Key Responsibilities
1. Leadership & Strategic Direction
- Design and execute a modern cybersecurity strategy aligned with both immediate needs and long-term business objectives.
- Build the security function from the ground up, including setting vision, defining org structure, hiring, and onboarding.
- Operate with a startup mindsetprioritizing agility, pragmatism, and fast iteration over bureaucracy.
2. Team Building & Talent Development
- Recruit, mentor, and retain top-tier cybersecurity professionals across diverse disciplines.
- Foster a growth culture centered around continuous learning, ownership, and career development.
- Scale the team sustainably while maintaining speed and accountability.
3. Security Operations & Incident Response
- Establish and lead end-to-end threat detection, incident response, and vulnerability management processes.
- Implement lightweight but effective operational playbooks tailored to a lean, high-impact environment.
- Collaborate closely with engineering and infrastructure teams for rapid issue resolution and improvement.
4. Security Engineering & Architecture
- Design and deploy a modern, cloud-native security architecture across infrastructure and applications.
- Introduce automation and tooling to streamline detection, response, and risk management.
- Make build-vs-buy decisions that reflect startup constraints without compromising security posture.
5. Governance, Risk & Compliance (GRC)
- Build foundational policies, controls, and compliance programs that can scale with the business.
- Ensure adherence to evolving regulatory and industry requirements (e.g., ISO 27001, GDPR, SOC 2).
- Work closely with legal and audit teams to prepare for external assessments and certifications.
Qualifications & Experience
- Bachelor's or Master's degree in Computer Science, Cybersecurity, or a related technical field.
- 10+ years in cybersecurity, with 5+ years in leadership rolespreferably in high-growth or startup environments.
- Proven success in building security teams from the ground upfrom hiring to culture-setting.
- Deep hands-on knowledge across security domains: operations, engineering, architecture, and GRC.
- Experience implementing security programs in agile, DevOps, or product-led tech organizations.
- Strong communication skills and the ability to influence technical and non-technical stakeholders.
- Familiarity with common security frameworks and certifications (e.g., ISO 27001, NIST, CISSP, CISM).