</span><span data-contrast="auto">) by delivering </span><span data-contrast="auto">architecture and implementation changes</span><span data-contrast="auto"> that are measurable, auditable, and durable.</span></li>
</ul>
<p><strong>What You’ll Bring</strong></p>
<ul>
<li><span data-contrast="auto">Experience as a Security Architect / Data Security Engineer / Privacy Engineer in a cloud-native, multi-tenant SaaS, with clear ownership of </span><span data-contrast="auto">data protection and privacy engineering outcomes.</span></li>
<li><span data-contrast="auto">Strong knowledge of </span><span data-contrast="auto">Azure</span><span data-contrast="auto"> security and data services (identity/managed identities, Key Vault, storage, databases, networking), and the ability to apply the right controls to protect customer data at scale (AWS familiarity is a plus).</span></li>
<li><span data-contrast="auto">Strong software engineering background</span><span data-contrast="auto"> and proven ability to ship and maintain production systems: proficiency in one or more of </span><span data-contrast="auto">C#/.NET, Go, Java, Python, or TypeScript</span><span data-contrast="auto">; comfortable with pull requests, code reviews, testing, and CI/CD.</span></li>
<li><span data-contrast="auto">Hands-on experience engineering </span><span data-contrast="auto">encryption</span><span data-contrast="auto">, </span><span data-contrast="auto">key management</span><span data-contrast="auto">, </span><span data-contrast="auto">tenant isolation</span><span data-contrast="auto">, and </span><span data-contrast="auto">access control</span><span data-contrast="auto"> for large-scale data systems (including designing for incident response and forensics).</span><span data-ccp-props="{"201341983":0,"335559740":276}"> </span></li>
<li><span data-contrast="auto">Understanding of compliance and privacy expectations (SOC 2 / ISO 27001 / FedRAMP-style) and how they translate into </span><span data-contrast="auto">practical data handling controls</span><span data-contrast="auto"> (auditability, least privilege, retention/deletion, data residency as applicable)</span><span data-ccp-props="{"201341983":0,"335559739":0,"335559740":276}">.</span></li>
<li><span data-contrast="auto">Track record applying </span><span data-contrast="auto">secure SDLC</span><span data-contrast="auto"> practices (threat modeling, secure design reviews, dependency/vulnerability management) and turning requirements into code and automation.</span></li>
<li><span data-contrast="auto">Clear communication and ability to work with engineering/SRE/AppSec teams</span><span data-ccp-props="{}">.</span></li>
</ul>
<p><strong>Bonus Skills</strong></p>
<ul>
<li><span data-contrast="auto">Shared platform services for data protection (central KMS strategy, entitlement services, tokenization/masking).</span><span data-ccp-props="{}"> </span></li>
<li><span data-contrast="auto">Experience building </span><span data-contrast="auto">secure observability</span><span data-contrast="auto"> for data planes and forensics for anomalous access</span><span data-ccp-props="{}">.</span></li>
<li><span data-contrast="auto">Multicloud/hybrid data protection experience.</span><span data-ccp-props="{}"> </span></li>
<li><span data-contrast="auto">Security-focused development experience and relevant certifications (Azure security/architecture, cloud security, privacy/data protection).</span></li>
</ul>
<p><strong>What You’ll Get </strong></p>
<ul>
<li>25 vacation days, 4 sick days, 21 paid medical leave days, plus 4 extra global VeeaMe Days for self-care and 24 paid volunteer hours annually through Veeam Cares</li>
<li class="___ccc16d0 fje8fi8 f1ng9h0j f1bwykku f18jd3zf" data-uuid="edf32eb5-9fd0-4c7c-8978-e79d37007503">Premium private medical insurance for employees and dependents</li>
<li class="___ccc16d0 fje8fi8 f1ng9h0j f1bwykku f18jd3zf" data-uuid="9f5cda51-08d8-4760-971e-d9f747f57f7d">Daily meal vouchers for restaurants and groceries (180 CZK per working day)</li>
<li class="___ccc16d0 fje8fi8 f1ng9h0j f1bwykku f18jd3zf" data-uuid="378750df-d64d-4338-975e-c9b4064240d2">Flexible cafeteria platform with thousands of lifestyle benefit options</li>
<li class="___ccc16d0 fje8fi8 f1ng9h0j f1bwykku f18jd3zf" data-uuid="fab46f32-3a73-4a50-8eab-142b44eb8a92">Multisport Card for gym and wellness, with family add-on options</li>
<li class="___ccc16d0 fje8fi8 f1ng9h0j f1bwykku f18jd3zf" data-uuid="e8ec9bf3-2992-4ad0-8128-28f123163245">Annual public transport reimbursement up to a set limit</li>
<li class="___ccc16d0 fje8fi8 f1ng9h0j f1bwykku f18jd3zf" data-uuid="0e65f6ac-21e2-4496-a397-aae4bda50c32">Corporate mobile plan with optional family tariff</li>
<li class="___ccc16d0 fje8fi8 f1ng9h0j f1bwykku f18jd3zf" data-uuid="6e123908-7b82-4cf6-847f-5cfcbf2d13b2">Opportunities to learn and grow through on-demand libraries (LinkedIn Learning, O’Reilly), mentoring, workshops and learning events like our annual Global Day of Learning</li>
</ul>
<p> </p>
<p><span style="font-family: helvetica, arial, sans-serif;">#LI-DS1<br><span lang="EN-US">#Hybrid</span></span></p><div class="content-conclusion"><div data-pm-slice="1 1 ["ul",null,"li",{"style":null,"checked":null,"value":null,"displayValue":null,"backgroundColor":null,"color":null,"listStyleType":null}]" data-en-clipboard="true"><hr></div>
<div data-pm-slice="1 1 ["ul",null,"li",{"style":null,"checked":null,"value":null,"displayValue":null,"backgroundColor":null,"color":null,"listStyleType":null}]" data-en-clipboard="true"><span lang="EN-US" style="font-family: helvetica, arial, sans-serif;"><strong>Veeam Software is an equal opportunity employer</strong> and does not tolerate discrimination in any form on the basis of race, color, religion, gender, age, national origin, citizenship, disability, veteran status or any other classification protected by federal, state or local law. All your information will be kept confidential.</span></div>
<div data-pm-slice="1 1 ["ul",null,"li",{"style":null,"checked":null,"value":null,"displayValue":null,"backgroundColor":null,"color":null,"listStyleType":null}]" data-en-clipboard="true">
<p><span style="font-family: helvetica, arial, sans-serif;">Please note that any personal data collected from you during the recruitment process will be processed in accordance with our <a href="https://www.veeam.com/recruiting-privacy-notice.html">Recruiting Privacy Notice</a>. </span></p>
<p><span style="font-family: helvetica, arial, sans-serif;">The Privacy Notice sets out the basis on which the personal data collected from you, or that you provide to us, will be processed by us in connection with our recruitment processes. </span></p>
<p><span style="font-family: helvetica, arial, sans-serif;">By applying for this position, you consent to the processing of your personal data in accordance with our <a href="https://www.veeam.com/recruiting-privacy-notice.html">Recruiting Privacy Notice</a>.</span><br><br><span style="font-family: helvetica, arial, sans-serif;"><strong>By submitting your application, you acknowledge that the information provided in your job application and any supporting documents is complete and accurate to the best of your knowledge. Any misrepresentation, omission, or falsification of information may result in disqualification from consideration for employment or, if discovered after employment begins, termination of employment.</strong></span></p>
</div>
<p><a id="app"></a></p></div>
Related Roles
Senior Production Engineer
Veeam Software
Pune, IndiaPlatform Engineer III
Veeam Software
Bangalore, IndiaPlatform Engineer III
Veeam Software
Pune, IndiaSenior Production Engineer
Veeam Software
Remote, United StatesRemoteSecurity Tech Lead
Veeam Software
Warsaw, PolandSecurity Tech Lead
Veeam Software
Prague, Czechia