> Markdown version of [/jobs/ext/1286578-chief-information-security-officer-ciso](https://www.wearedevelopers.com/jobs/ext/1286578-chief-information-security-officer-ciso). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Chief Information Security Officer (CISO) - **Company:** Brahma - **Location:** UK - **Experience:** Expert - **Salary:** £114,467.0 - **Contract:** Permanent contract - **Skills:** Training Data, Application Programming Interfaces (APIs), Artificial Intelligence, Amazon Web Services, Microsoft Azure, Software as a Service, Cyber Security, Continuous Delivery, Continuous Integration, CoreMedia CMS, Data Centers, Digital Signature, Identity and Access Management, Key Management, Machine Learning, Red Team (Cyber Security), Zero Trust Network Access, Security Software, Google Cloud, Software Security, Media Technology, Multi-Cloud, Generative AI, Data Lineage, Deployment Automation, Hardware Infrastructure, Static Application Security Testing, Dynamic Application Security Testing - **Published:** July 16, 2026 - **Apply:** https://www.adzuna.co.uk/jobs/details/5802868205 ## About the Role Professional Background * Minimum of 12 years of progressive experience in information security, including at least 4 years as a CISO or Head of Security within a fast-paced SaaS, AI-native, or advanced media technology organization. * Demonstrated experience building, scaling, and leading global security teams across regions and time zones, spanning security engineering, operations, and compliance functions. * Proven track record of building and executing automated security programs that support rapid code release cycles without introducing organizational friction. * Demonstrated experience achieving and maintaining SOC 2 Type 2, ISO/IEC 27001, and TPN certifications; experience leading an ISO/IEC 42001 implementation is a strong plus. * Proven experience governing security across hybrid, multi-cloud environments (AWS and GCP experience required; Azure and physical datacenter experience is beneficial). * Experience presenting security and risk posture to boards, investors, and enterprise customers. Technical Skills and Knowledge * Deep expertise in identity governance, zero-trust architectures, IAM/PAM frameworks, and enterprise key management. * Strong understanding of media security technologies, including DRM, forensic watermarking, AES encryption, and digital signatures. * Strategic understanding of machine learning development pipelines, container orchestration, model registries, C2PA specifications, adversarial ML threats, and AI-driven security automation tools. * Comprehensive knowledge of global data privacy and security frameworks, including HIPAA, GDPR, India's DPDP Act, and MPA Content Security Best Practices. ## Description This executive position works closely with the Chief Technology Officer (CTO), Chief Executive Officer (CEO), and the wider executive leadership team. Overseeing our global security posture across engineering, product, and multi-cloud environments, the CISO will build automated, developer-enabling security architectures in place of traditional gate-heavy enterprise controls. In this role, you will define our MLSecOps strategy, govern zero-trust identity frameworks, guide global privacy compliance (including HIPAA, GDPR, and India's DPDP Act), and establish the enterprise trust certifications that power our commercial growth. This is a hands-on security leadership role first. Brahma AI operates some of the most sensitive technology in the industry: highly realistic, photorealistic digital replicas of real people. Protecting our models, our data, our infrastructure, and the likenesses entrusted to us is the job, and you will build and lead the global security organization to execute on it. Trust, governance, and certification programs are how that protection becomes a commercial asset. Core Strategic Objectives Drive Security as a Commercial Enabler: Implement automated compliance and governance pipelines that accelerate product velocity and lower time-to-market for digital human solutions while upholding rigorous security standards.Govern MLSecOps Strategy: Architect and oversee the secure machine learning lifecycle from ingestion to serving, defining custom control frameworks for model registries, training data validation, and automated deployment pipelines. Protect Digital Identities: Own the security of Brahma AI's digital human technologies, covering likeness protection, misuse prevention, consent management, and content provenance. Build Enterprise Trust: Lead Brahma AI's trust and compliance posture across ISO/IEC 42001, SOC 2 Type 2, C2PA, and TPN, ensuring alignment with global regulatory frameworks including HIPAA, GDPR, and India's DPDP Act. Support customer security reviews and investor due diligence. Harden Multi-Cloud & Enterprise Environments: Maintain continuous posture monitoring and zero- trust perimeters across our multi-cloud footprint (AWS, GCP, and Azure) and physical facilities. Define Identity & Access Architecture: Enforce low-friction Identity and Access Management (IAM), Privileged Access Management (PAM), and automated secrets management across continuous delivery pipelines. Technical and Operational Responsibilities 1. Generative AI Security, MLSecOps, and Content Protection * Oversee the design and maturation of the MLSecOps architecture, establishing standards for automated gate controls, model registry signing, versioned data lineage, and pre-deployment adversarial testing. * Establish defenses against adversarial AI threats including prompt injection, model extraction, data and model poisoning, and misuse of generative APIs, validated through continuous AI red team exercises. * Drive the integration of content authenticity standards (C2PA) and media protection mechanisms, including forensic watermarking, DRM, and encryption, directly into core media pipelines. * Lead security and governance of digital human and synthetic media technologies: likeness protection, consent-driven identity registries for ATMAN digital likenesses (in partnership with Product and Legal), and authenticity controls. * Direct the evaluation and adoption of contemporary, AI-powered security tooling to continuously test, detect, monitor, and recover from software vulnerabilities.2. Multi-Cloud, Infrastructure, and Application Security. * Establish continuous, automated security posture management across GCP, AWS, and Azure, prioritizing engineering self-remediation. * Define enterprise access governance, IAM policy, and zero-trust perimeters to prevent unauthorized access and ensure strict multi-tenant isolation. * Ensure automated, low-latency security scanning (SAST, DAST, container checks) is seamlessly integrated into CI/CD workflows without creating development bottlenecks. * Provide security policy oversight and governance for physical facilities, on-premise datacenters, and GPU infrastructure to maintain compliance with TPN and ISO standards. 3. AI Governance, Risk Delegation, and Compliance * Lead the strategy to achieve and maintain primary certifications, specifically ISO/IEC 42001 and SOC 2 Type 2, while maintaining secondary certifications (TPN Gold Shield, ISO 27001). * In partnership with Legal and Product teams, guide organizational compliance for regulated client verticals, ensuring adherence to HIPAA, GDPR, India's DPDP Act, and emerging global AI frameworks. * Operationalize a delegated risk management framework that enables business units to evaluate and accept operational risks within clear, automated governance guardrails. * Lead security due diligence for mergers, acquisitions, and strategic partnerships, and support investor and customer due diligence processes. 4. Threat Operations, IncidentResponse, and Resilience * Oversee enterprise Incident Response (IR) playbooks covering data breaches, unauthorized access, identity spoofing, and synthetic media misuse. * Sponsor threat modelling and red team exercises targeting cloud perimeters, generative APIs, IAM, and biometric validation systems. * Maintain threat intelligence capabilities to proactively guard against external attacks and unauthorized misuse of Brahma AI models or digital identities. * Own business continuity and crisis management planning across cloud, on-premise, and production environments. 5. Executive and Board Governance * Present cybersecurity and AI risk posture to the Board, executive leadership, investors, and enterprise customers. * Maintain enterprise cyber and AI risk registers, risk dashboards, and security scorecards that give leadership a clear, quantified view of posture and progress. ## Related Videos - [The Open-source Java SDK for Multi-Cloud Development - Sandeep Pal](https://www.wearedevelopers.com/videos/2113-the-open-source-java-sdk-for-multi-cloud-development-sandeep-pal) - [The Cloud is Calling: Answer with In-Demand Skills](https://www.wearedevelopers.com/videos/945-the-cloud-is-calling-answer-with-in-demand-skills) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Enjoying SQL data pipelines with dbt](https://www.wearedevelopers.com/videos/823-enjoying-sql-data-pipelines-with-dbt) - [A Data Mesh needs Open Metadata](https://www.wearedevelopers.com/videos/505-a-data-mesh-needs-open-metadata) - [Leverage Cloud Computing Benefits with Serverless Multi-Cloud ML ](https://www.wearedevelopers.com/videos/78-leverage-cloud-computing-benefits-with-serverless-multi-cloud-ml) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence](https://www.wearedevelopers.com/magazine/736-best-us-ai-conferences-for-ctos-in-2026-build-vs-buy-vendor-evaluation-and-peer-intelligence) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology)