Responsibilities
- Define and operate Xebia's cybersecurity capability across prevention, detection, response and recovery.
- Own global incident response, cyber crisis coordination, tabletop exercises, post-incident reviews and remediation tracking.
- Own the security tooling strategy across SIEM, XDR, EDR, SOAR and threat intelligence.
- Drive detection engineering, alert quality, automation and security dashboards.
- Lead vulnerability and continuous exposure management across infrastructure, cloud, endpoints, applications and external-facing assets.
- Drive continuous improvement of Xebia's overall security posture.
- Own identity security and drive Zero Trust adoption, including PAM, conditional access and governance of service accounts and machine identities.
- Own cloud security posture and workload protection across multi-cloud environments, including containers, Kubernetes and infrastructure-as-code.
- Partner with Infrastructure, Applications and AI/Data teams to embed secure-by-design patterns and DevSecOps practices.
- Define and continuously improve minimum security baselines for endpoints, identities, cloud, SaaS, networks, code repositories and AI platforms.
- Evaluate and implement security technologies and controls that effectively address identified risks.
- Own security risk oversight for AI and LLM-based systems, including model and data security, training/fine-tuning data integrity, adversarial robustness, model theft/extraction, prompt injection and misuse.
- Define and enforce security guardrails for agentic AI, including least-privilege access, human-in-the-loop checkpoints, action logging, audit trails and containment controls.
- Assess risks related to third-party foundation models, plugins, MCP servers and agent frameworks.
- Maintain an inventory of AI models and agents in use across the business and assess their security exposure.
- Partner with AI/ML Engineering and platform teams to enable secure adoption of AI-assisted and agentic coding, delivery and client-facing tools.
- Help Xebia continuously adapt its security approach to the rapidly evolving AI threat landscape.
- Own the cybersecurity contribution to business continuity planning and disaster recovery.
- Ensure critical systems and services can be restored within agreed RTO/RPO objectives.
- Drive ransomware resilience through immutable and segmented backups, isolated recovery environments and tested recovery playbooks.
- Lead regular cyber crisis, business continuity and recovery exercises.
- Own protection of Xebia's and clients' intellectual property, source code, proprietary methodologies, AI models, training data and confidential client deliverables.
- Drive DLP, access controls, code repository security and exfiltration monitoring.
- Partner with HR and Legal to manage insider risk throughout the employee and contractor lifecycle.
- Own and continuously evolve Xebia's global cybersecurity transformation roadmap.
- Translate identified risks into concrete technology, process and programme initiatives.
- Lead cybersecurity programmes from definition through implementation, ensuring clear milestones, ownership and measurable outcomes.
- Build business cases and contribute to investment decisions around cybersecurity tooling, capabilities and team growth.
- Establish practical, measurable and enforceable security controls across the organisation.
- Build and develop a global cybersecurity team as the function grows.
- Work effectively with distributed teams and external security partners.
- Support customer security questionnaires, audits and assurance activities.
- Anticipate customer security expectations and translate them into practical security capabilities.
- Contribute to strategic sales opportunities and client engagements.
- Help position Xebia as a trusted technology and security partner.
- Balance security requirements with business and customer needs, finding pragmatic solutions rather than simply applying rigid controls.
- Provide executive and Board-level reporting on cybersecurity posture, threat trends, incidents, remediation status and maturity.
- Communicate complex cybersecurity risks in clear business terms.
- Maintain a risk-based cybersecurity transformation roadmap with quarterly milestones.
- Manage third-party, vendor and software/AI supply chain cyber risk.
- Own the execution of the security awareness programme, including phishing simulations, role-based training and insider risk culture.
- Support customer security assurance activities, audits, certifications and M&A cyber due diligence.
- Work with IT GRC & Assurance and Legal to ensure operational controls meet relevant regulatory obligations, including GDPR, NIS2, DORA and client contractual requirements.
Requirements
- Senior cybersecurity leader with deep operational security, cloud, identity and incident response experience, typically 12+ years in security with 5+ years in a leadership role.
- Track record running or transforming a SOC/detection function and leading enterprise-scale incident response and crisis management.
- Practical experience securing multi-cloud and modern application environments, plus AI models and agentic AI systems — model risk, prompt-level attacks and permissioning/containment of autonomous agents — given Xebia's AI-led business.
- Experience owning business continuity/disaster recovery planning and data loss prevention or IP protection programmes in a technology or professional services setting.
- Able to balance pragmatic delivery with risk reduction and customer assurance.
- Credible with executives, auditors, customers and technical teams; comfortable presenting cyber risk in business terms to the Board.
- Experience leading distributed, multicultural teams across regions.
Nice to Have
- CISSP
- CISM
- GCIH
- GCFA
- CCSP
- OSCP
- Working familiarity with: NIST CSF 2.0, ISO 27001, MITRE ATT&CK, GDPR, NIS2, DORA, OWASP LLM Top 10, OWASP Agentic AI threats, MITRE ATLAS or equivalent hands-on exposure to securing AI models and autonomous agents.
Work Arrangement
Hybrid — Poland, Spain, Bulgaria, Switzerland
What will make you successful
We are particularly interested in cybersecurity leaders who combine: - Strong hands-on technical depth - Cybersecurity programme and transformation leadership - Modern cloud and identity security expertise - Practical AI/LLM and agentic AI security experience - Strong customer orientation - Excellent communication and leadership presence - The ability to operate effectively in a global, distributed environment
Why join Xebia?
This is an opportunity to shape cybersecurity strategy and execution at a global technology company at a time when the security landscape is changing rapidly. You will have the opportunity to: - Shape and build a global cybersecurity capability. - Influence significant investments in security technology and people. - Work at the intersection of cybersecurity, cloud and AI. - Partner directly with executive leadership. - Work with international engineering, AI and delivery teams. - Help define how a global technology company approaches the security of emerging AI and agentic technologies.
Additional Information
- This is a global role based in Europe.
- Open to candidates based in locations such as Poland, Spain, Bulgaria or Switzerland, with other European locations considered on a case-by-case basis.
- The role is designed for a remote/hybrid working model, with the expectation that you can collaborate effectively with distributed teams across Europe and India.