Chief Information Security Officer (CISO)

Metamindz UK

Location
Remote
Employment
Full-time
Level
Supervisor
Category
Security
Posted
Deadline

Description

Metamindz is a UK-based technical consultancy - CTO-led software development, fractional CTO services, and technical recruitment for startups and scaleups across the UK, US, and Middle East. Every project is run by real developers and CTOs rather than non-technical account managers, so engineers here work directly on real products and real technical problems.

We're looking for a Chief Information Security Officer (CISO) to own and lead our client's global information security strategy, organization, and execution. The CISO will report directly to the CTO and work closely with Engineering, Platform, SRE, IT, Product, Data, AI, Legal, Privacy and the wider executive team.

This is a highly technical and hands-on security leadership role. It's not primarily about policies, audits, or certifications. We're looking for someone who can understand how systems actually work, identify the risks that matter, and build the technology, processes, teams and culture needed to manage those risks while allowing the company to move quickly.

Who we're looking for:

10+ years of experience in security roles, ideally within global software product companies

5+ years of significant security leadership experience in a technology, SaaS, marketplace, fintech, HR-tech or similarly data-intensive environment

2+ years of experience as a CISO or VP of Security in a global software technology company

Strong technical security background with the ability to go deep into architecture, infrastructure, identity, applications, cloud and security incidents when required

Experience leading security across both product technology and corporate IT environments

Strong cloud security experience, particularly with AWS and/or GCP

Strong understanding of IAM, SSO, MFA, privileged access, device trust and Zero Trust principles

Deep product and application security experience, including threat modelling, secure SDLC, vulnerability management, security testing and supply-chain security

Experience building or operating mature security operations and incident response capabilities

Experience protecting environments containing significant volumes of personal or otherwise sensitive data

Strong understanding of SaaS, third-party and supply-chain security risks

Experience with ISO 27001, SOC 2, GDPR and enterprise customer security requirements

Familiarity with AI security and emerging risks around LLM-based applications and AI agents

Strong communication skills and the ability to translate technical security risks into clear business context

Pragmatic and risk-driven approach - security should enable the business rather than become an unnecessary blocker

Strong leadership and organizational skills, with the ability to decide what should be built internally, automated, or outsourced

What you'll work on:

Owning global information security strategy, roadmap and security organization

Defining measurable security objectives, KPIs, KRIs and risk-acceptance processes

Building security into the software development lifecycle alongside Engineering rather than creating external approval gates

Leading product and application security across threat modelling, architecture reviews, secure coding, SAST/DAST, dependency and supply-chain security, secrets management, vulnerability management, penetration testing and bug bounty programs

Owning the security architecture of cloud infrastructure, including the ongoing migration from AWS to GCP

Working across IAM, privileged access, network security, containers, infrastructure-as-code, encryption, logging, detection, data security and cloud security posture management

Building and improving security operations, detection engineering, SIEM, incident response, investigations and security incident playbooks

Leading security across the corporate technology environment, including identity, SSO/MFA, endpoint security, SaaS and device trust

Moving the organization towards a practical Zero Trust model

Building a scalable third-party and supply-chain security program based on actual exposure and business impact

Establishing security controls for AI-powered products and internal AI usage, including LLM access, AI agents, prompt injection, data exfiltration, model/provider risk, logging and shadow AI

Working with Legal and Privacy on GDPR, EU AI Act and other regulatory requirements while maintaining ownership of the underlying technical security controls

Maintaining and evolving security programs such as ISO 27001 and SOC 2 Type II

Providing the CTO and executive team with a clear and measurable view of the company's security posture and material risks

Nice to have:

Experience in HR-tech, workforce technology, marketplace, fintech or another data-intensive technology environment

Experience leading a major cloud migration or transformation, particularly AWS to GCP

What we offer:

A global CISO role with direct reporting to the CTO and significant ownership of the company's security strategy

The opportunity to shape security across product, engineering, cloud infrastructure, corporate IT, data and AI

A genuinely technical leadership position where you can engage directly with architecture, engineering and security problems

The opportunity to lead security during a major cloud transformation from AWS to GCP

The chance to build and scale a security organization rather than simply maintain an established security program

Apply at the source

This role was published by Metamindz UK and listed via Djinni. Applications are handled there, not on this site.

View & apply on djinni.co ↗