CISO jobs · Chief information security officer vacancies · Permanent, interim and fractional
CISO jobs · permanent, interim and fractional
CISO jobs are chief information security officer roles: the most senior security seat in a company, setting its information and cyber security strategy, owning security risk and telling the board how exposed the business is. They come as permanent full-time posts, interim assignments, and fractional or virtual seats held for set days. The board below shows the CISO roles on our board, with permanent roles first where the posting says full-time.
We recruit permanent, interim, fractional and part-time technology and security leaders, and non-executive directors. Hiring rather than looking? On every brief we send a shortlist of 3–5, each with pay or day rate, availability and IR35 position set out.
How a brief runswhat we undertake
- 01Brief30-MINUTE SCOPING CALLDay 0
- 02Shortlist of 3–5VETTED · RATE BENCHMARK · IR35After the brief
- 03InterviewsYOU MEET THE SHORTLISTYour diary
- 04Scoped startFIRST-MONTH OUTCOMES AGREEDYou set the date
- 05Fractional, interim and permanentIR35 POSITION SET OUTOn every brief
Shortlist3–5
15 minutes · video or phone
Book 15 minutes to hire a CISO
Tell us the scope and the days a week. We come back with CISO candidates, their day rates and availability.
- 0115 minutes, video or phone
- 02We scope the role and the days a week
- 03A shortlist of 3–5 after the call
- 04Fractional, interim and permanent briefs
Pick a day that suits · live availability
On the board · last 3 months
CISO jobs jobs on the board
Current CISO roles on our board
How fractional recruitment agencies compare is set out in one place, including how we work: a CISO brief and a shortlist of three to five.
01/ the role
CISO jobs: what the board holds
The board on this page holds the CISO roles on our board: chief information security officer, head of information security at board level and CISO roles in every mode of work. Roles whose posting says full-time come first. Interim, fractional and virtual CISO roles follow, and where a posting states how the role is engaged, the listing says so. When there are few CISO roles, the board widens to the CIO and CTO seats beside it, and says that it has.
What the seat does
The Government Digital and Data framework says a chief information security officer creates an environment and culture that keeps the organisation’s information and technology secure: setting the security strategy, judging how mature security is today, advising the board on risk, and making sure the organisation can detect, respond to and recover from an attack. For the day-to-day picture, see what a CISO does.
One seat, several ways to hold it
A permanent CISO is employed full-time and owns security for years. An interim CISO holds the seat for a fixed period, to cover a departure, lead the response to an incident or carry a certification. A fractional CISO holds it for agreed days a week, often in a business that needs a named security lead for customers, insurers or a regulator before it can carry a full-time salary. The job title is the same; the contract, the days and the tax position are not.
Where the seat reports
A CISO may report to the CIO, the CTO, the chief risk officer or the CEO. Reporting to IT puts security close to the systems; reporting outside IT gives it independence from the people it checks. The posting should say which. The seats beside it are listed under CIO jobs and CTO jobs.
02/ scope
How to get a CISO job
1. Build depth in security first
Most CISOs come up through security operations, security architecture, risk and audit, or consulting, then lead a security team before taking the whole seat. Breadth matters: a CISO answers for people, process and technology, not one specialism. The cyber security assessment and ISO 27001 consultant pages show the kind of work the seat directs.
2. Hold the certifications postings ask for
Two certifications appear on many CISO postings. ISC2’s CISSP recognises the knowledge to lead an organisation’s information security programme, needs paid work experience across its domains, and names the CISO among the roles that hold it. ISACA’s CISM covers information security governance, risk management, the security programme and incident management. In the UK, the UK Cyber Security Council, established by Royal Charter, awards professional titles from Associate to Chartered, with Cyber Security Governance and Risk Management among its specialisms.
3. Show the board work
A CISO shortlist is decided on how well you brief a board. The government’s Cyber Governance Code of Practice sets out the governance actions directors of medium and large organisations are responsible for, and the NCSC’s Cyber Security Toolkit for Boards explains how to carry them out. The NCSC’s 10 Steps to Cyber Security is written for organisations with someone dedicated to managing cyber security: that someone is often the CISO.
4. Pick the route in
Not every CISO job is permanent. Interim CISO jobs cover a gap or an incident for a set period; fractional CISO jobs and virtual CISO jobs hold the seat for set days a week. If you work through your own company, the off-payroll working rules (IR35) may apply: status turns on how the engagement runs, and a medium or large client makes the determination. Our IR35 guide sets out the tests.
03/ related roles
CISO jobs by type
Every page we keep for the CISO seat, one per kind of role or question. We recruit permanent, interim, fractional and part-time CISOs.
04/ vetting
How we vet CISOs
What we undertake on every brief, before a candidate reaches you.
- 01
Qualification screen
Verify CISO tenure, sector context and stage fit.
SOURCING - 02
Mandate fit
Match to your situation — stage, board dynamics, timing.
MATCHING - 03
Reference deep-dive
We take references ourselves, from recent past clients — real outcomes, not titles.
VERIFY - 04
Shortlist
Three to five candidates with day rate, availability and IR35 position set out.
SHORTLIST OF 3–5
05/ chief information security officer jobs
Chief information security officer jobs the seat and its titles
Chief information security officer jobs are advertised under several titles. Chief information security officer and CISO are the same seat; head of information security, head of cyber security and director of security are often the same work in a smaller business, or the level below it in a larger one. Group CISO runs security across a group of companies.
Read the posting for what the seat owns: security strategy and risk, the security operations team, governance and certification, incident response, or all of them. Ask whether the seat owns a budget and a team, or advises others who do. A CISO who can only advise has a different job from one who can act.
Ask how the seat meets the board. Under the government’s cyber governance code, directors are responsible for cyber risk; a CISO who briefs the board directly has a different standing from one whose reports pass through IT.
06/ permanent ciso jobs
Permanent CISO jobs the market and the pay
Permanent CISO jobs are full-time employed roles, and they are the ones listed first on this page. Robert Half’s 2026 salary guide puts a full-time CISO in London at £131,000 at the 25th percentile, £184,000 at the median and £220,000 at the 75th percentile (Robert Half, London). Robert Half is a recruiter, these are its own starting-salary projections, and they are London figures, not a national rate.
Base pay is one part of a permanent package. Bonus, pension, on-call arrangements and notice period vary with the sector, and regulated sectors such as financial services ask more of the seat. For the pay picture across permanent, interim and fractional seats, see our CISO salary guide.
Some businesses do not need a full-time CISO yet. If the work fills a day or two a week, a fractional or virtual CISO may be the honest answer; see fractional CISO services for how that seat is scoped.
07/ questions
CISO jobs FAQ
The questions people ask before bringing in a CISO.

Book 15 minutes · shortlist of 3–5
Bring the brief. We architect the team.
A shortlist of 3–5 with day rate, availability and IR35 position set out, after five-stage vetting.
