· End-to-end ownership of one or more security capabilities/platforms: design, implement, operate, and evolve them with threats and business needs.
· Serve as L3 technical authority for complex/high-impact incidents: lead investigations, perform deep RCA, and define long-term preventive engineering actions.
· Drive exposure surface reduction by improving vulnerability management processes, prioritization, and engineering remediation patterns.
· Ensure operational excellence for anti-phishing and DLP (advanced tuning, policy design, exception governance, evidence-by-default).
· Embed security into DevOps and product environments: threat modeling facilitation, application security tooling/guardrails, and automation to shift left.
· Design and maintain AI security implementation patterns (data protection, identity controls, safe usage guardrails) aligned with compliance needs.
· Strengthen the SOC partner operating model: refine escalation criteria, enrich context, improve runbooks, and reduce noise via engineering.
· Mentor/coach (as IC leadership) on secure engineering practices, troubleshooting methodology, and standards adoption across teams.