Unified Exposure Strategy: Own and deliver a multi-year strategy across Vulnerability Management, Application Security and Penetration Testing, with clear roadmaps, budgets and capability plans; set direction with a high degree of autonomy.
Risk-Based Vulnerability Management: Evolve from volume-based scanning to prioritized exposure management using asset criticality, exploitability and threat intelligence; implement enterprise remediation governance and SLAs.
Attack Surface and Exposure Visibility: Maintain continuous visibility of internal and external attack surfaces—including cloud, SaaS and third-party exposure—and focus effort where real-world risk is highest.
Application Security Assurance: Run a secure development assurance program covering SAST, DAST and SCA; drive developer enablement and behaviors for software we build and buy.
Software Supply Chain Governance: Oversee software composition risk, SBOM practices and rapid response to widely exploited components; guide investment and policy.
Continuous Offensive Testing: Operate a continuous program of penetration testing and adversary emulation across applications, infrastructure, cloud and OT; run purple-team exercises with Threat Management to harden detection and response.
AI-Era Exposure Readiness: Prepare for machine-speed exploit generation by automating discovery, prioritization and validation; assess the security of AI and large language model systems.
Remediation Through Partners: Drive fixes through accountable asset owners; escalate and govern risk acceptance; keep the reporting honest and defensible.
Metrics and Executive Reporting: Own exposure KRIs—mean time to remediate, SLA attainment, recurrence, coverage, critical exposure ageing—and report credibly to senior leadership and risk committees.
Assurance Integration: Feed findings from offensive testing and cyber intelligence into prioritization; incorporate incident learnings so testing reflects how we are actually being attacked.
Executive Communication and Influence: Translate technical exposure into business risk the CISO, IT leadership and the Board can act on; defend prioritization decisions under scrutiny.
Build and Uplift the Function: Lead and uplift a multi-disciplinary team of roughly eighteen across regions; raise posture from operational scanning to strategic exposure management while preserving independence and integrity.
Lead Through Leaders: Manage the leaders of Vulnerability Management, Application Security and Penetration Testing; set objectives, review performance and build succession.
Talent, Culture and Capability: Recruit inclusively; develop career paths and upskilling in exposure management, cloud and application security, offensive testing and automation; leverage regional and external partnerships.
Budget and Tooling Ownership: Own budgets for scanning, application security and offensive tooling and specialist partners; build the investment cases that maximize business risk reduction.