Head of Cybersecurity
Poland and Eastern Europe
| Company | Poland and Eastern Europe |
| Category | Security |
| Location | Bulgaria; Czechia; Hungary; Poland; Romania; Slovakia; Sweden |
| Remote | On-site (inferred) |
| Employment | Not stated |
| Level | Director |
| Salary | Not stated by the employer |
| Posted | 10 Aug 2026 |
| Last verified | 11 Aug 2026 |
| Source | Employer ATS (greenhouse) |
Description
About Xebia
Xebia is a global technology consulting company helping organizations transform through technology, data, cloud, AI and software engineering.
We are looking for a Head of Cybersecurity to lead and further develop Xebia's global cybersecurity capability. Reporting directly to the Chief Information Officer (CIO) , you will play a key role in strengthening our security posture, shaping our cybersecurity transformation roadmap and enabling secure growth across the business.
This is a highly hands-on leadership role . You will combine strategic thinking with operational execution, working closely with technical teams, leadership, Sales and Delivery, while also being comfortable getting into the details when required.
The role is particularly relevant to the rapidly evolving security landscape around AI, LLMs and agentic AI , and we are looking for a leader who can help Xebia understand and address these emerging risks.
What you will do
Cybersecurity Operations & Incident Response
Define and operate Xebia's cybersecurity capability across prevention, detection, response and recovery.
Own global incident response, cyber crisis coordination, tabletop exercises, post-incident reviews and remediation tracking.
Own the security tooling strategy across SIEM, XDR, EDR, SOAR and threat intelligence.
Drive detection engineering, alert quality, automation and security dashboards.
Lead vulnerability and continuous exposure management across infrastructure, cloud, endpoints, applications and external-facing assets.
Drive continuous improvement of Xebia's overall security posture.
Identity, Cloud & Modern Architecture
Own identity security and drive Zero Trust adoption, including PAM, conditional access and governance of service accounts and machine identities.
Own cloud security posture and workload protection across multi-cloud environments, including containers, Kubernetes and infrastructure-as-code.
Partner with Infrastructure, Applications and AI/Data teams to embed secure-by-design patterns and DevSecOps practices.
Define and continuously improve minimum security baselines for endpoints, identities, cloud, SaaS, networks, code repositories and AI platforms.
Evaluate and implement security technologies and controls that effectively address identified risks.
AI, LLM & Agentic AI Security
Own security risk oversight for AI and LLM-based systems, including model and data security, training/fine-tuning data integrity, adversarial robustness, model theft/extraction, prompt injection and misuse.
Define and enforce security guardrails for agentic AI, including least-privilege access, human-in-the-loop checkpoints, action logging, audit trails and containment controls.
Assess risks related to third-party foundation models, plugins, MCP servers and agent frameworks.
Maintain an inventory of AI models and agents in use across the business and assess their security exposure.
Partner with AI/ML Engineering and platform teams to enable secure adoption of AI-assisted and agentic coding, delivery and client-facing tools.
Help Xebia continuously adapt its security approach to the rapidly evolving AI threat landscape.
Cyber Resilience, Business Continuity & Data Protection
Own the cybersecurity contribution to business continuity planning and disaster recovery.
Ensure critical systems and services can be restored within agreed RTO/RPO objectives.
Drive ransomware resilience through immutable and segmented backups, isolated recovery environments and tested recovery playbooks.
Lead regular cyber crisis, business continuity and recovery exercises.
Own protection of Xebia's and clients' intellectual property, source code, proprietary methodologies, AI models, training data and confidential client deliverables.
Drive DLP, access controls, code repository s