Head of Cybersecurity
Brak informacji o wynagrodzeniu
C-Level / ManagerFull-time
#434970·Dodano miesiąc temu·1
Źródło: XebiaTech Stack / Keywords
AICloud securitySIEMXDREDRSOARPAMZero TrustKubernetesDevSecOps
Firma i stanowisko
Xebia is a global technology consulting company helping organizations transform through technology, data, cloud, AI and software engineering.
Wymagania
Experience & credibility:
- Senior cybersecurity leader with deep operational security, cloud, identity and incident response experience; typically 12+ years in security with 5+ years in a leadership role.
- Track record of running or transforming a SOC/detection function and leading enterprise-scale incident response and crisis management.
- Practical experience securing multi-cloud and modern application environments, plus AI models and agentic AI systems.
- Experience owning business continuity/disaster recovery planning and data loss prevention or IP protection programmes in technology or professional services settings.
- Ability to balance pragmatic delivery with risk reduction and customer assurance.
- Credible with executives, auditors, customers and technical teams; comfortable presenting cyber risk in business terms to the Board.
- Experience leading distributed, multicultural teams across regions.
Certifications & knowledge:
- Indicative certifications: CISSP, CISM, GCIH, GCFA, CCSP, OSCP.
- Working familiarity with NIST CSF 2.0, ISO 27001, MITRE ATT&CK, GDPR, NIS2, DORA, OWASP LLM Top 10, OWASP Agentic AI threats, MITRE ATLAS or equivalent hands-on exposure securing AI models and autonomous agents.
What will make you successful:
- Strong hands-on technical depth.
- Cybersecurity programme and transformation leadership.
- Modern cloud and identity security expertise.
- Practical AI/LLM and agentic AI security experience.
- Strong customer orientation.
- Excellent communication and leadership presence.
- Ability to operate effectively in a global, distributed environment.
Obowiązki
Cybersecurity Operations & Incident Response:
- Define and operate cybersecurity capability across prevention, detection, response and recovery.
- Own global incident response, cyber crisis coordination, tabletop exercises, post-incident reviews and remediation tracking.
- Own security tooling strategy across SIEM, XDR, EDR, SOAR and threat intelligence.
- Drive detection engineering, alert quality, automation and security dashboards.
- Lead vulnerability and continuous exposure management across infrastructure, cloud, endpoints, applications and external-facing assets.
- Drive continuous improvement of overall security posture.
Identity, Cloud & Modern Architecture:
- Own identity security and drive Zero Trust adoption, including PAM, conditional access and governance of service accounts and machine identities.
- Own cloud security posture and workload protection across multi-cloud environments, including containers, Kubernetes and infrastructure-as-code.
- Partner with Infrastructure, Applications and AI/Data teams to embed secure-by-design patterns and DevSecOps practices.
- Define and continuously improve minimum security baselines for endpoints, identities, cloud, SaaS, networks, code repositories and AI platforms.
- Evaluate and implement security technologies and controls that address identified risks.
AI, LLM & Agentic AI Security:
- Own security risk oversight for AI and LLM-based systems including model and data security, training/fine-tuning data integrity, adversarial robustness, model theft/extraction, prompt injection and misuse.
- Define and enforce security guardrails for agentic AI including least-privilege access, human-in-the-loop checkpoints, action logging, audit trails and containment controls.
- Assess risks related to third-party foundation models, plugins, MCP servers and agent frameworks.
- Maintain inventory of AI models and agents in use and assess their security exposure.
- Partner with AI/ML Engineering and platform teams to enable secure adoption of AI-assisted and agentic coding, delivery and client-facing tools.
- Help continuously adapt security approach to evolving AI threat landscape.
Cyber Resilience, Business Continuity & Data Protection:
- Own cybersecurity contribution to business continuity planning and disaster recovery.
- Ensure restoration of critical systems and services within agreed RTO/RPO objectives.
- Drive ransomware resilience through immutable and segmented backups, isolated recovery environments and tested recovery playbooks.
- Lead regular cyber crisis, business continuity and recovery exercises.
- Own protection of intellectual property, source code, proprietary methodologies, AI models, training data and confidential client deliverables.
- Drive DLP, access controls, code repository security and exfiltration monitoring.
- Partner with HR and Legal to manage insider risk throughout employee and contractor lifecycle.
Security Programme & Transformation Leadership:
- Own and evolve global cybersecurity transformation roadmap.
- Translate identified risks into technology, process and programme initiatives.
- Lead cybersecurity programmes ensuring clear milestones, ownership and measurable outcomes.
- Build business cases and contribute to investment decisions around cybersecurity tooling, capabilities and team growth.
- Establish practical, measurable and enforceable security controls across organisation.
- Build and develop global cybersecurity team.
- Work effectively with distributed teams and external security partners.
Customer & Business Orientation:
- Support customer security questionnaires, audits and assurance activities.
- Anticipate customer security expectations and translate into practical security capabilities.
- Contribute to strategic sales opportunities and client engagements.
- Help position Xebia as a trusted technology and security partner.
- Balance security requirements with business and customer needs, finding pragmatic solutions.
Executive Leadership & Assurance:
- Provide executive and Board-level reporting on cybersecurity posture, threat trends, incidents, remediation status and maturity.
- Communicate complex cybersecurity risks in clear business terms.
- Maintain risk-based cybersecurity transformation roadmap with quarterly milestones.
- Manage third-party, vendor and software/AI supply chain cyber risk.
- Own execution of security awareness programme, including phishing simulations, role-based training and insider risk culture.
- Support customer security assurance activities, audits, certifications and M&A cyber due diligence.
- Work with IT GRC & Assurance and Legal to ensure operational controls meet regulatory obligations including GDPR, NIS2, DORA and client contractual requirements.
Benefity
- Opportunity to shape and build a global cybersecurity capability.
- Influence significant investments in security technology and people.
- Work at the intersection of cybersecurity, cloud and AI.
- Partner directly with executive leadership.
- Work with international engineering, AI and delivery teams.
- Help define global technology company approach to security of emerging AI and agentic technologies.
Xebia sp. z o.o.
96 aktywnych ofert