Overview
In this role you will define and drive Cognism’s technical security strategy for web and data products, data fusion pipelines, and corporate systems. You will partner with engineering and product leaders to embed security-by-design, mature secure SDLC, and elevate operational security. You will shape the security program to support AI, scale, and velocity while protecting crown jewels like data and the fusion engine. This is a chance to build a measurable, long-term security maturity roadmap and lead a high-performing security engineering team.
Responsibilities
- Define and own Cognism’s technical security strategy aligned with engineering velocity
- Direct secure SDLC adoption, threat modelling, CI/CD security, and vulnerability management
- Oversee risk-driven supply chain security for products
- Collaborate with IT operations to maintain strong corporate security posture and guardrails
- Lead and mentor application and infrastructure security engineers
- Establish a security culture where developers engage early in threat modeling and remediation
- Manage external security partners (SOC, pen testing) and ensure accountability
- Partner with data and AI leaders to secure data pipelines, enrichment engine, and AI integrations
- Align security practices with 24/7 SOC operations and SIEM enhancements
- Develop incident response playbooks and a trusted escalation process
Key requirements
- Experience building security programmes in product-led, engineering-first environments
- Ability to communicate risk to executives and engineers with precision
- Hands-on AppSec expertise (OWASP, API security, SAST/DAST, SDLC)
- Practical threat modelling experience and ability to coach senior engineers
- Knowledge of data security, cloud data warehouses, and pipeline integrity
- Cloud security fluency, container/Kubernetes security, IAM design, and cloud-native tools
- Familiarity with AI/LLM security risks and guardrails
- Proven leadership and partnership with engineering leadership
- Experience managing external security partners and improving performance
- Influential leadership and stakeholder management
- Strategic thinking with risk-based prioritization
- Collaborative and cross-functional communication
- Application security (OWASP, API security)
- Threat modelling
- SAST/DAST
…
