- Take full ownership of Valarian's internal security posture, enterprise risk framework, and product compliance
- Embed security into the engineering culture and maintain customer trust
- Design and execute Valarian's Zero-Trust security roadmap, policies, risk assessments, and executive reporting for leadership and the board
- Own end-to-end audit readiness for SOC 2 Type II, ISO 27001, Cyber Essentials Plus, and NIST 800-53
- Embed DevSecOps and secure SDLC practices into CI/CD pipelines
- Oversee penetration testing, red teaming, and threat modeling across core infrastructure
- Serve as the technical security authority in customer procurement reviews, vendor risk assessments, and defense customer evaluations
- Build and manage internal incident response capabilities, continuous monitoring, vulnerability management, and employee security awareness programs
Requirements
- Ambitious, technical security leader
- Experience suitable for a Senior Security Manager, Architect, or Director stepping into a first CISO-level leadership role
- Experience with Zero-Trust security roadmaps, policies, and risk assessments
- Experience with SOC 2 Type II, ISO 27001, Cyber Essentials Plus, and NIST 800-53
- Experience embedding DevSecOps and secure SDLC practices into CI/CD pipelines
- Experience overseeing penetration testing, red teaming, and threat modeling
- Experience with customer procurement reviews, vendor risk assessments (DDQs), and defense customer evaluations
- Experience building and managing incident response, continuous monitoring, vulnerability management, and employee security awareness programs
Core Competencies
Demonstrates expertise in Zero-Trust security frameworks, compliance standards such as SOC 2 Type II and ISO 27001, and embedding security practices within engineering cultures. Proven ability to lead incident response initiatives, manage risk assessments, and oversee vulnerability management programs.
Highest-signal resume keywords
- Zero-Trust Security Roadmap
- SOC 2 Type II Compliance
- ISO 27001 Certification
- DevSecOps Practices
- Incident Response Management
Hard Skills
- Risk Assessment
- Penetration Testing
- Threat Modeling
- Vulnerability Management
- Continuous Monitoring
Soft Skills
- Leadership
- Ambition
- Technical Authority
Certifications & Qualifications
- Cyber Essentials Plus
- NIST 800-53
Industry Keywords
- Enterprise Risk Framework
- Security Awareness Programs
- Vendor Risk Assessments
- Customer Procurement Reviews
Tools & Technologies
- CI/CD Pipelines
- Security Posture Management
Head of Information Security employer: Jobtailor
As a Client Services Coordinator at our dynamic company, you will thrive in a supportive work culture that prioritises employee growth and development. We offer comprehensive training, opportunities for advancement, and a collaborative environment where your contributions are valued. Located in a vibrant area, our team enjoys a healthy work-life balance and the chance to engage with diverse clients, making every day rewarding and meaningful.