HQ - CISO - EMEA Remote
Descripción del puesto
About the Role
Job&Talent is looking for a Chief Information Security Officer (CISO) to own and lead the company's global information security strategy, organization, and execution.
Reporting directly to the CTO, the CISO will be responsible for protecting Job&Talent's technology, infrastructure, products, corporate environment, and data while enabling the company to move quickly and safely.
Job&Talent operates a large-scale technology product supporting critical workforce processes, including hiring, worker management, clocking, payroll-related workflows, and increasingly AI-powered capabilities. This creates a broad security surface spanning cloud infrastructure, SaaS, endpoints, identity, product security, sensitive personal data, AI systems, third-party vendors, and multiple regulatory environments.
The CISO will therefore need to combine deep technical security expertise, strong operational execution, risk management, GRC understanding, and executive leadership.
We are looking for someone who can understand how systems actually work, identify the risks that matter, prioritize them pragmatically, and build the technology, processes, teams, and culture required to address them.
What you'll own
Strategy, Leadership & Executive Oversight
- Own and continuously evolve Job&Talent's global information security strategy and roadmap, ensuring security investment is aligned with the company's actual risk profile and business priorities.
- Translate technical security risks into clear business risks and provide the CTO and executive team with an accurate view of the company's security posture.
- Establish measurable security objectives, KPIs, KRIs and risk-acceptance processes.
- Build a security organization capable of supporting a fast-moving global technology company without creating unnecessary friction for Engineering or the business.
Product, Application & Cloud Security
- Own the security lifecycle across Job&Talent's products and engineering organization, including threat modelling, architecture reviews, secure development, application and supply-chain security, vulnerability management and security testing.
- Own security architecture across cloud infrastructure and platform environments, ensuring security is embedded into architecture and technology decisions from the beginning.
- Partner closely with Engineering, Platform and SRE to integrate security into development and infrastructure processes.
- Provide appropriate security governance for AI-powered products, agents, and LLM integrations.
Identity, Corporate & Data Security
- Own security across Job&Talent's corporate technology environment, including identity and access management, privileged access, endpoint and SaaS security, and corporate network security.
- Drive the organization toward a Zero Trust model where access decisions consider identity, device posture, risk, and context.
- Own the technical controls required to protect sensitive data throughout its lifecycle, including data access, encryption, monitoring and data-loss prevention.
- Partner closely with Legal, Privacy and the DPO on applicable privacy requirements while maintaining a clear distinction between privacy governance and technical security ownership.
Security Operations & Incident Response
- Build and continuously improve Job&Talent's ability to detect, investigate, contain and recover from security incidents.
- Own security monitoring, detection engineering, incident response and threat intelligence capabilities.
- Ensure significant security incidents are handled with strong operational discipline and effective coordination across technical, business and executive stakeholders.
- Drive continuous improvement through incident reviews, remediation and lessons learned.
Governance, Risk & Third-Party Security
- Maintain and evolve Job&Talent's security management framework, risk management and compliance programs, including ISO 27001, SOC 2 Type II, GDPR and applicable customer and regulatory security requirements.
- Maintain clear ownership, remediation and risk acceptance while automating compliance and control monitoring wherever practical.
- Own security risk management across Job&Talent's technology and vendor ecosystem, ensuring third-party risk is assessed based on actual exposure and impact.
AI Security & Governance
- Establish the technical security framework for AI across Job&Talent products and internal use.
- Address emerging risks related to data access, AI agents, authentication and authorization, data exfiltration, model and provider risk, and shadow AI.
- Partner with Legal and Privacy on regulatory requirements, including the EU AI Act, while maintaining ownership of the required technical security controls.
Security Culture & Organization
- Build and develop a strong security organization with clear ownership and accountability.
- Build a strong security culture across Job&Talent, embedding security into how Engineering, Product, IT, and business teams make decisions.
- Develop targeted security education and effective security champion programs where they provide value.
Experience Required:
- 10+ years of experience in information security, with significant experience within global software technology product companies.
- 5+ years in significant security leadership roles within technology, SaaS, marketplace, fintech, HR-tech or similarly data-intensive product environments.
- 2+ years as a CISO, VP Security or equivalent senior security leader within a global SaaS or software technology product company.
- Experience leading security across both product technology and corporate IT environments.
- Strong track record across Product and Application Security, cloud security and modern security architecture.
- Demonstrated experience building or operating mature Security Operations and Incident Response capabilities.
- Deep understanding of modern identity architecture, IAM, SSO, device trust and Zero Trust principles.
- Experience protecting significant volumes of personal or otherwise sensitive data and managing SaaS and third-party security risks.
- Experience with ISO 27001, SOC 2, GDPR and enterprise customer security requirements.
- Familiarity with AI security and emerging risks associated with LLM-based applications and AI agents.
- Experience partnering with Engineering, Platform, SRE, IT, Legal and Privacy teams, as well as executive leadership.
Skills & Competencies:
- Technical Credibility: Ability to engage deeply with architecture, infrastructure, identity, applications, cloud security and incidents, independently assessing technical risks.
- Risk-Driven Thinking: Ability to distinguish theoretical vulnerabilities and compliance gaps from risks that could materially impact the business, and prioritize security efforts accordingly.
- Pragmatic Approach: Ability to balance security requirements with business priorities, enabling Engineering and the wider organization to operate securely without unnecessary friction.
- Data-Driven Leadership: Ability to quantify security posture, establish meaningful metrics and demonstrate whether risk is increasing or decreasing.
- Hands-On Mindset: Ability to move between executive-level discussions and detailed technical investigations when required.
- Engineering Collaboration: Ability to establish strong partnerships with Engineering teams, collaborate on technical decisions and integrate security into engineering practices.
- Incident Leadership: Ability to make clear decisions under uncertainty and coordinate technical, business, privacy and legal stakeholders during security incidents.
- Organizational Leadership: Ability to build and develop effective security capabilities, determining what should be owned internally, automated, outsourced or supported by specialist expertise.
Habilidades mencionadas
Postúlate a este puesto
Use the application link supplied with this listing to apply to jobandtalent. Check the destination before entering personal information.
