At IBM Software, we transform client challenges into solutions. Building the world’s leading AI-powered, cloud-native products that shape the future of business and society. Our legacy of innovation creates endless opportunities for IBMers to learn, grow, and make an impact on a global scale. Working in Software means joining a team fueled by curiosity and collaboration. You’ll work with diverse technologies, partners, and industries to design, develop, and deliver solutions that power digital transformation. With a culture that values innovation, growth, and continuous learning, IBM Software places you at the heart of IBM’s product and technology landscape. Here, you’ll have the tools and opportunities to advance your career while creating software that changes the world. Confluent is pioneering a fundamentally new category of data infrastructure focused on data in motion. Have you ever found a new favorite series on Netflix, picked up groceries curbside at Walmart, or paid for something using Square? That’s the power of data in motion in action—giving organisations instant access to the massive amounts of data that is constantly flowing throughout their business. At Confluent, we’re building the foundational platform for this new paradigm of data infrastructure. Our cloud-native offering is designed to be the intelligent connective tissue enabling real-time data, from multiple sources, to constantly stream across the organisation. With Confluent, organisations can create a central nervous system to innovate and win in a digital-first world. About the Role The Office of the CISO (OCISO) is part of Confluent’s Trust and Security organisation and its mission is to earn and retain trust by championing Confluent’s security, privacy, resilience, and compliance positions, thereby accelerating customer adoption and use of our platform and products. We are looking for an individual who will partner with Confluent's customers to ensure that we build the most trustworthy platform that meets security, compliance, and privacy requirements. Success in this role will be finding the best solution not only with the current technologies and practices we currently have on hand, but defining new opportunities for product development, customer engagement strategy, audit and access transparency, and field enablement. While this role will engage with leadership frequently, we also expect the individual in this role to roll up their sleeves to get things done. The OCISO Trust Lead will “lead by influence”, and oversee and drive trust (security, privacy, resilience and compliance) related customer engagements and interactions. The EMEA OCISO Trust Lead will partner cross-functionally with Sales, Customer Solutions Group, Product, Engineering and Legal teams to provide assurance to customers on Confluent’s security and compliance posture, enable contract reviews and negotiations, and drive externally facing communications with customers. This position is a remote-based position. Primary Responsibilities: ● Drive execution of customer trust engagements and interactions to provide context about Confluent's security and compliance posture and negotiate security terms when necessary ● Propose and partner with product, engineering, and security teams to design security and compliance solutions and frameworks to meet customer requirements ● Coach and mentor field and security staff on customer security needs and requirements ● Be a subject matter expert for the company around customer security assurance, and develop and demonstrate POVs on important existing and emerging regulatory positions impacting cloud service adoption ● Build and scale key internal capabilities and programs required to drive customer enablement interactions ● Maintain relations with internal teams such as Sales, CSG, Product, Engineering and Legal to drive and enable programs required to build trust with customers ● 8 years’ experience in Information Security and Compliance ● Customer-facing experience at a cloud provider or consulting firm ● Experience at a cloud or SaaS provider or as a customer of a cloud or SaaS provider with complex & demanding security and compliance requirements ● Experience with a combination of the following: ISO 27001, HITRUST, SOC2, CSA, NIST, etc. ● Architectural familiarity across multiple security domains (e.g., identity and access management, data protection, network security, cloud infrastructure) with the ability to synthesize across domains and recommend practical solutions to complex customer security problems ● Proven experience independently managing customer trust and assurance engagements end-to-end — from initial scoping and security questionnaires through assessment completion and negotiation — with minimal supervision. ● Understanding of digital sovereignty requirements relevant to Cloud adoption ● Bachelor’s degree required plus a minimum of 8 years’ experience in Information Security and Compliance ● Customer-facing experience at a cloud provider or consulting firm ● Experience at a cloud or SaaS provider or as a customer of a cloud or SaaS provider with complex & demanding security and compliance requirements ● Experience with a combination of the following: ISO 27001, HITRUST, SOC2, CSA, NIST, etc. ● Architectural familiarity across multiple security domains (e.g., identity and access management, data protection, network security, cloud infrastructure) with the ability to synthesize across domains and recommend practical solutions to complex customer security problems ● Proven experience independently managing customer trust and assurance engagements end-to-end — from initial scoping and security questionnaires through assessment completion and negotiation — with minimal supervision. ● Understanding of digital sovereignty requirements relevant to Cloud adoption ● Current Security CISSP, CIPP, CISA, CISM, or equivalent certification completed ● Excellent verbal and written communication, organizational, and planning skills ● Knowledge and understanding of GDPR, SOC2, ISO 27001, HIPAA, HITRUST, CSA, NIST, C5, and other regulatory standards in EMEA (such as DORA, NIS 2, EU AI Act ● Experience with industry (Financial Services, Public Sector, etc.) specific regulatory requirements impacting cloud adoption (e.g. from Financial Services regulators such as ECB, EBA, PRA, FCA etc.) ● Prior experience reviewing and negotiating security clauses within customer contracts a plus ● Demonstrated ability to assess the broader risk implications of customer security engagements, and to proactively structure work in a way that reduces risk exposure for both the customer and Confluent. ● Familiarity with emerging AI/ML security and governance considerations, including data pipeline security, model risk, and evolving regulatory expectations around AI in cloud environments. ● Ability to work and lead programs independently United Kingdom Software Engineering Remote Professional Multiple Cities (8660) IBM United Kingdom Limited