Career path

CISO Recruiters: How to Get on Executive Search Radars

How retained search actually works for CISO roles, which firms run security searches, and how to build recruiter relationships before you need them.

Last reviewed August 2, 2026 · 6 min read · Free, no paywall

Most CISO seats at serious companies are filled through retained executive search, and most security leaders have no idea how that machine works until they are inside it. The result is predictable: strong candidates are invisible to the people staffing the exact roles they want, then scramble to build recruiter relationships in the two weeks after a layoff, which is the one moment the relationship is worth the least.

I sit inside security leadership hiring at a large technology company and watch this from the buying side. This guide is the mechanics: how retained search works, which firms actually run CISO searches, how to get on their radar before you need them, and how to behave once you are in a process.

Which recruiters place CISOs?

Most CISO roles at serious companies are filled through retained executive search. The global firms that place CISOs include Heidrick & Struggles, Spencer Stuart, Russell Reynolds, Korn Ferry, and Egon Zehnder, alongside security-focused boutiques such as Hitch Partners, Artico Search, and True Search. The company pays the fee, so a recruiter charging you for placement is not running real executive search.

How retained search actually works

Executive search splits into two models, and confusing them causes most candidate mistakes.

Retained search is what companies use for real CISO seats. The company pays the firm a fee, commonly a third of first-year cash compensation, to run the search exclusively: build the spec with the hiring executive, map the market, approach candidates who are mostly not looking, and manage the loop through offer. The firm works for the company, not for you. That is worth internalizing, because it explains everything else: the recruiter’s product is a credible slate, their currency is information, and their risk is a candidate who embarrasses them late in the process.

Contingency recruiting is paid on placement, non-exclusive, and volume-driven. It fills the tier of roles below the executive seat and is the source of most of the low-effort “exciting CISO opportunity” spam in your inbox. Contingency is not evil, but it is a different machine: blind resume forwarding, thin specs, no exclusivity. If a recruiter cannot tell you who the hiring executive is or resists a conversation before sending your resume anywhere, you are in a contingency process, and you should control your own paper accordingly.

Inside a retained firm, two people matter to you. The partner owns the client relationship and the spec, and their opinion of you effectively decides whether you reach the hiring executive. The associate does the mapping and the first screens. Candidates who are dismissive of associates because they are junior and non-technical are making an unforced error: the associate writes the candidate summary that the partner and the client read, and the spec-matching described in the resume guide happens at their desk.

The firms that run CISO searches

Two tiers matter. The global generalist firms run many of the large-cap and board-adjacent searches: Heidrick & Struggles, Spencer Stuart, Russell Reynolds, Korn Ferry, and Egon Zehnder all place CISOs, usually out of their technology-officers or cybersecurity practices. If your target is a Fortune 500 or a regulated enterprise seat, these practices are staffing a meaningful share of them.

Below that sits a tier of boutique and technology-focused firms where security leadership is a core or dedicated practice. Names that recur in CISO and security-executive searches include Hitch Partners, Artico Search, Marlin Hawk, True Search, Caldwell, SPMB, Riviera Partners, and Daversa, with the last two or three weighted toward venture-backed and growth-stage companies. Boutiques often run deeper security networks than the global firms and are frequently the ones staffing the $200M-to-$5B company seats where most first-time CISOs actually land.

Treat any list like this as a map, not a directory: practices move with individual partners, and the person matters more than the letterhead. The durable version of this advice is: identify the two or three firms that keep appearing in searches at your target company stage and vertical, find the partner who runs security there, and be known to that person before a search opens.

Getting on the radar before you need it

Recruiters find candidates through three channels, in descending order of weight: referrals from people they trust, their own files from prior searches, and outbound research, which mostly means LinkedIn plus conference speaker lists and press. You influence all three.

Be referred. When a recruiter calls a CISO who is not interested, the next question is always “who should I be talking to?” Being the name that sitting CISOs mention is the single strongest way into the files. This is the compounding return on peer relationships, CISO communities, and being genuinely useful to people senior to you.

Be a source before you are a candidate. When an associate calls to ask about a search you are wrong for, take the fifteen minutes. Give a real read on the market, suggest two names, be honest about why the spec is hard. Sources get remembered as insiders and called first when the right search opens. Candidates who only engage when they want something get remembered too, differently.

Be findable in their language. Your LinkedIn should carry the scope numbers and regulatory keywords associates filter on, because outbound research is keyword-driven. The resume guide covers exactly which numbers those are. Speaking slots, published incident-retrospective talks, and community leadership all function as third-party proof of altitude.

Or invert the problem. The quiet-search dilemma is that public visibility is capped by your current employer watching. That is the gap the CISO Network exists to close: a private profile with your real scope, visible only to vetted recruiters, anonymous until you approve each introduction. It is the “be findable” channel without the public signal.

Once a partner calls about a live search, a few rules keep you in the strong half of the slate:

Tell the truth about compensation immediately. The partner will ask current comp and expectations on the first call. This is not negotiation, it is slate calibration, and evasiveness reads as either inexperience or a problem being hidden. Give real numbers with structure: base, bonus, equity, vesting remaining. The salary guide has current ranges if you need to calibrate expectations first. Negotiation happens later, with leverage; hiding the ball happens never.

Be fast and be boring. Respond within a day, show up prepared, deliver documents when promised. A shocking fraction of executive candidates fail on pure logistics, and the recruiter’s private ranking weights reliability heavily, because every candidate behavior is a preview of what they are exporting to a client.

Never go around the firm. If the search is retained, approaching the hiring executive directly reads as either naivety or a knife to the recruiter, and the recruiter controls the narrative about you either way. Win the recruiter, and use them: they will tell you more about the real decision dynamics than anyone in the loop if you ask good questions.

Ask the questions that reveal the seat. Why is the seat open, what happened to the predecessor, who owns risk acceptance, what does the board currently see. The questions guide has the full set. Recruiters respect diligence; it signals you have done this at altitude before. And if the answers start describing accountability without authority, run the Scapegoat Score before you fall in love with the title.

Close every process well. If you withdraw or lose, do it gracefully and stay in touch. Search firms recycle slates constantly: the strong runner-up from last year’s fintech search is the first call for this year’s. Several people get their seat on the second or third search with the same partner. The file is the asset. Behave like everything goes in it, because it does.

The timeline nobody likes

Building recruiter relationships from a standing start takes six to eighteen months to produce a real search conversation, which is why the correct time to start is while you are happily employed. If you are starting late, compress honestly: get referred by name, be useful fast, and put your scope where recruiters can find it. And read how CISOs actually get hired for the rest of the machine, because search firms are the largest channel into the seat, but they are not the only one.

Frequently asked

Should I ever pay a recruiter to find me a CISO job?

No. In retained executive search the company pays the fee, typically a percentage of first-year compensation. Anyone charging candidates for placement or radar access is not running real executive search. Career coaching is a legitimate separate service, but placement fees from candidates are a red flag.

How do I find out which search firm is running a specific CISO search?

Ask the person who contacted you, check whether the posting names a firm, and ask your network: peers who interviewed for the role will know. For unlisted searches, security-focused practices are worth a proactive note, since the same handful of firms run a large share of them.

Will recruiters keep my search confidential from my current employer?

Reputable retained firms treat confidentiality as core to the business, since most executive candidates are employed. Say explicitly that your search is confidential and that you are not to be used as a source of hire without consent. Blind-forwarding resumes is contingency behavior, not retained behavior.

How often should I stay in touch with an executive recruiter?

Twice a year is enough when nothing is happening: a short note on a scope change, a promotion, a board appearance, or a useful market observation. When you are actively looking, tell them directly. Recruiters keep files; your job is to keep yours current, not to be memorable for volume.

Free template

Steal the 90-Day CISO Plan

The exact 90-day plan structure hiring panels expect: the single asset every CISO candidate gets asked for. Free, editable, yours in one click.

Instant access, no confirmation hoops. Occasional emails on landing the seat; unsubscribe anytime.