Location: Western Europe, remote first, with regular travel across Europe and availability to travel to Ukraine
Reports to: CEO / Executive Leadership Team
Type: Full-time
About Occam
Occam Industries is a British defence-tech company building hardware-agnostic autonomous AI software for military drones. Our AI pilot, OccamX, turns existing, mass-produced aerial platforms into autonomous systems: software-only, running on cheap commodity hardware, and integrating into the supply chains our customers already use.
We work directly with OEMs and defence partners to get capability to the field at speed and scale.
That work is being proven on the front line in Ukraine right now. Our team operates close to the reality of modern warfare, where security, speed, discretion and reliability are not theoretical. They are the conditions that allow the mission to stand up.
Working with Occam
We believe the only defence technology that matters is the kind that changes outcomes on the battlefield. That means we move quickly, work pragmatically, and stay close to the people who use what we build.
The work is sensitive, fast-moving and operationally serious. We need a security leader who understands that security is not just a policy set, an audit trail or a compliance exercise. It is how we protect our people, our systems, our partners, our customers and the mission itself.
This role is for someone who can operate at senior level while staying close enough to the ground to know what is really happening. Someone calm, discreet and credible. Someone who can build trust with engineers, executives, partners and defence stakeholders. Someone who knows when to apply structure, when to move fast, and when to draw a hard line.
The Role
We are looking for a Chief Information Security Officer to lead Occam’s security strategy, governance, risk management and operational security across a high-trust, defence-tech environment.
The CISO will be accountable for protecting Occam’s people, information, systems, products, supply chain and operating model. You will set the security direction for the organisation, build the controls and assurance processes we need, and ensure Occam can operate credibly with government, defence, enterprise and NATO-aligned stakeholders.
This is a senior leadership role, but it is not a purely theoretical one. Occam is scaling quickly, the environment is complex, and the work connects directly to Ukraine. You will need to be comfortable moving between board-level security strategy, hands-on risk decisions, technical security conversations and practical operational judgement.
The successful candidate must be based in Western Europe, eligible to obtain and maintain security clearance through their own host country, and eligible for NATO-related clearance where required. They must also be willing and able to travel to Ukraine.
What You’ll Own
Security leadership and strategy
● Define and lead Occam’s information security strategy, roadmap and operating model.
● Act as the senior security advisor to the CEO, executive team, board and relevant client stakeholders.
● Build a pragmatic, risk-based security culture across the organisation.
● Ensure security enables the business without creating unnecessary operational friction.
● Own security priorities, tooling, budget, resourcing and maturity planning.
● Support Occam’s credibility with defence, government and NATO-aligned partners.
Governance, risk and compliance
● Develop and maintain Occam’s security governance framework, policies and standards.
● Lead risk assessments across technology, people, suppliers and operations.
● Ensure alignment with relevant standards such as ISO 27001, NIST, Cyber Essentials Plus, SOC 2 or equivalent frameworks where appropriate.
● Oversee internal audits, external audits, client security reviews and assurance activity.
● Lead preparation for government, defence and NATO-aligned security requirements.
● Ensure appropriate handling of sensitive, restricted or classified information.
Security operations
● Oversee security monitoring, incident response and threat detection.
● Own the incident response framework, including escalation, communication and post-incident review.
● Ensure Occam has robust business continuity, disaster recovery and crisis response plans.
● Lead vulnerability management, penetration testing and remediation tracking.
● Ensure endpoint, identity, cloud, network and application security controls are effective and proportionate.
● Maintain clear escalation paths for security issues affecting Ukraine operations, travel, infrastructure or sensitive work.
Product, engineering and cloud security
● Work closely with product and engineering teams to embed security into the software development lifecycle.
● Review architecture, cloud environments and technical designs from a security perspective.
● Support secure development practices, code review standards, secrets management and dependency risk management.
● Ensure security requirements are built into product design, delivery and release processes.
● Provide guidance on secure AI, data protection and emerging technology risks where relevant.
● Help engineering teams move quickly without creating unacceptable security exposure.
Operational security and Ukraine-related risk
● Develop and maintain practical operational security standards for a defence-tech company working with Ukraine.
● Support secure communications, access management, information handling and travel security.
● Work with relevant teams to assess risks linked to Ukraine travel, local operations and partner engagement.
● Ensure staff understand the security expectations that apply to their role and location.
● Support crisis response planning for travel, operational disruption, cyber incidents and sensitive stakeholder matters.
● Act as a trusted leader during periods of heightened security risk.
Supplier and third-party security
● Own the third-party security risk framework.
● Assess and manage risk across vendors, contractors, partners and critical suppliers.
● Ensure appropriate contractual security obligations, assurance requirements and access controls are in place.
● Support due diligence for sensitive partnerships, procurement activity and client engagements.
● Work with operations and finance colleagues to ensure supplier decisions reflect security requirements.
People, culture and clearance readiness
● Lead security awareness, role-based training and executive-level security briefings.
● Support clearance readiness for relevant people, projects and client engagements.
● Build clear expectations around confidentiality, discretion and secure working.
● Ensure security is understood as part of how Occam operates, not as a separate function that sits outside the work.
● Create a culture where people raise risks early, make good decisions and understand the seriousness of the environment.
About You
You are an experienced security leader who can operate in a sensitive, fast-moving and high-trust environment.
You are not looking for a role where security sits in a corner producing policies that nobody reads. You want to build the security backbone of a company working on technology that genuinely matters.
You are calm under pressure, discreet by nature and confident enough to challenge senior people when the risk requires it. You understand that defence-tech needs discipline, but you also understand that speed matters. You know how to balance both.
You are comfortable working with ambiguity, imperfect information and changing priorities. You can move between strategic leadership and practical delivery without losing credibility in either space.
Required Experience
● Significant experience in senior information security leadership, ideally as a CISO, Deputy CISO, Head of Security or equivalent.
● Experience operating in high-trust, regulated, defence, government, critical infrastructure or security-sensitive environments.
● Strong understanding of security governance, risk management, assurance and compliance.
● Hands-on understanding of cloud security, identity and access management, endpoint security and secure software development.
● Experience preparing organisations for external audit, client security review or formal certification.
● Strong incident management experience, including executive-level communication during security events.
● Experience working with senior stakeholders, boards, clients and technical teams.
● Ability to balance strategic leadership with practical execution.
Clearance, Location and Travel Requirements
● Must be based in Western Europe.
● Must be eligible to work from their country of residence.
● Must be eligible to obtain and maintain security clearance through their own host country or relevant national authority.
● Must be eligible for NATO-related clearance where required.
● Existing national, government, defence or NATO clearance would be highly advantageous.
● Must be willing and able to travel across Europe.
● Must be available to travel to Ukraine, subject to business need, security assessment and appropriate travel protocols.
● Must be able to work in environments requiring strict confidentiality, discretion and operational security.
Desirable Experience
● Experience in defence technology, cyber security, intelligence, military technology or dual-use technology.
● Experience with NATO, EU, UK, national government or defence procurement requirements.
● Knowledge of classified information handling, secure facilities, secure communications or operational security.
● Experience building a security function in a scaling organisation.
● Relevant certifications such as CISSP, CISM, CISA, CCSP, ISO 27001 Lead Implementer or equivalent.
● Experience supporting teams operating in or around conflict zones.
● Familiarity with security requirements for autonomous systems, AI products, drones or mission-critical software.
Personal Attributes
● Calm, credible and decisive under pressure.
● Highly discreet, trustworthy and security-aware.
● Commercially aware and pragmatic.
● Able to explain complex security topics clearly to non-technical leaders.
● Comfortable working in ambiguous, fast-moving and sensitive environments.
● High integrity and strong judgement.
● Able to challenge constructively and make difficult recommendations when required.
● Strong written and verbal communication skills.
● Comfortable working with teams across the UK, Western Europe and Ukraine.
Why This Role
Most CISO roles protect a company.
This one protects a mission.
You will be responsible for the security backbone of a defence-tech company building software that is being tested against the realities of modern warfare. The work is serious, the environment is sensitive, and the expectations are high.
If you want a polished corporate security role, this is probably not it. If you want to build the security function for a company where speed, trust, discretion and operational judgement really matter, this is the role.