Join Valarian as the Head of Information Security to lead security strategy and compliance in a cutting-edge technology company.
Posted by employer 4 days ago
First seen on Joblaze 3 days ago
Last verified on the company career page 1 day ago
Not disclosed in this posting: compensation, years of experience, visa sponsorship.
Joblaze summary
The Head of Information Security at Valarian is responsible for shaping and implementing the company's security strategy, ensuring compliance with various global standards, and integrating security practices into the engineering culture. This role requires expertise in risk management, security governance, and DevSecOps, making it suitable for experienced professionals transitioning to a CISO-level position. Valarian emphasizes collaboration within high-performing teams, reflecting its commitment to innovation in safeguarding critical data and infrastructure.
Quick facts
- Is the Head of Information Security role remote?
- No — this is an on-site role in London.
- Where is the role based?
- Valarian is hiring for this position in London.
- What's the tech stack?
- Joblaze extracted these technologies from the posting: CI/CD, Cyber Essentials Plus, DevSecOps, ISO 27001, NIST 800-53, SOC 2 Type II.
- What seniority level is this role?
- Valarian targets c-level candidates for this position.
- Is this full-time or contract?
- Full-time for this Head of Information Security role at Valarian.
From the original posting
Valarian Technologies is a dual-use technology company building critical tools to safeguard the future in an era of evolving global security challenges. We're rethinking security beyond traditional military domains, addressing asymmetric threats that impact our technological advantage, economic strength, and democratic institutions.
We build Acra – the platform foundation for everything we do as a dual-use technology company. The platform’s name, rooted in the Greek word for citadel (or, fortress), reflects the design and purpose of our infrastructure-agnostic secure enclaves: protecting critical data. Some of the government and commercial workflows include: increased operational resiliency for mission-critical systems and functions; enabling organisations to more quickly and widely adopt emerging technologies while ensuring the integrity of their intellectual property; information flow during disaster response scenarios, and zero-trust / least-privilege environments for M&A, attorney-client privileged communications, etc. And we’ve only scratched the surface.
At our core, we're driven by a shared mission and a belief in making a tangible impact on our world. Whether you join our London HQ or the wider global organisation, you’ll be a part of collaborative, high-performing teams, creating cutting-edge software, platforms, and infrastructure.
The Role:
We are seeking an ambitious, technical Head of Information Security (Deputy CISO) to take full ownership of Valarian’s internal security posture, enterprise risk framework, and product compliance. Ideal for a Senior Security Manager, Architect, or Director stepping into their first CISO-level leadership role, you will embed security into our engineering culture, maintain customer trust, and ensure full compliance across global enterprise and defense standards.
What you’ll do:
Drive Security Strategy & Governance: Design and execute Valarian’s Zero-Trust security roadmap, policies, risk assessments, and executive reporting for leadership and the board.
Lead Compliance & Certifications: Own end-to-end audit readiness for enterprise and defense frameworks, including SOC 2 Type II, ISO 27001, Cyber Essentials Plus, and NIST 800-53.
Partner with Product & Engineering: Embed DevSecOps and secure SDLC practices into our CI/CD pipelines; oversee pentesting, red teaming, and threat modeling across our core infrastructure.
Enable Enterprise Sales: Serve as the technical security authority in high-stakes customer procurement reviews, vendor risk assessments (DDQs), and defense customer evaluations.
Oversee Security Operations: Build and manage internal incident response capabilities, continuous monitoring, vulnerability management, and employee security awareness programs.
What we are looking for: