Must HaveOutcome-based leadership. You translate business objectives into clear outcomes and keep the
team focused on them. You set the requirements and constraints, guide the how without dictating it,
and trust your team to own execution. You know what good looks like and reach it efficiently; the
right-sized solution, delivered without micromanagement.
Accountability for results. You measure success by whether risk actually went down and whether
engineers can do their jobs safely; not by how many findings you produced. You drive fixes to
closure, even when another team owns the code.
Partnership with Engineering. Engineering is your customer. You default to “how do we make this
work safely?” and when you must say no, you explain it in terms they value and offer a path. You
assert security and compliance requirements; you don’t dictate product decisions.
Speed and judgment. Assessments turn around in days, not weeks. You right-size rigor to the
decision in front of you and avoid security theater.
Technical depth. You move fluently across threat modeling, code and architecture review,
SCA/SAST, secret scanning, vuln management, and cloud/CSPM — enough to earn engineers’
respect and coach your team.
Integrity and trust. You handle privileged access with discretion, and you build a team where
sharing bad news early is safe and rewarded.
AI fluency. Our security org runs on AI daily (Claude, Gemini, custom tooling). You treat AI as a
force multiplier and champion AI-augmented security workflows.