Head of Information Security

Valarian's Zero-trust
UK
18 days ago
Apply on www.apply4u.co.uk
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Working hours
Regular working hours

Tech stack

Software System Penetration Testing Encodings Cyber Security Information Security Management Zero Trust Network Access Software Vulnerability Management Devsecops

Job description

Job Description Take full ownership of Valarian’s internal security posture, enterprise risk framework, and product compliance Embed security into the engineering culture and maintain customer trust Design and execute Valarian’s Zero-Trust security roadmap, policies, risk assessments, and executive reporting for leadership and the board Own end-to-end audit readiness for SOC 2 Type II, ISO 27001, Cyber Essentials Plus, and NIST 800-53 Embed DevSecOps and secure SDLC practices into CI/CD pipelines Oversee penetration testing, red teaming, and threat modeling across core infrastructure Serve as the technical security authority in customer procurement reviews, vendor risk assessments, and defense customer evaluations Build and manage internal incident response capabilities, continuous monitoring, vulnerability management, and employee security awareness programs Requirements Ambitious, technical security leader Experience suitable for a Senior Security Manager, Architect, or Director

Requirements

stepping into a first CISO-level leadership role Experience with Zero-Trust security roadmaps, policies, and risk assessments Experience with SOC 2 Type II, ISO 27001, Cyber Essentials Plus, and NIST 800-53 Experience embedding DevSecOps and secure SDLC practices into CI/CD pipelines Experience overseeing penetration testing, red teaming, and threat modeling Experience with customer procurement reviews, vendor risk assessments (DDQs), and defense customer evaluations Experience building and managing incident response, continuous monitoring, vulnerability management, and employee security awareness programs Core Competencies Demonstrates expertise in Zero-Trust security frameworks, compliance standards such as SOC 2 Type II and ISO 27001, and embedding security practices within engineering cultures. Proven ability to lead incident response initiatives, manage risk assessments, and oversee vulnerability management programs.Highest-signal resume keywords Zero-Trust Security Roadmap SOC 2 Type II Compliance ISO 27001 Certification DevSecOps Practices Incident Response Management Hard Skills Risk Assessment Penetration Testing Threat Modeling Vulnerability Management Continuous Monitoring Soft Skills Leadership Ambition Technical Authority Certifications & Qualifications Cyber Essentials Plus NIST 800-53 Industry Keywords Enterprise Risk Framework Security Awareness Programs Vendor Risk Assessments Customer Procurement Reviews Tools & Technologies CI/CD Pipelines Security Posture Management #J-18808-Ljbffr

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.apply4u.co.uk
Prepare application

Good distractions

Loading talks and stories from around this role…