Rodeo
Get started

CyberKainos

vCISO Partner

England
Posted about 16 hours ago
Sign up to applySee more jobs like this

How your CV stacks up

1Upload CV
2Analyse CV
3Improve CV

Upload your CV to see how well it fits this job role

?%

Company Description

CyberKainos is a cyber security, information security, and risk advisory firm helping mid market and enterprise organisations build resilient, scalable, and commercially aligned security programmes.

We work with clients to translate complex cyber security risks into clear business outcomes through strategic advisory, operational delivery, governance, risk and compliance, and technology enabled security services.

Our core services include Virtual Chief Information Security Officer services, cyber security strategy, information security governance, cyber risk and maturity assessments, ISO 27001 implementation and assurance, regulatory compliance, third party risk management, supply chain security, incident response readiness, security operations, and managed security services.

CyberKainos is also developing a platform led approach to Governance, Risk and Compliance, continuous security monitoring, cyber risk management, and supplier assurance.

Our focus is pragmatic security leadership, measurable risk reduction, regulatory compliance, operational resilience, and alignment between cyber security investment and business objectives.

Role Description

CyberKainos is seeking an experienced Virtual Chief Information Security Officer (vCISO) to provide strategic and operational cyber security leadership across a portfolio of client organisations.

The vCISO will act as a trusted security adviser to executive leadership teams, boards, technology leaders, risk functions, and operational stakeholders. The role combines cyber security strategy, governance, risk management, compliance, security assurance, incident readiness, and oversight of security operations.

The successful candidate will lead the development and implementation of client cyber security strategies aligned with business objectives, risk appetite, regulatory obligations, and recognised information security frameworks.

Key Responsibilities

  • Develop and maintain cyber security strategies, security roadmaps, governance frameworks, policies, standards, and security improvement programmes.
  • Perform cyber risk assessments, security maturity assessments, gap assessments, and control effectiveness reviews.
  • Lead ISO 27001 implementation, certification readiness, Information Security Management System development, Statement of Applicability preparation, internal assurance, and continual improvement.
  • Apply recognised cyber security frameworks including ISO 27001, ISO 27005, NIST Cybersecurity Framework, CIS Controls, and associated risk management standards.
  • Advise clients on regulatory and compliance requirements including UK GDPR, GDPR, NIS2, DORA, Cyber Essentials, and other relevant sector specific obligations.
  • Develop and maintain enterprise cyber risk registers, risk treatment plans, remediation roadmaps, security metrics, Key Risk Indicators, and Key Performance Indicators.
  • Lead third party risk management, supplier security assurance, supply chain risk assessments, and vendor security governance.
  • Develop incident response strategies, Cyber Incident Response Plans, playbooks, escalation procedures, crisis management processes, and tabletop exercises.
  • Provide executive and board level cyber security reporting, translating technical vulnerabilities and threats into business risk, commercial impact, and investment priorities.
  • Work with Security Operations Centres, Managed Detection and Response providers, penetration testing teams, vulnerability management teams, infrastructure teams, and other technical security functions.
  • Provide security oversight across identity and access management, vulnerability management, endpoint security, cloud security, data protection, security monitoring, threat detection, and incident response.
  • Build strong relationships with client executives, technology teams, risk and compliance functions, external auditors, regulators, suppliers, and managed security service providers.
  • Support CyberKainos delivery teams and contribute to the continued development of CyberKainos vCISO, Governance, Risk and Compliance, managed security, and platform capabilities.

Reasons to use Rodeo

I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?

Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.

Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.

Start with a chat, not a search bar

Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.

P

Graduate Consultant — 2026 Scheme

PwC·London, UK
£35,000/yr

Why you're a good match

Strong

Your economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.

See breakdown
Save jobNot relevant
View details

It searches the market for you

Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.

Why you're a good match

You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.

See breakdown
Strong

Experience fit

Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.

See breakdown
Strong

Only hits

No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.

Qualifications and Experience

Essential Experience

  • Significant experience in cyber security, information security, cyber risk management, security governance, or CISO leadership roles.
  • Previous experience operating as a CISO, vCISO, Head of Information Security, Cyber Security Director, Security Consultant, or equivalent senior security leadership position.
  • Demonstrable experience developing and delivering enterprise cyber security strategies and multi year security improvement programmes.
  • Strong practical knowledge of ISO 27001, Information Security Management Systems, NIST Cybersecurity Framework, CIS Controls, and risk management methodologies.
  • Experience conducting cyber security maturity assessments, risk assessments, gap assessments, control reviews, and remediation programmes.
  • Experience developing cyber risk registers, risk treatment plans, security roadmaps, policies, standards, procedures, and governance structures.
  • Strong understanding of third party risk management, supplier assurance, and supply chain cyber security.
  • Practical incident response experience including incident planning, playbook development, tabletop exercises, crisis management, and coordination during live security incidents.
  • Experience working with Security Operations Centres, Managed Detection and Response services, SIEM, EDR, vulnerability management, penetration testing, threat intelligence, and security monitoring capabilities.
  • Proven experience engaging with CEOs, CIOs, CTOs, CFOs, boards, audit committees, risk committees, and other senior stakeholders.
  • Excellent ability to translate technical cyber security issues into business risk, financial exposure, operational impact, and clear executive recommendations.
  • Strong written communication, analytical thinking, stakeholder management, facilitation, presentation, and consulting skills.
  • Ability to manage multiple client engagements and competing priorities while maintaining high standards of delivery.
  • Ability to work regularly from CyberKainos in Windsor and work closely with clients and internal delivery teams.

Get help with your application

Your very own career expert that helps elevate your application to the next level.

Get help applying for this job

Desirable Qualifications

Relevant professional certifications are advantageous, including CISSP, CISM, CRISC, ISO 27001 Lead Auditor, ISO 27001 Lead Implementer, CCSP, or equivalent cyber security and risk management qualifications.

Trusted by 25,000+ job seekers

“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”

Jessica, London

Get help applying for this job

Skills

Cyber Security Strategy
Information Security Governance
Risk Management
ISO 27001 Implementation
Regulatory Compliance
Third Party Risk Management
Incident Response Planning
Security Maturity Assessments
Stakeholder Management
Executive Reporting
NIST Cybersecurity Framework
CIS Controls
GDPR Compliance
Vulnerability Management
Security Operations Oversight
Consulting

Location

England, United Kingdom

Sign up to applySee more jobs like this