Chief Information Security Officer
Summary
The Chief Information Security Officer at UpGuard will own the entire enterprise technology stack including security, infrastructure, identity, cloud platform, and workplace technology. The role involves leading a team of 9 FTE across IT Operations, Security Operations, Cloud Platform Engineering, and GRC, with a focus on maturing security operations, implementing zero trust architecture, and bein
Who are we?
At UpGuard, we are replacing manual security bottlenecks with AI-driven precision. Fresh off a US$75M Series C, we are scaling our infrastructure to process 100 billion risk signals daily. This isn’t just growth; it’s a total reimagining of how the world manages cyber risk.
We build the Cyber Risk Posture Management (CRPM) platform that security teams actually love. By integrating security ratings, threat intel, and agentic AI, we empower organisations to stay ahead of an ever evolving attack surface.
We aren’t just building another tool; we’re defining a category. We provide the autonomy to ship world-class technology and the resources to do it at a global scale.
Where does this role fit in?
This is not a conventional CISO role, and we'd rather say that up front than have you discover it in week three.
You will own the entire enterprise technology stack — security and infrastructure, identity, end user compute, networking, cloud platform, and the technology and physical security services behind our workspaces. Security is the substrate, or underlay, for that stack - not a separate function that reviews someone else's work. If you have run infrastructure or operations at scale and layered security over it, this remit will feel natural. If your background is governance-first, it won't.
The environment you're inheriting has been run deliberately lean for through start-up and scale-up, and it is opinionated by design. There is no Microsoft directory, productivity, or desktop footprint anywhere in the estate — Google Workspace, Okta, macOS and ChromeOS, managed browser for BYOD. Attack surface has been controlled by refusing to acquire it. We want that philosophy continued and extended, not unwound.
You'll lead a team - currently nine FTE in size, across four functions: IT Operations, Security Operations, Cloud Platform Engineering and GRC. Your first structural job is maturing security operations to serve both enterprise and product systems — deeper investment in Google SecOps and our n8n automation platform to lift analytics, orchestration and response well beyond what a team this size would normally reach.
And because our product is the leading Cyber Risk Posture Management platform, you are customer zero. You and your team run UpGuard Cyber Risk harder than any of our customers do, turning what you learn into use cases Sales and Customer Success can take to market and signal Product can build on. That is a real, recurring part of the job, not a nice-to-have.
You'll report directly to the CEO, with a defined transition period alongside the outgoing CISO. Details of the remit are below.
What will you do?
Own the full technology and security remit. Enterprise infrastructure, security, identity, applications, and workplace technology under a single accountability. No handoffs, no shared ownership of outcomes
Lead and grow three functions. IT & Security Operations, Cloud Platform Engineering, and GRC. Coach the existing leaders, set the technical bar, and build the team you need beneath you — while holding the line on lean
Mature security operations. Build detection, analytics, orchestration and response capability that covers both enterprise and product systems. Drive investment into Google SecOps and n8n so that automation, not headcount, carries the load
Own identity end to end. IAM across our GCP project estate and identity governance and administration for the entire global workforce — joiner/mover/leaver, entitlement review, privileged access, and OAuth consent risk (which, fittingly, we control with our own User Risk product)
Own the network and cloud perimeter. ZTNA as the strategic access model, GCP perimeter security and networking
Own end user compute globally. A predominantly macOS fleet with selective use of ChromeOS and enterprise managed browser services for BYOD. Device provisioning and retrieval across all operating regions
Own the workspaces. Technology and physical security services for our offices — two today, potentially four by the end of 2027 across Australia and the US
Own the compliance program. [Delegated to the Infosec GRC Lead] SOC-2 Type II today, with ISO 27001 targeted to facilitate European growth. Own the enterprise risk register, and the security function's inputs into vendor management and procurement
Be customer zero. Use our own platform to its full extent and beyond, integrating with external systems via our Risk Automations product, feeding real operating experience back into Product, with co-creation of the cases and proof points that Sales and Customer Success will turn into new deals and expands
Communicate at executive level. Brief the executive team, the Steering Committee and the Board, and be credible in front of customers and prospects when their security teams want to talk to ours
What will you bring?
We care far more about your track record than your tenure. The bar is a leader who has personally built and operated technology at scale, with security as the discipline layered over it.
An infrastructure and operations foundation. You have run a data centre, an infrastructure function, or a substantial operations function — and security became your remit because you were already accountable for the systems. Architecture is where you're strongest
Process discipline learned somewhere consequential. You've operated in an environment where failure had real consequences and process was the answer — financial services is a strong example of the discipline we mean, though not the only one. You know how to defend, operate, and structure
A demonstrated ability to do a lot with a little. You have built and scaled capability without heavy resourcing, and you reach for automation before headcount. This is the single most important thing we're selecting for. If your effectiveness has depended on a large team, this role will frustrate you
Genuine comfort owning infrastructure, security, applications and identity together. Not as a stretch, but as your natural shape
Hands-on credibility. You are a leader, not a manager. You can architect a control, review a Terraform change, or lead an incident yourself — and you set the technical bar by example, not from the org chart
Cloud-native depth. Substantial GCP experience strongly preferred; deep AWS or Azure experience considered where the architectural instincts transfer. Zero trust access, identity-centric security models, and modern SaaS estate management
Ownership of a compliance program. You have carried SOC 2, ISO 27001, or equivalent as the accountable owner — through audit, not just through policy authoring
The ability to absorb context at speed. You'll have a structured handover and then it's yours. We need someone who is oriented in weeks, not quarters
Personal drive that doesn't need to be managed. High-energy, self-directed, and relentless about the work. You'll be given full ownership from day one, and we expect you to use it
Comfort operating in a fast-paced, high-growth, remote-first environment
What's in it for you?
Monthly Lifestyle subsidy: Use this for financial, physical, and mental well-being
WFH set-up allowance: To ensure you have the right environment to work in, we will help you get set up within your first 3 months at UpGuard
$1500 USD annual Learning & Development allowance: To support your career development, all team members will be able to expense development opportunities against this allowance
Annual leave: PTO plus two additional UpGuardian leave days to give you time to recharge your batteries.
18 weeks paid Parental Leave: Irrespective of parenting role
Personal Leave Allowance: This includes sick & carer’s leave
Fully remote working environment: While we have physical offices in Sydney & Hobart, we do not mandate compulsory attendance
Top-spec hardware: All team members will be provided with top-spec laptops for their role
Generative AI subsidy: UpGuard provides paid subscriptions for all team members to access generative AI tools to support their work
UpGuard is a Certified Great Place to Work® in the US, Australia, UK and India, establishing its position as a leading global technology employer. 99% of team members agree that UpGuard is a great place to work! Apply now to find out why!
As an Equal Employment Opportunity and Affirmative Action Employer, qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender perception or identity, national origin, age, marital status, protected veteran status, or disability status.
For applications to positions in the United States, please note, at this time, we can only support hiring in the following US states: CA, MD, MA, IL, OR, WA, CO, TX, FL, PA, LA, MO, or DC.
Before starting work with us, you will need to undertake a national police history check and reference checks. Also, please note that at this time, we cannot support candidates requiring visa sponsorship or relocation.