Security Engineer
Metamindz is a UK-based technical consultancy - CTO-led software development, fractional CTO services, and technical recruitment for startups and scaleups across the UK, US, and Middle East. Every project is run by real developers and CTOs rather than non-technical account managers, so engineers here work directly on real products and real technical problems.
We're looking for a Chief Information Security Officer (CISO) to own and lead our client's global information security strategy, organization, and execution. The CISO will report directly to the CTO and work closely with Engineering, Platform, SRE, IT, Product, Data, AI, Legal, Privacy and the wider executive team.
This is a highly technical and hands-on security leadership role. It's not primarily about policies, audits, or certifications. We're looking for someone who can understand how systems actually work, identify the risks that matter, and build the technology, processes, teams and culture needed to manage those risks while allowing the company to move quickly.
Who we're looking for:
- 10+ years of experience in security roles, ideally within global software product companies
- 5+ years of significant security leadership experience in a technology, SaaS, marketplace, fintech, HR-tech or similarly data-intensive environment
- 2+ years of experience as a CISO or VP of Security in a global software technology company
- Strong technical security background with the ability to go deep into architecture, infrastructure, identity, applications, cloud and security incidents when required
- Experience leading security across both product technology and corporate IT environments
- Strong cloud security experience, particularly with AWS and/or GCP
- Strong understanding of IAM, SSO, MFA, privileged access, device trust and Zero Trust principles
- Deep product and application security experience, including threat modelling, secure SDLC, vulnerability management, security testing and supply-chain security
- Experience building or operating mature security operations and incident response capabilities
- Experience protecting environments containing significant volumes of personal or otherwise sensitive data
- Strong understanding of SaaS, third-party and supply-chain security risks
- Experience with ISO 27001, SOC 2, GDPR and enterprise customer security requirements
- Familiarity with AI security and emerging risks around LLM-based applications and AI agents
- Strong communication skills and the ability to translate technical security risks into clear business context
- Pragmatic and risk-driven approach - security should enable the business rather than become an unnecessary blocker
- Strong leadership and organizational skills, with the ability to decide what should be built internally, automated, or outsourced
What you'll work on:
- Owning global information security strategy, roadmap and security organization
- Defining measurable security objectives, KPIs, KRIs and risk-acceptance processes
- Building security into the software development lifecycle alongside Engineering rather than creating external approval gates
- Leading product and application security across threat modelling, architecture reviews, secure coding, SAST/DAST, dependency and supply-chain security, secrets management, vulnerability management, penetration testing and bug bounty programs
- Owning the security architecture of cloud infrastructure, including the ongoing migration from AWS to GCP
- Working across IAM, privileged access, network security, containers, infrastructure-as-code, encryption, logging, detection, data security and cloud security posture management
- Building and improving security operations, detection engineering, SIEM, incident response, investigations and security incident playbooks
- Leading security across the corporate technology environment, including identity, SSO/MFA, endpoint security, SaaS and device trust
- Moving the organization towards a practical Zero Trust model
- Building a scalable third-party and supply-chain security program based on actual exposure and business impact
- Establishing security controls for AI-powered products and internal AI usage, including LLM access, AI agents, prompt injection, data exfiltration, model/provider risk, logging and shadow AI
- Working with Legal and Privacy on GDPR, EU AI Act and other regulatory requirements while maintaining ownership of the underlying technical security controls
- Maintaining and evolving security programs such as ISO 27001 and SOC 2 Type II
- Providing the CTO and executive team with a clear and measurable view of the company's security posture and material risks
Nice to have:
- Experience in HR-tech, workforce technology, marketplace, fintech or another data-intensive technology environment
- Experience leading a major cloud migration or transformation, particularly AWS to GCP
What we offer:
- A global CISO role with direct reporting to the CTO and significant ownership of the company's security strategy
- The opportunity to shape security across product, engineering, cloud infrastructure, corporate IT, data and AI
- A genuinely technical leadership position where you can engage directly with architecture, engineering and security problems
- The opportunity to lead security during a major cloud transformation from AWS to GCP
- The chance to build and scale a security organization rather than simply maintain an established security program