Own the intake pipeline for risks submitted from every source, including internal observation, audit findings, penetration tests, red team exercises, vulnerability scans, threat modeling, tabletop exercises, incidents, and compliance frameworks such as SOC 2, SOX, FedRAMP, IRAP, C5, UK Cyber, and NIST CSF.