We are seeking an experienced CISO to lead the cybersecurity strategy, architecture and engineering agenda for a leading technology company operating in a cloud-native environment with high adoption of AI and emerging technologies.
The role will combine strategic security leadership with deep technical oversight, ensuring security is embedded across cloud infrastructure, applications, data, AI platforms and the software development lifecycle. The successful candidate will work closely with Technology, Engineering, Data and AI leadership to build a scalable, resilient and innovative security environment.
Key Responsibilities
Cybersecurity Strategy & Leadership
- Define and execute the company's technical cybersecurity strategy and roadmap aligned with business and technology objectives.
- Lead and develop high-performing teams across Security Engineering, Cloud Security, Application Security, Security Operations and Threat Management.
- Establish security architecture, engineering standards and secure-by-design principles across the technology environment.
- Act as the senior technical security advisor to the CTO, CIO and executive leadership.
Cloud & Infrastructure Security
- Lead security strategy across AWS, Azure and/or GCP cloud environments.
- Establish and enhance cloud security architecture, identity and access management, network security, workload protection and data security.
- Oversee cloud security posture management, vulnerability and exposure management, logging, monitoring and cyber resilience.
- Ensure security is embedded into cloud transformation and platform engineering initiatives.
AI & Emerging Technology Security
- Establish the organisation's AI Security strategy and framework covering Generative AI, AI agents, machine learning and AI-enabled applications.
- Identify and manage risks including prompt injection, model manipulation, data leakage, model abuse, AI supply-chain risk and insecure AI integrations.
- Embed security controls throughout the AI development and deployment lifecycle.
- Partner with Data Science and AI Engineering teams to implement secure-by-design AI architecture.
Security Engineering & DevSecOps
- Drive DevSecOps and security-by-design practices across software development and engineering teams.
- Integrate security into CI/CD pipelines, infrastructure-as-code and software development lifecycles.
- Oversee application security, API security, container and Kubernetes security, secrets management and software supply-chain security.
- Promote automation to continuously identify and remediate security risks.
Cyber Defence & Threat Management
- Provide technical leadership across Security Operations, Incident Response, Threat Intelligence and Threat Hunting.
- Ensure effective detection, investigation and response capabilities across cloud, endpoint, network and application environments.
- Lead response to major cybersecurity incidents and ensure effective post-incident remediation.
- Develop proactive capabilities to identify emerging threats and reduce the organisation's attack surface.
Governance, Risk & Resilience
- Establish appropriate security policies, standards, controls and security metrics.
- Oversee security risk assessments, penetration testing, vulnerability management and third-party security risk.
- Ensure compliance with relevant regulatory and industry requirements.
- Strengthen cyber resilience, disaster recovery and crisis management capabilities.
Requirements:
- 15+ years of cybersecurity experience, with significant experience leading technical security functions.
- Proven experience as a CISO, Deputy CISO, Head of Security Engineering, Head of Cloud Security or equivalent technical security leadership role.
- Strong technical expertise across cloud security, security architecture, application security, DevSecOps and cyber defence.
- Extensive experience securing AWS, Azure and/or GCP environments.
- Strong understanding of AI/ML security and Generative AI risks, with practical experience securing AI platforms or AI-enabled applications highly preferred.
- Experience with modern security technologies including CNAPP/CSPM, EDR, SIEM, IAM, WAF, API security, container/Kubernetes security and security automation.
- Strong understanding of security frameworks such as NIST CSF, CIS Controls, ISO 27001 and MITRE ATT&CK.
- Proven experience leading cybersecurity transformation in a high-growth or technology-driven environment.
- Strong executive communication and stakeholder management skills, with the ability to translate complex technical risks into business outcomes.
- Relevant certifications such as CISSP, CISM, CCSP or GIAC are advantageous.
Pam Lim
MORGAN MCKINLEY
EA Licence No: 11C5502
Registration No: R1106192