GetPro

CISO (Chief Information Security Officer)

Leads the company's security strategy: risk governance, compliance, incident response and security culture.

Why this hire matters.

The CISO turns security from an anxiety-inducing cost center into a commercial advantage. Concretely: without one, your enterprise deals stall on security questionnaires, your certifications (SOC 2, ISO 27001) don't progress, and a ransomware attack can halt the company for weeks. With one, security becomes a sales argument and a condition for a smooth fundraise. The right profile knows how to arbitrate: too lax and the company is exposed; too rigid and the product stalls while teams route around them. In a scale-up, look for a 'builder' CISO able to start from a blank page and speak business risk to the board — not a policy administrator from a large group. NIS2 and the AI Act keep expanding the regulatory scope.

Key missions.

  • Define security strategy and risk governance
  • Drive certifications (ISO 27001, SOC 2) and compliance (GDPR, NIS2)
  • Organize incident response and crisis management
  • Oversee pentests, bug bounty and product security
  • Spread security culture (training, simulated phishing)
  • Answer customer and investor due diligence
  • Report risk posture to exec committee and board

Skills.

Technical skills

  • Risk governance (ISO 27005)
  • Standards and compliance (ISO 27001, SOC 2, GDPR, NIS2)
  • Cloud security architecture
  • Cyber crisis management

Expected qualities

  • Board communication
  • Pragmatism
  • Influence without authority
  • Composure

Common stack

EDR/SIEM (CrowdStrike, Sentinel)Vanta/DrataIAM (Okta)GRC tools

Salaries 2025-2026

LevelExperienceAnnual gross baseAnnual gross package
Deputy CISO / SMB5-8 yrs62–80 k€
CISO scale-up / mid-cap8-12 yrs90–115 k€
Group CISO12+ yrs110–150 k€130–220 k€

Paris market ranges, 2025-2026.

Outside the Paris region, expect 10 to 15 % less.

Sources : Free-Work 2026 · Get in Talent 2026 · ESIC 2026 · Michael Page 2026

Hiring this profile.

Typical background

Typically 15+ years: security engineer or pentester who moved into governance, often via consulting or an IT department. CISSP/CISM common.

When to hire

When security gates the business: enterprise customers, sensitive data, regulated sector — often Series B. Before that, a security lead under the CTO suffices.

Career path

Scale-up CISO → Group CISO → CTO/CIO, cybersecurity advisory or board roles.

Related job profiles.

Contact GetPro