CIO JOB DESCRIPTION

CIO job description: the role, the responsibilities and when to hire one

You are writing a CIO job description because something has outgrown your current technology leadership. This page sets out what the role actually does, what good looks like, the signs you need it now, and how a fractional or interim arrangement gives you the same authority without a permanent salary.

Book a conversation

What a CIO does

A Chief Information Officer owns the strategy, delivery and risk of everything technology touches in the business. That means three things at once: setting the direction for systems and data so they support where the company is going, running technology delivery so projects land and operations stay up, and holding accountability for cost, security and resilience at board level. A good CIO translates commercial goals into a technology plan the rest of the leadership team can read, then makes it happen. The role is not about managing the helpdesk. It is about deciding what to build, what to buy, what to retire, and what to protect, and owning the consequences of those calls. If you want a fuller picture of how that mandate is delivered without a full-time hire, the fractional CIO and CISO page sets out the model.

Core responsibilities to put in the job description

A practical CIO job description should name the responsibilities that matter rather than a generic wish list. The core ones are: owning the technology strategy and roadmap and keeping it aligned to the business plan; accountability for cyber security, governance and regulatory obligations; budget ownership across capital and operating spend; vendor and supplier management, including contracts and renewals; programme and project delivery for the changes that actually move the business; data strategy and the responsible use of AI; and resilience, meaning the company can keep trading through an outage or an attack.

What good looks like

A strong CIO is judged on outcomes the board can feel, not on activity. Good looks like a technology plan the rest of the leadership team understands and trusts, projects that ship on a predictable cadence, a security posture that stands up to scrutiny from customers, insurers and regulators, and technology spend that is visible and defensible. A weak CIO leaves the board guessing: surprises in the budget, projects that slip without explanation, and a security position nobody can describe with confidence. The difference is rarely technical brilliance. It is judgement, communication and the discipline to prioritise. The best CIOs say no to most things so the few that matter get done. Where cyber maturity is the immediate gap, that judgement is what cyber security consulting exists to supply.

Signs you need this role

You usually feel the absence of a CIO before you write the job description. The signs are consistent: technology decisions are being made by whoever shouts loudest or by the most senior person who happens to be technical, rather than by someone accountable for the whole picture. Projects start with energy and stall. Your security position is unclear, and you cannot answer a customer questionnaire or an insurer’s renewal questions without scrambling. A private equity sponsor or an acquirer is asking technology and security questions you cannot answer, which is exactly where technology due diligence bites. Regulation such as NIS2 compliance has landed on your desk and nobody owns it. Or you have lost a technology leader and the gap is widening by the week, the situation described on the interim CIO leadership gap page.

What this role costs full time

A full-time CIO is a significant fixed cost, and the security half of the mandate carries its own price: a UK CISO salary alone runs roughly £95,000 to £600,000 or more depending on sector, scope and risk. On top of base salary sit bonus, equity, pension, recruitment fees and the time it takes to find the right person, which can run to many months for a senior hire. For a mid-market company, that is a substantial commitment for a role you may not need at full intensity every week. The risk of getting the hire wrong is also real: a mis-hire at this level sets technology strategy back a year. If you want to model the difference between a permanent hire and a fractional arrangement, the CIO and CISO cost calculator and the pricing page give you concrete numbers to work with.

How a fractional or interim CIO delivers the role

You do not have to choose between a full-time hire and no senior technology leadership at all. A fractional CIO carries the same accountability for strategy, delivery and risk, but on a defined number of days a month, scaled to what the business actually needs. An interim CIO steps in at full intensity to cover a gap, lead a transformation or steady a function while you recruit. The board still gets a single accountable owner who sits in leadership meetings, owns the roadmap and the budget, and answers for security. What changes is the cost and the commitment. Where the priority is security rather than the full technology brief, the same logic applies to a virtual CISO or CISO as a service engagement, and to the lighter-touch vCIO model for smaller organisations. Regulated firms, particularly in finance, often start with cyber security for financial services and ransomware readiness before broadening the mandate.

Why Starkhorn

Starkhorn is led by Daniel J. Jacobs, who has spent over 20 years in technology and security, 15 of them in leadership roles, including Interim Group Technology Director at VetPartners, the BC Partners-backed veterinary group, and CIO and CISO at Jardine Motors Group. He is the author of The Strategy Bridge and holds PRINCE2, ITIL Foundation and full membership of the Institute of Interim Management.

That experience means the CIO job description above is not theory: it describes the work Daniel has actually owned, from setting technology strategy and running delivery in a private equity-backed group to holding combined CIO and CISO accountability at board level.

Frequently asked questions

What is the difference between a CIO and a CISO?

A CIO owns technology strategy, delivery and budget across the whole business. A CISO owns cyber security specifically: the defence of systems and data, governance and regulatory obligations. In smaller and mid-market companies one person often holds both, which is the combined role Daniel has carried.

Do we need a full-time CIO or a fractional one?

If technology is central to the business and changing fast every week, a full-time hire may be right. If you need senior judgement, board-level accountability and a clear roadmap but not at full intensity, a fractional CIO delivers the same role at a fraction of the cost. The deciding factor is how much of the role you genuinely need each month.

What should a CIO be accountable for?

Technology strategy aligned to commercial goals, cyber security and governance, budget and supplier management, delivery of the change programme, data and AI use, and the resilience of the business through outages and attacks. If those things have no single owner, that is the gap a CIO fills.

How quickly can an interim CIO start?

An interim CIO is built for speed. Where a permanent hire takes months to find and onboard, an interim steps in to cover a gap, lead a transformation or steady the function while you recruit, with accountability from day one rather than after a long ramp-up.

How do we know if we are ready to hire a CIO?

Start with the symptoms: stalled projects, unclear security, technology decisions with no clear owner, or due diligence questions you cannot answer. The free Technology Leadership Gap check turns those symptoms into a clear read on whether you need the role and at what intensity.

START HERE

Not sure whether you need a CIO yet?

If you recognise the stalled projects, the unclear security position and the decisions with no clear owner, the Technology Leadership Gap check tells you, in a few minutes, whether you need this role and how much of it. Or book a conversation and we will talk it through against your situation.

Technology Leadership Gap check Book a conversation