CISO (Chief Information Security Officer)
Leads the company's security strategy: risk governance, compliance, incident response and security culture.
Why this hire matters.
The CISO turns security from an anxiety-inducing cost center into a commercial advantage. Concretely: without one, your enterprise deals stall on security questionnaires, your certifications (SOC 2, ISO 27001) don't progress, and a ransomware attack can halt the company for weeks. With one, security becomes a sales argument and a condition for a smooth fundraise. The right profile knows how to arbitrate: too lax and the company is exposed; too rigid and the product stalls while teams route around them. In a scale-up, look for a 'builder' CISO able to start from a blank page and speak business risk to the board — not a policy administrator from a large group. NIS2 and the AI Act keep expanding the regulatory scope.
Key missions.
- Define security strategy and risk governance
- Drive certifications (ISO 27001, SOC 2) and compliance (GDPR, NIS2)
- Organize incident response and crisis management
- Oversee pentests, bug bounty and product security
- Spread security culture (training, simulated phishing)
- Answer customer and investor due diligence
- Report risk posture to exec committee and board
Skills.
Technical skills
- Risk governance (ISO 27005)
- Standards and compliance (ISO 27001, SOC 2, GDPR, NIS2)
- Cloud security architecture
- Cyber crisis management
Expected qualities
- Board communication
- Pragmatism
- Influence without authority
- Composure
Common stack
Salaries 2025-2026
| Level | Experience | Annual gross base | Annual gross package |
|---|---|---|---|
| Deputy CISO / SMB | 5-8 yrs | 62–80 k€ | — |
| CISO scale-up / mid-cap | 8-12 yrs | 90–115 k€ | — |
| Group CISO | 12+ yrs | 110–150 k€ | 130–220 k€ |
Paris market ranges, 2025-2026.
Outside the Paris region, expect 10 to 15 % less.
Sources : Free-Work 2026 · Get in Talent 2026 · ESIC 2026 · Michael Page 2026
Hiring this profile.
Typical background
Typically 15+ years: security engineer or pentester who moved into governance, often via consulting or an IT department. CISSP/CISM common.
When to hire
When security gates the business: enterprise customers, sensitive data, regulated sector — often Series B. Before that, a security lead under the CTO suffices.
Career path
Scale-up CISO → Group CISO → CTO/CIO, cybersecurity advisory or board roles.