• Define the security strategy and leads implementation of high-priority initiatives across MCAPS-Core, translating company objectives into security roadmaps, measurable outcomes, investment priorities, and coordinated delivery across products, platforms, and business operations.
• Establish security initiative governance, success measures, decision frameworks, and operating rhythms; influence schedules, investments, dependencies, and risk decisions; remove execution barriers; and represent security priorities and outcomes in leadership forums.
• Lead large-scale security and architectural design reviews for feature areas, ensure secure design and development practices are embedded in delivery, translate findings into prioritized remediation plans, and track closure of material risks to maximize review value.
• Provide security architecture expertise through design reviews and threat models; evaluate how proposed controls, dependencies, and attack paths affect the end-to-end feature design; and translate findings into actionable guidance for partner teams.
• Evaluate security, customer, business, and operational tradeoffs; document risk-based recommendations; and drive timely decisions, mitigations, or escalations when requirements compete.
• Analyze complex security issues across multiple data sources, validate their scope and impact across dependent and down-level platforms, and lead cross-functional mitigation or remediation of systemic and emerging risks.
• Lead virtual and cross-functional security teams by establishing clear outcomes, decision rights, workstreams, owners, milestones, and dependencies; resolve ambiguity and conflict; and maintain alignment to strategic security goals.
• Build trusted partnerships across Security, Engineering, product, operations, and business teams to align on security priorities, secure commitments, drive adoption of mitigations and secure practices, and ensure material issues are addressed.
• Develop and scale secure practices, reference patterns, playbooks, and validation approaches for products, services, and systems; incorporate lessons from reviews, incidents, escalations, and recurring risk themes to improve security maturity for business.
• Conduct in-depth evaluations against security baselines, identify material control gaps and systemic weaknesses, and translate findings into prioritized improvements for products, platforms, and business processes.
• Assess the efficiency, consistency, and effectiveness of security reviews; prioritize effort based on risk and customer impact; and develop automation, analytics, and AI-assisted capabilities that improve review quality, coverage, traceability, and time to insight.
• Scale security expertise by coaching and mentoring others, sharing reusable guidance and lessons learned, and modeling sound judgment, accountability, and ethical behavior in security practice.