• Operational Leadership: Manage day-to-day security operations, ensuring policies and strategies set by senior leadership are implemented effectively across teams and systems.
• Risk Management: Identify, assess, and track cyber risks; recommend and implement mitigations through technology, process, and policy changes.
• Policy Implementation: Maintain and enforce information security policies, standards, and procedures; recommend updates based on operational realities.
• Security Operations: Manage security monitoring, incident response, vulnerability management, and threat intelligence functions, including coordinating with SOC/MSSP resources as applicable.
• AI Governance and Tooling: Own the security review, deployment, and ongoing monitoring of AI tools used across the organization. Manage platforms such as Harmonic (for AI/data risk visibility and shadow AI detection) and Weave (for AI-related threat and behavior monitoring), including configuration, alert tuning, and reporting on findings. Develop and maintain guidelines for safe employee use of generative AI and third-party AI tools, and evaluate new AI tools/vendors for security and data-handling risk before adoption.
• Governance, Risk, and Compliance (GRC) Support: Support compliance with relevant laws, regulations, and frameworks (e.g., GDPR, HIPAA, PCI DSS, NIST). Coordinate evidence gathering and remediation for internal and external audits.
• Team Leadership: Lead, mentor, and develop a team of security analysts/engineers; manage workload, performance, and skill development.
• Incident Response: Lead execution of incident response plans for day-to-day and moderate-severity incidents; escalate and support leadership during major incidents.
• Stakeholder Communication: Communicate security status, risks, and AI tooling findings clearly to IT leadership and relevant business stakeholders.
• Technology Management: Manage and optimize the organization’s security tool stack (SIEM, EDR/endpoint protection, IAM, vulnerability scanners, and AI monitoring platforms like Harmonic and Weave), including licensing, integration, and vendor relationships.
• Vendor and Third-Party Risk: Conduct security assessments of third-party vendors, partners, and AI tool providers; track remediation of identified issues.
• Budget Support: Assist in developing and managing the security budget for tools, staffing, and training within the team’s scope.
• Awareness and Training: Run organization-wide security awareness programs, including training on safe and compliant use of AI tools.
• Continuous Improvement: Stay current on cyber threats, AI-specific risks (e.g., prompt injection, data leakage via AI tools, shadow AI usage), and industry best practices; recommend program improvements.