Head of Cybersecurity
2 нед. назад
BulgariaCzechiaEuropeHead
siemxdredrsoarthreat intelligenceincident responsevulnerability management
Lead and develop global cybersecurity capability, strengthen security posture, and shape cybersecurity transformation roadmap.
Условия
- This is an opportunity to shape cybersecurity strategy and execution at a global technology company at a time when the security landscape is changing rapidly.
- You will have the opportunity to:
- Shape and build a global cybersecurity capability.
- Influence significant investments in security technology and people.
- Work at the intersection of cybersecurity, cloud and AI .
- Partner directly with executive leadership.
- Work with international engineering, AI and delivery teams.
- Help define how a global technology company approaches the security of emerging AI and agentic technologies.
Другое
- is a global technology consulting company helping organizations transform through technology, data, cloud, AI and software engineering.
- We are looking for a Head of Cybersecurity to lead and further develop 's global cybersecurity capability. Reporting directly to the Chief Information Officer (CIO) , you will play a key role in strengthening our security posture, shaping our cybersecurity transformation roadmap and enabling secure growth across the business.
- This is a highly hands-on leadership role . You will combine strategic thinking with operational execution, working closely with technical teams, leadership, Sales and Delivery, while also being comfortable getting into the details when required.
- The role is particularly relevant to the rapidly evolving security landscape around AI, LLMs and agentic AI , and we are looking for a leader who can help understand and address these emerging risks.
-
- Define and operate 's cybersecurity capability across prevention, detection, response and recovery.
- Own global incident response, cyber crisis coordination, tabletop exercises, post-incident reviews and remediation tracking.
- Own the security tooling strategy across SIEM, XDR, EDR, SOAR and threat intelligence.
- Drive detection engineering, alert quality, automation and security dashboards.
- Lead vulnerability and continuous exposure management across infrastructure, cloud, endpoints, applications and external-facing assets.
- Drive continuous improvement of 's overall security posture.
- Own identity security and drive Zero Trust adoption, including PAM, conditional access and governance of service accounts and machine identities.
- Own cloud security posture and workload protection across multi-cloud environments, including containers, Kubernetes and infrastructure-as-code.
- Partner with Infrastructure, Applications and AI/Data teams to embed secure-by-design patterns and DevSecOps practices.
- Define and continuously improve minimum security baselines for endpoints, identities, cloud, SaaS, networks, code repositories and AI platforms.
- Evaluate and implement security technologies and controls that effectively address identified risks.
- Own security risk oversight for AI and LLM-based systems, including model and data security, training/fine-tuning data integrity, adversarial robustness, model theft/extraction, prompt injection and misuse.
- Define and enforce security guardrails for agentic AI, including least-privilege access, human-in-the-loop checkpoints, action logging, audit trails and containment controls.
- Assess risks related to third-party foundation models, plugins, MCP servers and agent frameworks.
- Maintain an inventory of AI models and agents in use across the business and assess their security exposure.
- Partner with AI/ML Engineering and platform teams to enable secure adoption of AI-assisted and agentic coding, delivery and client-facing tools.
- Help continuously adapt its security approach to the rapidly evolving AI threat landscape.
- Own the cybersecurity contribution to business continuity planning and disaster recovery.
- Ensure critical systems and services can be restored within agreed RTO/RPO objectives.
- Drive ransomware resilience through immutable and segmented backups, isolated recovery environments and tested recovery playbooks.
- Lead regular cyber crisis, business continuity and recovery exercises.
- Own protection of 's and clients' intellectual property, source code, proprietary methodologies, AI models, training data and confidential client deliverables.
- Drive DLP, access controls, code repository security and exfiltration monitoring.
- Partner with HR and Legal to manage insider risk throughout the employee and contractor lifecycle.
- Own and continuously evolve 's global cybersecurity transformation roadmap.
- Translate identified risks into concrete technology, process and programme initiatives.
- Lead cybersecurity programmes from definition through implementation, ensuring clear milestones, ownership and measurable outcomes.
- Build business cases and contribute to investment decisions around cybersecurity tooling, capabilities and team growth.
- Establish practical, measurable and enforceable security controls across the organisation.
- Build and develop a global cybersecurity team as the function grows.
- Work effectively with distributed teams and external security partners.
- Cybersecurity at is also a business and revenue enabler .
- You will work closely with Sales, Delivery, Solutions and technical teams to:
- Support customer security questionnaires, audits and assurance activities.
- Anticipate customer security expectations and translate them into practical security capabilities.
- Contribute to strategic sales opportunities and client engagements.
- Help position as a trusted technology and security partner.
- Balance security requirements with business and customer needs, finding pragmatic solutions rather than simply applying rigid controls.
- Provide executive and Board-level reporting on cybersecurity posture, threat trends, incidents, remediation status and maturity.
- Communicate complex cybersecurity risks in clear business terms.
- Maintain a risk-based cybersecurity transformation roadmap with quarterly milestones.
- Manage third-party, vendor and software/AI supply chain cyber risk.
- Own the execution of the security awareness programme, including phishing simulations, role-based training and insider risk culture.
- Support customer security assurance activities, audits, certifications and M&A cyber due diligence.
- Work with IT GRC & Assurance and Legal to ensure operational controls meet relevant regulatory obligations, including GDPR, NIS2, DORA and client contractual requirements.
-
- Senior cybersecurity leader with deep operational security, cloud, identity and incident response experience, typically 12+ years in security with 5+ years in a leadership role .
- Track record running or transforming a SOC/detection function and leading enterprise-scale incident response and crisis management.
- Practical experience securing multi-cloud and modern application environments, plus AI models and agentic AI systems — model risk, prompt-level attacks and permissioning/containment of autonomous agents — given 's AI-led business.
- Experience owning business continuity/disaster recovery planning and data loss prevention or IP protection programmes in a technology or professional services setting.
- Able to balance pragmatic delivery with risk reduction and customer assurance.
- Credible with executives, auditors, customers and technical teams; comfortable presenting cyber risk in business terms to the Board.
- Experience leading distributed, multicultural teams across regions.
- Indicative certifications include:
- CISSP