GUS Germany GmbH operates Europe's largest dynamic network of higher education institutions, with over 18,000 students enrolled across campuses in Berlin, Hamburg, Iserlohn, Potsdam, Amsterdam, Athens, Barcelona, Paris, and Dubai. The network spans business, technology, data science, engineering, sports, and fine arts disciplines - offering a broad surface area of institutional data, from student records and research IP to cross-border operational systems. For anyone building defenses in education-tech, that's a complex threat landscape: federated identity across multiple jurisdictions, third-party brand partnerships funneling practical-experience data, and a Research and Academic Support Center (RASC) whose scholarly outputs and interdisciplinary datasets carry their own risk profiles.
The operational model leans on collaboration with world-leading brands for student insights and practical experiences, which means supply-chain trust and data-sharing agreements are baked into how the organization functions - not bolted on after the fact. Campuses spanning the EU, the UK's data-proximity neighbors, and the UAE introduce multi-regulatory compliance pressure: GDPR baseline, plus whatever each jurisdiction layers on top. The attack surface isn't theoretical; it's distributed across physical campuses, digital learning platforms, and partner integrations running in parallel.
Security teams here aren't guarding a single perimeter - they're supporting a federated education network where each node has its own culture, faculty tooling, and student-facing systems. The RASC adds a research dimension: think data classification, access controls on pre-publication work, and the kind of intellectual property that nation-state actors actually care about. If you're looking at roles that demand cross-jurisdictional fluency, education-sector domain knowledge, and the ability to reason about risk across a heterogeneous estate, this is a concrete place to do that work.





