Back to jobs
New

Head of Cybersecurity

Bulgaria; Czechia; Hungary; Poland; Romania; Slovakia; Sweden

About Xebia

Xebia is a global technology consulting company helping organizations transform through technology, data, cloud, AI and software engineering.

We are looking for a Head of Cybersecurity to lead and further develop Xebia's global cybersecurity capability. Reporting directly to the Chief Information Officer (CIO), you will play a key role in strengthening our security posture, shaping our cybersecurity transformation roadmap and enabling secure growth across the business.

This is a highly hands-on leadership role. You will combine strategic thinking with operational execution, working closely with technical teams, leadership, Sales and Delivery, while also being comfortable getting into the details when required.

The role is particularly relevant to the rapidly evolving security landscape around AI, LLMs and agentic AI, and we are looking for a leader who can help Xebia understand and address these emerging risks.

 

What you will do

Cybersecurity Operations & Incident Response

  • Define and operate Xebia's cybersecurity capability across prevention, detection, response and recovery.

  • Own global incident response, cyber crisis coordination, tabletop exercises, post-incident reviews and remediation tracking.

  • Own the security tooling strategy across SIEM, XDR, EDR, SOAR and threat intelligence.

  • Drive detection engineering, alert quality, automation and security dashboards.

  • Lead vulnerability and continuous exposure management across infrastructure, cloud, endpoints, applications and external-facing assets.

  • Drive continuous improvement of Xebia's overall security posture.

Identity, Cloud & Modern Architecture

  • Own identity security and drive Zero Trust adoption, including PAM, conditional access and governance of service accounts and machine identities.

  • Own cloud security posture and workload protection across multi-cloud environments, including containers, Kubernetes and infrastructure-as-code.

  • Partner with Infrastructure, Applications and AI/Data teams to embed secure-by-design patterns and DevSecOps practices.

  • Define and continuously improve minimum security baselines for endpoints, identities, cloud, SaaS, networks, code repositories and AI platforms.

  • Evaluate and implement security technologies and controls that effectively address identified risks.

AI, LLM & Agentic AI Security

  • Own security risk oversight for AI and LLM-based systems, including model and data security, training/fine-tuning data integrity, adversarial robustness, model theft/extraction, prompt injection and misuse.

  • Define and enforce security guardrails for agentic AI, including least-privilege access, human-in-the-loop checkpoints, action logging, audit trails and containment controls.

  • Assess risks related to third-party foundation models, plugins, MCP servers and agent frameworks.

  • Maintain an inventory of AI models and agents in use across the business and assess their security exposure.

  • Partner with AI/ML Engineering and platform teams to enable secure adoption of AI-assisted and agentic coding, delivery and client-facing tools.

  • Help Xebia continuously adapt its security approach to the rapidly evolving AI threat landscape.

Cyber Resilience, Business Continuity & Data Protection

  • Own the cybersecurity contribution to business continuity planning and disaster recovery.

  • Ensure critical systems and services can be restored within agreed RTO/RPO objectives.

  • Drive ransomware resilience through immutable and segmented backups, isolated recovery environments and tested recovery playbooks.

  • Lead regular cyber crisis, business continuity and recovery exercises.

  • Own protection of Xebia's and clients' intellectual property, source code, proprietary methodologies, AI models, training data and confidential client deliverables.

  • Drive DLP, access controls, code repository security and exfiltration monitoring.

  • Partner with HR and Legal to manage insider risk throughout the employee and contractor lifecycle.

Security Programme & Transformation Leadership

  • Own and continuously evolve Xebia's global cybersecurity transformation roadmap.

  • Translate identified risks into concrete technology, process and programme initiatives.

  • Lead cybersecurity programmes from definition through implementation, ensuring clear milestones, ownership and measurable outcomes.

  • Build business cases and contribute to investment decisions around cybersecurity tooling, capabilities and team growth.

  • Establish practical, measurable and enforceable security controls across the organisation.

  • Build and develop a global cybersecurity team as the function grows.

  • Work effectively with distributed teams and external security partners.

Customer & Business Orientation

Cybersecurity at Xebia is also a business and revenue enabler.

You will work closely with Sales, Delivery, Solutions and technical teams to:

  • Support customer security questionnaires, audits and assurance activities.

  • Anticipate customer security expectations and translate them into practical security capabilities.

  • Contribute to strategic sales opportunities and client engagements.

  • Help position Xebia as a trusted technology and security partner.

  • Balance security requirements with business and customer needs, finding pragmatic solutions rather than simply applying rigid controls.

Executive Leadership & Assurance

  • Provide executive and Board-level reporting on cybersecurity posture, threat trends, incidents, remediation status and maturity.

  • Communicate complex cybersecurity risks in clear business terms.

  • Maintain a risk-based cybersecurity transformation roadmap with quarterly milestones.

  • Manage third-party, vendor and software/AI supply chain cyber risk.

  • Own the execution of the security awareness programme, including phishing simulations, role-based training and insider risk culture.

  • Support customer security assurance activities, audits, certifications and M&A cyber due diligence.

  • Work with IT GRC & Assurance and Legal to ensure operational controls meet relevant regulatory obligations, including GDPR, NIS2, DORA and client contractual requirements.

 

What we are looking for

Experience & credibility

  • Senior cybersecurity leader with deep operational security, cloud, identity and incident response experience, typically 12+ years in security with 5+ years in a leadership role.

  • Track record running or transforming a SOC/detection function and leading enterprise-scale incident response and crisis management.

  • Practical experience securing multi-cloud and modern application environments, plus AI models and agentic AI systems — model risk, prompt-level attacks and permissioning/containment of autonomous agents — given Xebia's AI-led business.

  • Experience owning business continuity/disaster recovery planning and data loss prevention or IP protection programmes in a technology or professional services setting.

  • Able to balance pragmatic delivery with risk reduction and customer assurance.

  • Credible with executives, auditors, customers and technical teams; comfortable presenting cyber risk in business terms to the Board.

  • Experience leading distributed, multicultural teams across regions.

Certifications & knowledge

Indicative certifications include:

  • CISSP

  • CISM

  • GCIH

  • GCFA

  • CCSP

  • OSCP

Certifications are not the only measure of expertise — practical experience and the ability to implement and lead are critical.

Working familiarity with:

  • NIST CSF 2.0

  • ISO 27001

  • MITRE ATT&CK

  • GDPR

  • NIS2

  • DORA

  • OWASP LLM Top 10

  • OWASP Agentic AI threats

  • MITRE ATLAS

or equivalent hands-on exposure to securing AI models and autonomous agents.

 

What will make you successful

We are particularly interested in cybersecurity leaders who combine:

  • Strong hands-on technical depth

  • Cybersecurity programme and transformation leadership

  • Modern cloud and identity security expertise

  • Practical AI/LLM and agentic AI security experience

  • Strong customer orientation

  • Excellent communication and leadership presence

  • The ability to operate effectively in a global, distributed environment

You will initially work closely with existing cybersecurity resources and will have the opportunity to build and grow the global security team as Xebia continues to invest significantly in cybersecurity capabilities and technology.

 

Location & working model

This is a global role based in Europe.

We are open to candidates based in locations such as Poland, Spain, Bulgaria or Switzerland, with other European locations considered on a case-by-case basis.

The role is designed for a remote/hybrid working model, with the expectation that you can collaborate effectively with distributed teams across Europe and India.

 

Why join Xebia?

This is an opportunity to shape cybersecurity strategy and execution at a global technology company at a time when the security landscape is changing rapidly.

You will have the opportunity to:

  • Shape and build a global cybersecurity capability.

  • Influence significant investments in security technology and people.

  • Work at the intersection of cybersecurity, cloud and AI.

  • Partner directly with executive leadership.

  • Work with international engineering, AI and delivery teams.

  • Help define how a global technology company approaches the security of emerging AI and agentic technologies.

Apply for this job

*

indicates a required field

Phone
Resume/CV*

Accepted file types: pdf, doc, docx, txt, rtf

Cover Letter

Accepted file types: pdf, doc, docx, txt, rtf


Select...
Select...
Select...
Select...
Select...
Select...
Select...