Own the enterprise security program. Establish strategy, risk appetite, policies, control framework, roadmap, metrics, executive reporting, and decision rights
Clarify and operate the product/corporate boundary. Partner with Product Security to define who owns application security, cloud/production security, identity engineering, vulnerability management, detection/response, customer trust, and remediation
Lead IT Operations and Engineering. Build a high-quality global service model across support, identity, endpoint, SaaS, collaboration, office/network, automation, asset lifecycle, and resilience. Separate frontline support from systems engineering and drive secure self-service
Build detection and response. Define priority threats and crown jewels, improve telemetry and detection coverage, establish 24/7 response, run incidents and exercises, and ensure corrective actions prevent recurrence
Own GRC, assurance, and customer trust. Maintain and streamline processes for SOC 1, SOC 2, ISO 27001, and IS 42001, prepare for future SOX/public-company controls, manage audits and findings, and enable fast, accurate customer security responses
Secure AI and internal tools. Partner with internal teams to define the risk tolerance, framework, and infrastructure to securely deploy AI and business apps built in-house
Drive EIAM and data protection. Mature joiner/mover/leaver, privileged access, service identities, access reviews, data classification, DLP, encryption/key management, retention/deletion, and sensitive-data controls
Manage third-party and resilience risk. Mature TPRM by risk-tiering vendors, ensuring contractual and operational controls, defining service criticality/RTO/RPO, and maintaining crisis readiness
Build the team and culture. Assess roles and capability gaps, hire selectively, develop leaders, create security/IT champions, and make the safe path the easy path