CISO jobs · Chief information security officer vacancies · Permanent, interim and fractional

CISO jobs · permanent, interim and fractional

CISO jobs are chief information security officer roles: the most senior security seat in a company, setting its information and cyber security strategy, owning security risk and telling the board how exposed the business is. They come as permanent full-time posts, interim assignments, and fractional or virtual seats held for set days. The board below shows the CISO roles on our board, with permanent roles first where the posting says full-time.

We recruit permanent, interim, fractional and part-time technology and security leaders, and non-executive directors. Hiring rather than looking? On every brief we send a shortlist of 3–5, each with pay or day rate, availability and IR35 position set out.

How a brief runswhat we undertake

  1. 01Brief30-MINUTE SCOPING CALLDay 0
  2. 02Shortlist of 3–5VETTED · RATE BENCHMARK · IR35After the brief
  3. 03InterviewsYOU MEET THE SHORTLISTYour diary
  4. 04Scoped startFIRST-MONTH OUTCOMES AGREEDYou set the date
  5. 05Fractional, interim and permanentIR35 POSITION SET OUTOn every brief

Shortlist3–5

3–5
Shortlist · with pay or day rate, availability and IR35 set out
5
Vetting · stages before a candidate reaches a client
£184,000
Full-time CISO salary, London median · 50th percentile
Robert Half, 2026

15 minutes · video or phone

Book 15 minutes to hire a CISO

Tell us the scope and the days a week. We come back with CISO candidates, their day rates and availability.

  1. 0115 minutes, video or phone
  2. 02We scope the role and the days a week
  3. 03A shortlist of 3–5 after the call
  4. 04Fractional, interim and permanent briefs
Prefer email? Use the booking page →

Pick a day that suits · live availability

Current CISO roles on our board

How fractional recruitment agencies compare is set out in one place, including how we work: a CISO brief and a shortlist of three to five.

01/ the role

CISO jobs: what the board holds

The board on this page holds the CISO roles on our board: chief information security officer, head of information security at board level and CISO roles in every mode of work. Roles whose posting says full-time come first. Interim, fractional and virtual CISO roles follow, and where a posting states how the role is engaged, the listing says so. When there are few CISO roles, the board widens to the CIO and CTO seats beside it, and says that it has.

What the seat does

The Government Digital and Data framework says a chief information security officer creates an environment and culture that keeps the organisation’s information and technology secure: setting the security strategy, judging how mature security is today, advising the board on risk, and making sure the organisation can detect, respond to and recover from an attack. For the day-to-day picture, see what a CISO does.

One seat, several ways to hold it

A permanent CISO is employed full-time and owns security for years. An interim CISO holds the seat for a fixed period, to cover a departure, lead the response to an incident or carry a certification. A fractional CISO holds it for agreed days a week, often in a business that needs a named security lead for customers, insurers or a regulator before it can carry a full-time salary. The job title is the same; the contract, the days and the tax position are not.

Where the seat reports

A CISO may report to the CIO, the CTO, the chief risk officer or the CEO. Reporting to IT puts security close to the systems; reporting outside IT gives it independence from the people it checks. The posting should say which. The seats beside it are listed under CIO jobs and CTO jobs.

02/ scope

How to get a CISO job

1. Build depth in security first

Most CISOs come up through security operations, security architecture, risk and audit, or consulting, then lead a security team before taking the whole seat. Breadth matters: a CISO answers for people, process and technology, not one specialism. The cyber security assessment and ISO 27001 consultant pages show the kind of work the seat directs.

2. Hold the certifications postings ask for

Two certifications appear on many CISO postings. ISC2’s CISSP recognises the knowledge to lead an organisation’s information security programme, needs paid work experience across its domains, and names the CISO among the roles that hold it. ISACA’s CISM covers information security governance, risk management, the security programme and incident management. In the UK, the UK Cyber Security Council, established by Royal Charter, awards professional titles from Associate to Chartered, with Cyber Security Governance and Risk Management among its specialisms.

3. Show the board work

A CISO shortlist is decided on how well you brief a board. The government’s Cyber Governance Code of Practice sets out the governance actions directors of medium and large organisations are responsible for, and the NCSC’s Cyber Security Toolkit for Boards explains how to carry them out. The NCSC’s 10 Steps to Cyber Security is written for organisations with someone dedicated to managing cyber security: that someone is often the CISO.

4. Pick the route in

Not every CISO job is permanent. Interim CISO jobs cover a gap or an incident for a set period; fractional CISO jobs and virtual CISO jobs hold the seat for set days a week. If you work through your own company, the off-payroll working rules (IR35) may apply: status turns on how the engagement runs, and a medium or large client makes the determination. Our IR35 guide sets out the tests.

03/ related roles

CISO jobs by type

Every page we keep for the CISO seat, one per kind of role or question. We recruit permanent, interim, fractional and part-time CISOs.

04/ vetting

How we vet CISOs

What we undertake on every brief, before a candidate reaches you.

  1. 01

    Qualification screen

    Verify CISO tenure, sector context and stage fit.

    SOURCING
  2. 02

    Mandate fit

    Match to your situation — stage, board dynamics, timing.

    MATCHING
  3. 03

    Reference deep-dive

    We take references ourselves, from recent past clients — real outcomes, not titles.

    VERIFY
  4. 04

    Shortlist

    Three to five candidates with day rate, availability and IR35 position set out.

    SHORTLIST OF 3–5

05/ chief information security officer jobs

Chief information security officer jobs the seat and its titles

Chief information security officer jobs are advertised under several titles. Chief information security officer and CISO are the same seat; head of information security, head of cyber security and director of security are often the same work in a smaller business, or the level below it in a larger one. Group CISO runs security across a group of companies.

Read the posting for what the seat owns: security strategy and risk, the security operations team, governance and certification, incident response, or all of them. Ask whether the seat owns a budget and a team, or advises others who do. A CISO who can only advise has a different job from one who can act.

Ask how the seat meets the board. Under the government’s cyber governance code, directors are responsible for cyber risk; a CISO who briefs the board directly has a different standing from one whose reports pass through IT.

06/ permanent ciso jobs

Permanent CISO jobs the market and the pay

Permanent CISO jobs are full-time employed roles, and they are the ones listed first on this page. Robert Half’s 2026 salary guide puts a full-time CISO in London at £131,000 at the 25th percentile, £184,000 at the median and £220,000 at the 75th percentile (Robert Half, London). Robert Half is a recruiter, these are its own starting-salary projections, and they are London figures, not a national rate.

Base pay is one part of a permanent package. Bonus, pension, on-call arrangements and notice period vary with the sector, and regulated sectors such as financial services ask more of the seat. For the pay picture across permanent, interim and fractional seats, see our CISO salary guide.

Some businesses do not need a full-time CISO yet. If the work fills a day or two a week, a fractional or virtual CISO may be the honest answer; see fractional CISO services for how that seat is scoped.

07/ questions

CISO jobs FAQ

The questions people ask before bringing in a CISO.

On this page: the board shows the CISO roles on our board, permanent roles first where the posting says full-time, then interim, fractional and virtual. Each kind of CISO role also has its own page, from interim CISO jobs to fractional CISO jobs.
Roles leading a company’s information and cyber security: the strategy, security risk, the security team, incident response and reporting to the board. The Government Digital and Data framework describes the chief information security officer as the person who creates the environment and culture that keep information and technology secure.
Robert Half’s 2026 guide puts a full-time CISO in London at £131,000 (25th percentile), £184,000 (median) and £220,000 (75th percentile) (Robert Half). Interim, fractional and virtual CISOs are paid by the day; see our CISO salary page.
Build depth in security operations, architecture or risk, lead a security team, and learn to brief a board in plain terms. Many postings ask for CISSP or CISM. Interim, fractional and virtual CISO roles are another way into the seat.
It is not a legal requirement. It is one of the certifications CISO postings commonly name, with ISACA’s CISM beside it. The UK Cyber Security Council also awards chartered status for the profession. Check what each posting asks for; some regulated employers name a specific certification.
The CIO runs the systems and IT the business depends on; the CISO protects them and the information in them, and often checks the CIO’s own work. In smaller companies the CIO or CTO may hold security as part of the job. See CIO jobs for that seat.
It depends on how the engagement runs in practice, not on its label. In most cases a medium or large client makes the determination; for a small client outside the public sector, the worker’s own company decides (HMRC). We set out each candidate’s IR35 position on the shortlist and do not promise an outcome.
Decide whether the seat is permanent, interim or for set days a week, then write down what it owns, who it reports to and whether it briefs the board. To hire a CISO for part of the week, start with the fractional CISO hub. On every brief we send a shortlist of 3–5 after five-stage vetting.

Book 15 minutes · shortlist of 3–5

Bring the brief. We architect the team.

A shortlist of 3–5 with day rate, availability and IR35 position set out, after five-stage vetting.

For executives

Your next role, read against your repo.

Sign up now →Browse the board

  1. Build your repo once; every job on the board is read against it
  2. Fractional, interim, part-time, permanent and board roles
  3. Nothing goes on your repo until you confirm it
  4. A call when it suits you — five minutes, then it is written down for your yes
Fractional Quest logo — how to hire a CISO, CISO jobs