Job at a glance
Take full ownership of Valarian’s internal security posture, enterprise risk framework, and product compliance Embed security into the engineering culture and maintain customer trust Design and execute Valarian’s Zero-Trust security roadmap, policies, risk assessments, and executive reporting for leadership and the board Own end-to-end audit readiness for SOC 2 Type II, ISO 27001, Cyber Essentials Plus, and NIST 800-53 Embed DevSecOps and secure SDLC practices into CI/CD pipelines Oversee penetration testing, red teaming, and threat modeling across core infrastructure Serve as the technical security authority in customer procurement reviews, vendor risk assessments, and defense customer evaluations Build and manage internal incident response capabilities, continuous monitoring, vulnerability management, and employee security awareness programs Requirements Ambitious, technical security leader Experience suitable for a Senior Security Manager, Architect, or Director stepping into a first CISO-level leadership role Experience with Zero-Trust security roadmaps, policies, and risk assessments Experience with SOC 2 Type II, ISO 27001, Cyber Essentials Plus, and NIST 800-53 Experience embedding DevSecOps and secure SDLC practices into CI/CD pipelines Experience overseeing penetration testing, red teaming, and threat modeling Experience with customer procurement reviews, vendor risk assessments (DDQs), and defense customer evaluations Experience building and managing incident response, continuous monitoring, vulnerability management, and employee security awareness programs Core Competencies Demonstrates expertise in Zero-Trust security frameworks, compliance standards such as SOC 2 Type II and ISO 27001, and embedding security practices within engineering cultures.
Proven ability to lead incident response initiatives, manage risk assessments, and oversee vulnerability management programs. Highest-signal resume keywords Zero-Trust Security Roadmap SOC 2 Type II Compliance ISO 27001 Certification DevSecOps Practices Incident Response Management Hard Skills Risk Assessment Penetration Testing Threat Modeling Vulnerability Management Continuous Monitoring Soft Skills Leadership Ambition Technical Authority Certifications & Qualifications Cyber Essentials Plus NIST 800-53 Industry Keywords Enterprise Risk Framework Security Awareness Programs Vendor Risk Assessments Customer Procurement Reviews Tools & Technologies CI/CD Pipelines Security Posture Management #J-18808-Ljbffr