
Chief Information Security Officer (CISO)
Remote
United Kingdom
Full Time
18-03-2025
Job Specifications
Hurry up! We’ve got a dream to build!
BlueConic is the market-leading customer data platform, which gives marketers the power to liberate their data and use it to improve marketing outcomes. Our clients use BlueConic to unify individual-level data and then use that single view across channels. Our SaaS platform is the solution for challenges marketers haven’t been able to solve for years. We’re headquartered in Boston and our development team works from the Netherlands. With more than 300 brands currently using the platform, our work is experienced by millions. Our mission is to make an out-sized impact, every day – for customers, for partners, for employees.
BlueConic is an international, high-growth SaaS company in the martech space. Built and supported by teams around the globe, our industry-first customer data operating system empowers marketing and growth doers with an unmatched range of capabilities to access relevant customer data, create resonant customer experiences, and drive maximum returns for their business.
Security is paramount to us at BlueConic and we need a visionary Chief Information Security Officer (CISO) who is at the forefront of this ever-evolving digital landscape. You’ll lead a small but critical team of passionate InfoSec and compliance professionals and play a hands-on role in shaping and executing our security strategy, protecting company and customer data, and ensuring compliance.
In this role you will:
Design and lead an innovative cybersecurity strategy that aligns with our company’s growth and vision.
Develop and enforce crystal-clear security policies, procedures, and best practices that keep us ahead of emerging threats, keeping our data safe and our customers confident.
Oversee compliance with regulatory requirements and industry standards (e.g. ISO 27001, SOC 2, GDPR, and CCPA).
Collaborate with engineering and IT teams in multiple countries to integrate security best practices into software development and infrastructure management.
Lead incident response efforts, ensuring swift identification, mitigation, and reporting of security breaches.
Drive security awareness training and education, cultivating a proactive, security-minded culture throughout the company.
Evaluate and implement security technologies and tools to enhance threat detection and prevention.
Act as the primary security liaison for external stakeholders, including customers, auditors, and regulatory bodies.
Take an active role in all Security functions.
You have:
10-15 years of experience in a senior leadership Security role within a SaaS or software-driven environment, with demonstrated ability to adapt in an evolving technology landscape.
Deep expertise in cybersecurity frameworks, risk management, and compliance requirements (e.g., ISO 27001, SOC 2, GDPR, NIST, CCPA).
Experience with Cloud Security, DevSecOps practices, and modern security architectures.
Deep understanding of security technologies, protocols, and frameworks.
Experience managing incident response, disaster recovery, and business continuity planning.
Experience developing and implementing AI security and governance programs to ensure the secure and ethical use of AI technologies within the company. This includes risk assessment, compliance with regulatory standards, security controls, and continuous monitoring of AI systems to mitigate potential threats and vulnerabilities
A passion for fostering a culture of security consciousness and continuous improvement.
Reasons to join us:
Help build & support the best martech product ever, period.
Take advantage of great opportunities for career advancement.
Empower big name brands to achieve their marketing goals.
Be a part of a growing, remote-first team with employees based in the Netherlands, the United States, the United Kingdom, Canada, and beyond.
Thrive in a multi-cultural environment with a values-driven work culture that has been thoughtfully crafted to enable growth and foster inclusion from the very beginning.
About BlueConic:
BlueConic is the operating system that puts data into action for marketing and growth doers. Our vision is one where marketers achieve their long-held, rarely realized ambitions of blending creativity with data, and performance with agility. With BlueConic, this ambition becomes a reality, transforming the relationship between brands and consumers. More than 500 businesses worldwide rely on BlueConic to unlock their full customer data potential, including Forbes, Heineken, Mattel, Michelin, Telia Company, and VF Corp.
As a group, we are driven by “building the dream” - the collective passion, ethic, vision, and set of values channeled by a group to achieve a common goal of being extraordinary. Our goal is for BlueConic to be a fun, productive, welcoming, and safe space where BlueCrew members of all races and ethnicities, gender identities, gender expressions, sexual orientations, physical abilities, neurodivergences, physical appearances, socioeconomic backgrounds, life experiences, nationalities, ages, religions, and beliefs are empowered to be able to make an outsized impact every day – for customers, for partners, for employees.
About the Company
BlueConic is the operating system that puts data into action for marketing and growth doers. The industry-first solution empowers doers with an unmatched range of capabilities to access relevant customer data, create resonant customer experiences, and drive maximum returns for their business. More than 500 businesses worldwide rely on BlueConic to unlock their full customer data potential, including Forbes, Heineken, Mattel, Michelin, Telia Company, and VF Corp. Know more
Related Jobs


- Company Name
- Vertus Partners
- Job Title
- Cyber Security Architect - Banking - London
- Job Description
- My client, a leading multinational bank is looking for a Security Architect who can help in strengthening their security posture and ensuring that their application lifecycle meets the highest standards of protection. You’ll be responsible for leading and designing comprehensive security solutions including creating end-to-end blueprints for security infrastructure to help protect their systems from any potential cyber threats. Requirements Proven experience as a Cyber Security Architect, with a focus on designing, implementing, and securing large-scale systems. Strong experience in Network Security, Application Security, Cloud Security and implementing security toolsets to improve overall system security. Knowledge and hands-on experience with application lifecycle processes and security measures at each stage. A proactive mindset to identify gaps in security and a strong track record of delivering successful security solutions. Ability to work with stakeholders across all levels discussing complex solutions. Certifications such as CISSP or CISM would be a plus. Please note this role will require you to be in their London office 5 days per week.


- Company Name
- monday.com
- Job Title
- Application Security Researcher - London
- Job Description
- Description monday.com is looking for an application security researcher to research our platform for vulnerabilities, manage our bug bounty program, and work with R&D to enhance the security of our platform. The Application Security Team is based in our headquarters, Tel Aviv, Israel - you’ll be the first to join the team from London. monday.com works hybrid with 3 days in the London office. About The Role Perform black, gray, and white box penetration testing on monday.com’s platform - both frontend and backend. Manage the bug bounty program, including hacker engagement and communication with the hacker community. End-to-end work on reported vulnerabilities as part of the bug bounty program. Provide guidance on security best practices to developers. Embed/improve security threat modeling and secure coding in the development lifecycle. Develop security abuse cases for testing as part of the software development lifecycle. Perform and oversee security testing and manage remediation of identified vulnerabilities. Monitor and proactively report on current threats and vulnerabilities to application security. Initiate and automate processes for detecting and monitoring the platform security. Requirements Scripting capabilities and automation mindset. At least 2 years of experience in web penetration-testing. In-depth knowledge of application security vulnerabilities, testing techniques, and the OWASP framework. Experience working with the hacker/pen-testing community. Team player able to and build relationships across the organization, also remotely. Understanding of secure web application development. Comprehensive knowledge of IT and information security subject matter. Exposure to methods of promoting security awareness. Strong communication (verbal/written) and influencing skills, with an ability to manage internal and external relationships. Anticipates problems and identifies long-term implications of decisions and actions. Ability to work and learn alone. Able to prioritize workload and drive work to set deadlines.


- Company Name
- British Heart Foundation
- Job Title
- Information Security Manager
- Job Description
- Location: Dual - London office & home Salary Details: £59,000 - £62,000 p/a + benefits Hours Per Week: 35 Closing Date: 31 Mar 2025 Vacancy type: Permanent Are you an Information Security expert looking to work for one of the UK's largest charities? British Heart Foundation (BHF) is undergoing a digital transformation and seeking an Information Security Manager to oversee Governance, Risk, and Compliance (GRC) within the security team and ensure regulatory and policy compliance. Joining a dynamic and growing information security team at an exciting point in the charities history you’ll collaborate with teams across British Heart Foundation (BHF) to protect BHF’s objectives and integrity. Responsibilities include risk identification, assessment, mitigation, and maintaining a robust governance framework. Managing the Information Security GRC team, you'll enhance security, compliance, and risk posture in line with industry standards while maintaining ethical practices. Working arrangements This is a blended role, where your work will be dual located between your home and our London office. At BHF we believe in the power of being together, so our colleagues on blended contracts can expect to spend some time in their office, at least one day each week, on average. The use of our office spaces is driven in part by your role and the activities you need to do. This may vary from time to time, so you will need to work in a flexible way to unlock your best work for our cause. About you This opportunity would suit an experienced GRC professional who excels in a collaborative environment and has hands-on risk management and reporting experience. With previous experience managing and leading an InfoSec GRC team, you’ll have strong knowledge and experience of working with the following: • Payment Card Industry Data Security Standard (PCI-DSS) for a Tier 1 merchant • General Data Protection Regulation (GDPR) • NIST Cybersecurity Framework (CSF) v2.0 • Critical Security Controls Libraries such as CIS Controls • Cyber Essential Plus (CEP) With proven experience in managing and delivering complex GRC activities within a fast-paced and dynamic security domain, you’ll have previous experience of working within a risk management framework as well as Cloud Security governance. To be successful in this role you’ll also have the following skills and experience: • Effective at building relationships across a large complex organisation and influencing stakeholders. • Excellent communication and presentation skills, able to translate complex security-related matters into terms that are easily understood by colleagues. • Planning skills to develop a governance risk and compliance roadmap to be executed by the GRC team. • Excellent analytical and problem-solving skills. • Able to manage multiple tasks and meet deadlines in a fast-paced environment. About us At BHF, we are focused on the urgent need to fund more research into heart and circulatory diseases like heart diseases, stroke, vascular dementia and the conditions that cause them, to find answers fit for 21st century challenges. We are independent, have more than fifty years of breakthroughs under our belts and we won’t stop until we beat heartbreak forever. We value and respect every individual’s unique contribution, celebrate diversity, and make inclusion part of what we do every day. Our Equality, Diversity and Inclusion (EDI) Strategy, Igniting Change, along with our internal EDI group, Kaleidoscope, and a growing number of employee network groups (our Affinity Groups), help us create an environment where all our colleagues and volunteers can succeed. How to apply It’s quick and easy to apply for a role at BHF. Just click through to our careers site to apply. All you’ll need is an up-to-date CV and a supporting statement, outlining your interest in the role and how you meet the role’s criteria. As part of our commitment to be an inclusive employer and ensure fairness and consistency in selecting the best candidate for this role, the BHF will use anonymous CV software as part of the application journey. Should you need any adjustments to the recruitment process, at either application or interview, please contact us.


- Company Name
- Nottingham University Hospitals NHS Trust
- Job Title
- Data Protection & Security Manager
- Job Description
- Are you looking to make a difference and use your leadership and coaching skills? Then we want to hear from you as we have an excellent opportunity for you. We need experts in Data Protection and Security to help the Trust deliver an excellent Data Protection Office service. You probably know the NHS is one of the largest employers in the UK and EU and it needs you. In return this role can offer you a fantastic opportunity for you to learn, grow and develop whilst being supported by experienced leaders within this field. We’ve recently undertaken a full workforce change across the Data Protection Office service and are seeking strong, visible and competent leaders who can use their knowledge, skills and abilities to coach a team of staff to learn, develop and grow to achieve shared service wide objectives. In addition to the brief list below you must familiarise yourself with the full job description and person specification attached to this advert prior to applying. The post holder will be an experienced leader and specialist in relation to data protection, security, confidentiality, line management, service delivery and records managements. Responsible for the day to day management of the Data Protection Office / service. Lead and promote data protection and security awareness and provide advice and guidance to the Trust, Employee’s and Management in relation to the organisation achieving compliance with Data Protection Legislation. Provide Information Governance support in relation to commercial, informatics, and research projects. Provide first line support for all data protection and security enquiries. Including commercial, data analytics and research to the Trust. Such as contracts and procurement process and due diligence, ISA, DPA, DPIAs and DTAC. Work with managers, Heads of Service and Directors of operations to identify any new working practices required and to support the change programme to implement these utilising a Privacy by Design process. Ensure Continuous Professional Development (CPD) of self and supervisee’s. Provide expert advice to the Trust in relation to relevant Information Security / Cyber Security frameworks such as ISO27001 compliance but not limited too. Keeping themselves up to date with relevant frameworks. The post requires a mix of on-site and home working to suit the needs of our service. Typically, one or two days a week depending on the service needs. The service has an agile working approach and planned meeting schedules so the entire service can plan accordingly their home and work life balance accordingly. With over 20,000 staff, we are one of the biggest employers in the city with a central role in supporting the health and wellbeing of our local population. We play a leading role in research, education and innovation. Come and join our wonderful team at NUH. We are big believers in diversity and welcome new ideas to help develop our team in order to deliver world class healthcare to the vast patient populations we serve. With endless personal development opportunities available, at NUH we will endeavour to turn your job into a career! We particularly welcome applications from people who identify as Black, Asian and Minority Ethnic, or Disabled, as we are striving to be better represented at NUH. For further details / informal visits contact: Name: Marc Wilson Job title: Head of Information Security & Data Protection Email address: marc.wilson@nhs.net Please email to arrange discussion.