Metamindz is a UK-based technical consultancy - CTO-led software development, fractional CTO services, and technical recruitment for startups and scaleups across the UK, US, and Middle East. Every project is run by real developers and CTOs rather than non-technical account managers, so engineers here work directly on real products and real technical problems.
We're looking for a Chief Information Security Officer (CISO) to own and lead our client's global information security strategy, organization, and execution. The CISO will report directly to the CTO and work closely with Engineering, Platform, SRE, IT, Product, Data, AI, Legal, Privacy and the wider executive team.
This is a highly technical and hands-on security leadership role. It's not primarily about policies, audits, or certifications. We're looking for someone who can understand how systems actually work, identify the risks that matter, and build the technology, processes, teams and culture needed to manage those risks while allowing the company to move quickly.
Who we're looking for:
10+ years of experience in security roles, ideally within global software product companies
5+ years of significant security leadership experience in a technology, SaaS, marketplace, fintech, HR-tech or similarly data-intensive environment
2+ years of experience as a CISO or VP of Security in a global software technology company
Strong technical security background with the ability to go deep into architecture, infrastructure, identity, applications, cloud and security incidents when required
Experience leading security across both product technology and corporate IT environments
Strong cloud security experience, particularly with AWS and/or GCP
Strong understanding of IAM, SSO, MFA, privileged access, device trust and Zero Trust principles
Deep product and application security experience, including threat modelling, secure SDLC, vulnerability management, security testing and supply-chain security
Experience building or operating mature security operations and incident response capabilities
Experience protecting environments containing significant volumes of personal or otherwise sensitive data
Strong understanding of SaaS, third-party and supply-chain security risks
Experience with ISO 27001, SOC 2, GDPR and enterprise customer security requirements
Familiarity with AI security and emerging risks around LLM-based applications and AI agents
Strong communication skills and the ability to translate technical security risks into clear business context
Pragmatic and risk-driven approach - security should enable the business rather than become an unnecessary blocker
Strong leadership and organizational skills, with the ability to decide what should be built internally, automated, or outsourced
What you'll work on:
Owning global information security strategy, roadmap and security organization
Defining measurable security objectives, KPIs, KRIs and risk-acceptance processes
Building security into the software development lifecycle alongside Engineering rather than creating external approval gates
Leading product and application security across threat modelling, architecture reviews, secure coding, SAST/DAST, dependency and supply-chain security, secrets management, vulnerability management, penetration testing and bug bounty programs
Owning the security architecture of cloud infrastructure, including the ongoing migration from AWS to GCP
Working across IAM, privileged access, network security, containers, infrastructure-as-code, encryption, logging, detection, data security and cloud security posture management
Building and improving security operations, detection engineering, SIEM, incident response, investigations and security incident playbooks
Leading security across the corporate technology environment, including identity, SSO/MFA, endpoint security, SaaS and device trust
Moving the organization towards a practical Zero Trust model
Building


