ყველა ვაკანსიაზე დაბრუნება
Chief Information Security Officer
UpGuard
დისტანციურიAustralia1 დღის წინწყარო: Jobicy
ამ ვაკანსიებზე განაცხადი დამსაქმებლის საკუთარ საიტზე იგზავნება. ჩვენ დოკუმენტებს ვამზადებთ და ბმულს გაძლევთ.
ვაკანსიის აღწერა
Who are we?
At UpGuard, we are replacing manual security bottlenecks with AI-driven precision. Fresh off a US$75M Series C, we are scaling our infrastructure to process 100 billion risk signals daily. This isn’t just growth; it’s a total reimagining of how the world manages cyber risk.
We build the Cyber Risk Posture Management (CRPM) platform that security teams actually love. By integrating security ratings, threat intel, and agentic AI, we empower organisations to stay ahead of an ever evolving attack surface.
We aren’t just building another tool; we’re defining a category. We provide the autonomy to ship world-class technology and the resources to do it at a global scale.
Where does this role fit in?
This is not a conventional CISO role, and we'd rather say that up front than have you discover it in week three.
You will own the entire enterprise technology stack — security and infrastructure, identity, end user compute, networking, cloud platform, and the technology and physical security services behind our workspaces. Security is the substrate, or underlay, for that stack - not a separate function that reviews someone else's work. If you have run infrastructure or operations at scale and layered security over it, this remit will feel natural. If your background is governance-first, it won't.
The environment you're inheriting has been run deliberately lean for through start-up and scale-up, and it is opinionated by design. There is no Microsoft directory, productivity, or desktop footprint anywhere in the estate — Google Workspace, Okta, macOS and ChromeOS, managed browser for BYOD. Attack surface has been controlled by refusing to acquire it. We want that philosophy continued and extended, not unwound.
You'll lead a team - currently nine FTE in size, across four functions: IT Operations, Security Operations, Cloud Platform Engineering and GRC. Your first structural job is maturing security operations to serve both enterprise and product systems — deeper investment in Google SecOps and our n8n automation platform to lift analytics, orchestration and response well beyond what a team this size would normally reach.
And because our product is the leading Cyber Risk Posture Management platform, you are customer zero. You and your team run UpGuard Cyber Risk harder than any of our customers do, turning what you learn into use cases Sales and Customer Success can take to market and signal Product can build on. That is a real, recurring part of the job, not a nice-to-have.
You'll report directly to the CEO, with a defined transition period alongside the outgoing CISO. Details of the remit are below.
What will you do?
Own the full technology and security remit. Enterprise infrastructure, security, identity, applications, and workplace technology under a single accountability. No handoffs, no shared ownership of outcomes
Lead and grow three functions. IT & Security Operations, Cloud Platform Engineering, and GRC. Coach the existing leaders, set the technical bar, and build the team you need beneath you — while holding the line on lean
Mature security operations. Build detection, analytics, orchestration and response capability that covers both enterprise and product systems. Drive investment into Google SecOps and n8n so that automation, not headcount, carries the load
Own identity end to end. IAM across our GCP project estate and identity governance and administration for the entire global workforce — joiner/mover/leaver, entitlement review, privileged access, and OAuth consent risk (which, fittingly, we control with our own User Risk product)
Own the network and cloud perimeter. ZTNA as the strategic access model, GCP perimeter security and networking
Own end user compute globally. A predominantly macOS fleet with selective use of ChromeOS and enterprise managed browser services for BYOD. Device provisioning and retrieval across all operating regions
Own the workspaces. Technology and physical security services
CybersecurityDirector