Chief Information Security Officer (CISO) – AI / SaaS
UK Wide | Hybrid
Our client is an AI start-up on a mission to redefine how intelligent systems solve real-world problems through cutting-edge artificial intelligence technologies. Backed by early-stage investors and building momentum towards the next phase of growth, we are exclusively supporting them in building a team of bold thinkers, high-calibre operators, and commercially credible leaders.
We are now hiring a Chief Information Security Officer (CISO) to take ownership of security and trust across the business.
This is a hands-on, operational leadership role with full accountability for security across internal systems, product and platform, customer deployments, and the company’s AI-enabled operating model. This is a true Greenfield opportunity to build and scale security within a modern SaaS environment, operating as a senior individual contributor within a lean team, with the expectation to both define strategy and execute.
You will ensure security is embedded into how the business builds, delivers, and scales — not added as a control layer at the end.
Role scope
Working as part of the COO leadership team, you will partner closely with Engineering, Product, Delivery and Operations to define and implement a pragmatic, scalable security model that supports growth, delivery, and customer trust.
Key accountabilities
Corporate & internal security
- Own internal security architecture, controls and policies across systems, identities, devices and third-party tools
- Lead IAM, privileged access, endpoint security, access reviews and security awareness
- Ensure the organisation scales securely without introducing unnecessary friction
Platform, product & AI security
- Define security standards across software, infrastructure, APIs, data and customer environments within a SaaS model
- Embed secure SDLC, threat modelling, vulnerability management, penetration testing and remediation governance
- Own security for AI-enabled workflows, including data exposure, model misuse, prompt and automation risks
- Partner with CTO and Product to ensure security is embedded in design and release
Customer security, privacy & compliance
- Own customer assurance: security reviews, questionnaires, DPIAs and audit responses
- Ensure all deployments meet security standards prior to go-live
- Support enterprise and regulated customer environments with a credible, practical security posture
- Represent the business with customers, auditors and regulators
Security risk, incident response & assurance
- Own risk identification, mitigation tracking and reporting to COO, Board and governance forums
- Lead security incident response end-to-end (detection, containment, recovery and communication)
- Own regulatory and contractual notification obligations
- Ensure reporting is clear, proportionate and action-oriented
Security enablement & maturity
- Build a pragmatic, scalable security model suited to a growing SaaS / AI business from an early-stage (greenfield) foundation
- Define and deliver a staged maturity roadmap aligned to frameworks (SOC 2, ISO 27001, GDPR)
- Use automation and AI-assisted tooling to operate effectively within a lean team structure
- Embed security discipline across Product, Engineering and Operations as the business scales
Ownership of
- Final security sign-off for go-live
- Authority to escalate or require remediation of risk
- Ownership of security incidents and external communications
- Accountability for defining baseline controls and assurance standards
Experience required
- Experience leading or owning security in a startup or scale-up SaaS environment, ideally in a greenfield or early-stage build
- Strong hands-on capability as an individual contributor, with the ability to operate without large supporting teams
- Deep experience across product security, cloud security, IAM, vulnerability management and incident response
- Practical understanding of AI and automation-related security risks
- Experience supporting enterprise and regulated customers
- Strong familiarity with SOC 2, ISO 27001, GDPR / UK DPA and DPIAs
- Comfortable working cross-functionally with engineering, product and operations teams
Profile
- Hands-on, pragmatic and execution-focused
- Comfortable operating as a senior individual contributor in a lean, high-growth environment
- Able to balance risk, delivery and commercial reality
- Motivated by building security capability from the ground up in a SaaS business
…
