Where does this role fit in?
This is not a conventional CISO role, and we’d rather say that up front than have you discover it in week three.
You will own the entire enterprise technology stack — security and infrastructure, identity, end user compute, networking, cloud platform, and the technology and physical security services behind our workspaces. Security is the substrate, or underlay, for that stack - not a separate function that reviews someone else’s work. If you have run infrastructure or operations at scale and layered security over it, this remit will feel natural. If your background is governance-first, it won’t.
The environment you’re inheriting has been run deliberately lean for through start-up and scale-up, and it is opinionated by design. There is no Microsoft directory, productivity, or desktop footprint anywhere in the estate — Google Workspace, Okta, macOS and ChromeOS, managed browser for BYOD. Attack surface has been controlled by refusing to acquire it. We want that philosophy continued and extended, not unwound.
You’ll lead a team - currently nine FTE in size, across four functions: IT Operations, Security Operations, Cloud Platform Engineering and GRC. Your first structural job is maturing security operations to serve both enterprise and product systems — deeper investment in Google SecOps and our n8n automation platform to lift analytics, orchestration and response well beyond what a team this size would normally reach.
And because our product is the leading Cyber Risk Posture Management platform, you are customer zero. You and your team run UpGuard Cyber Risk harder than any of our customers do, turning what you learn into use cases Sales and Customer Success can take to market and signal Product can build on. That is a real, recurring part of the job, not a nice-to-have.
You’ll report directly to the CEO, with a defined transition period alongside the outgoing CISO. Details of the remit are below.