Policy, standards, and risk
• Own the information security policy set and the control framework, mapped to ISO 27001 Annex A, SOC 2 Trust Services Criteria, and our customer and regulatory obligations.
• Own the technical standards the estate owners implement — hardening baselines, encryption, logging and retention, authentication, segmentation, and secure configuration.
• Own the risk framework and the risk register: current, evidenced, reviewed on cadence, with named owners.
• Own the exception process and approve risk acceptances below the material threshold; prepare and escalate anything above it.
• Own security architecture review for significant changes and new technology, before commitment.
• Report the risk position to the CIO, executive leadership, and the Audit Committee.
Detection and incident response
• Own security monitoring across endpoints, cloud, on-premises, corporate applications, and identity — coverage, detection content, and tuning.
• Own the SIEM estate and any managed detection provider relationship.
• Act as incident commander for declared security incidents, with authority to direct containment in any estate.
• Own post-incident review and drive remediation into the owning function’s backlog, tracked to closure.
• Run tabletop and live exercises across technical teams and executive leadership.
Vulnerability and threat management
• Own the vulnerability management program: scanning coverage, severity model, and remediation SLAs.
• Own the prioritization model — excitability, exposure, business impact — so remediation effort is directed rather than alphabetical.
• Track SLA attainment by estate owner, report it, and escalate breaches.
• Own penetration testing and red team engagements: scope, vendors, cadence, and finding closure.
• Own security testing requirements in the SDLC — SAST, dependency scanning, secrets detection, image scanning — and the gating thresholds.
Identity and access governance
• Own the access governance model: least privilege, segregation of duties, and the evidence each control must produce.
• Own privileged access policy — vaulting, just-in-time elevation, session recording, and break-glass.
• Own the design, scope, and cadence of access reviews, and certify their completion.
• Own authentication and session policy: MFA requirements, phishing-resistant factors, conditional access, and device trust.
Compliance and customer assurance
• Own the ISO 27001 ISMS: scope, Statement of Applicability, internal audit program, management review, and certification maintenance.
• Own the SOC 2 Type 2 program: control narrative, evidence calendar, and the audit period itself.
• Close out FedRAMP authorization: authorization path and agency sponsorship, system boundary, the NIST SP 800-53 baseline, System Security Plan, 3PAO assessment, POA&M, and the monthly continuous monitoring that follows.
• Close out CMMC Level 2: CUI scoping and enclave boundary, NIST SP 800-171 implementation, SSP and POA&M, SPRS submission, C3PAO assessment, and annual affirmation.
• Sequence all four frameworks against one control set — shared evidence, one calendar, and a single answer to a control tested under more than one regime.
• Own the external auditor and certification body relationship, plus the agency sponsor relationship where one is required, and coordinate evidence from each estate owner.
• Build continuous control monitoring so compliance is a measured state, not an annual scramble.
• Direct the compliance specialist, who runs evidence collection, control testing, POA&M tracking, and audit logistics. You keep framework scope, control interpretation, assessor and sponsor relationships, and the risk decisions behind them.
• Own customer security assurance — questionnaires, customer audits, trust documentation, and security terms in contracts and DPAs.
• Own the customer assurance pipeline: questionnaire intake, a library of pre-approved answers, and a turnaround commitment to Sales. The specialist drafts; you approve anything that commits us to a control, a date, or a contractual term.
• Own controlled distribution of audit artifacts under NDA — SOC 2 report, penetration test summaries, certifications, authorization packages — and decide what is not released.
Third-party risk and security culture
• Own vendor and SaaS security assessment: tier, assessment depth, sign-off before contract, and reassessment cadence.
• Own security requirements in vendor contracts — control obligations, right to audit, and incident notification terms.
• Own the awareness program, phishing simulation, and role-specific training for developers, privileged operators, and executives.