1. Organization and People Leadership
•
Lead, coach, and develop managers and engineers across the United States and India. Establish role clarity, career paths, succession coverage, and consistent performance expectations.
•
Create an operating cadence that supports asynchronous execution, reliable cross-region handoffs, rapid escalation, and shared accountability.
•
Build workforce and capacity plans aligned to product growth, AI investment, risk, and business priorities.
•
Foster a culture of constructive challenge, disagree and commit, continuous learning, quality, and automation-first improvement.
2. AI and Product Security
•
Own the security strategy for AI-enabled product capabilities from design through production, including threat modeling, architecture review, secure development standards, testing, monitoring, and release readiness.
•
Address AI-specific risks such as prompt injection, insecure tool or agent access, sensitive-data exposure, model and data pipeline integrity, excessive agency, abuse, and third-party model or service dependencies.
•
Partner with AI/ML, Product, and Engineering teams to define secure patterns for models, agents, retrieval-augmented generation, application programming interfaces, data access, and human approval controls.
•
Advance product security practices including secure software development lifecycle controls, code and design review, application security testing, penetration testing, security champions, and coordinated vulnerability disclosure or bug bounty.
3. Vulnerability Operations
•
Own end-to-end vulnerability discovery, prioritization, remediation governance, exception management, and validation across applications, cloud infrastructure, containers, endpoints, operating systems, and third-party components.
•
Move beyond severity-only prioritization by incorporating exploitability, internet exposure, asset criticality, data sensitivity, available compensating controls, and active threat intelligence.
•
Improve remediation speed and predictability through automation, clear service-level objectives, transparent ownership, and decision-ready reporting.
•
Establish effective coverage for software supply chain risk, including open-source dependencies, build systems, artifacts, secrets, and continuous integration and delivery pipelines.
4. Infrastructure and Cloud Security
•
Own preventive and detective security guardrails for the AWS environment, infrastructure as code, containers, identity and access, network boundaries, workloads, secrets, logging, and data services.
•
Partner with Infrastructure and Platform Engineering to make secure cloud patterns easy to adopt and to reduce reliance on manual review.
•
Drive least privilege, secure administrative access, workload identity, segmentation, configuration assurance, and continuous cloud risk reduction.
•
Ensure architecture and change reviews focus on material risk while preserving engineering velocity.
5. Strategy, Governance, and Business Partnership
•
Translate business strategy, product roadmaps, AI priorities, threat trends, customer commitments, and audit requirements into a multi-quarter security engineering roadmap.
•
Define quarterly objectives and key results, key performance indicators, and key risk indicators that show coverage, outcomes, trends, and remaining exposure.
•
Communicate risk and tradeoffs clearly to technical leaders and executives. Escalate material risks with practical options, owners, and recommended decisions.
•
Maintain policies, standards, control evidence, inventories, and operating procedures that support SOC 2, ISO 27001, privacy, customer assurance, and other applicable obligations.
•
Evaluate and rationalize security tools and services based on measurable risk reduction, engineer experience, coverage, integration, and total cost.
Success will be measured by outcomes and sustained operating health, not activity volume alone:
Material vulnerabilities and security design risks are identified early, prioritized consistently, and remediated or formally accepted within defined objectives.
Security controls and testing provide measurable coverage across product code, AI features, cloud infrastructure, containers, identities, dependencies, and critical data paths.
Approved secure patterns, automation, and self-service controls reduce security friction and late-stage rework.
AI features have repeatable security requirements, threat models, tests, release criteria, monitoring, and documented residual risk.
The three teams operate with clear ownership, reliable cross-region handoffs, actionable metrics, current documentation, and effective escalation.
The organization demonstrates strong engagement, skill growth, succession depth, retention, and accountable delivery across locations.
Product, Engineering, Infrastructure, and executive partners receive timely, clear, decision-ready security guidance and reporting.