Valarian
Head of Information Security
London · Posted 3h ago
Job Description
Valarian Technologies is a dual-use technology company building critical tools to safeguard the future in an era of evolving global security challenges. We're rethinking security beyond traditional military domains, addressing asymmetric threats that impact our technological advantage, economic strength, and democratic institutions. We build Acra – the platform foundation for everything we do as a dual-use technology company. The platform’s name, rooted in the Greek word for citadel (or, fortress), reflects the design and purpose of our infrastructure-agnostic secure enclaves: protecting critical data. Some of the government and commercial workflows include: increased operational resiliency for mission-critical systems and functions; enabling organisations to more quickly and widely adopt emerging technologies while ensuring the integrity of their intellectual property; information flow during disaster response scenarios, and zero-trust / least-privilege environments for M&A, attorney-client privileged communications, etc. And we’ve only scratched the surface. At our core, we're driven by a shared mission and a belief in making a tangible impact on our world. Whether you join our London HQ or the wider global organisation, you’ll be a part of collaborative, high-performing teams, creating cutting-edge software, platforms, and infrastructure. The Role: We are seeking an ambitious, technical Head of Information Security (Deputy CISO) to take full ownership of Valarian’s internal security posture, enterprise risk framework, and product compliance. Ideal for a Senior Security Manager, Architect, or Director stepping into their first CISO-level leadership role, you will embed security into our engineering culture, maintain customer trust, and ensure full compliance across global enterprise and defense standards. What you’ll do: Drive Security Strategy & Governance: Design and execute Valarian’s Zero-Trust security roadmap, policies, risk assessments, and executive reporting for leadership and the board. Lead Compliance & Certifications: Own end-to-end audit readiness for enterprise and defense frameworks, including SOC 2 Type II, ISO 27001, Cyber Essentials Plus, and NIST 800-53. Partner with Product & Engineering: Embed DevSecOps and secure SDLC practices into our CI/CD pipelines; oversee pentesting, red teaming, and threat modeling across our core infrastructure. Enable Enterprise Sales: Serve as the technical security authority in high-stakes customer procurement reviews, vendor risk assessments (DDQs), and defense customer evaluations. Oversee Security Operations: Build and manage internal incident response capabilities, continuous monitoring, vulnerability management, and employee security awareness programs. What we are looking for: