Security Strategy & Governance
▸ Own Dynata’s enterprise security strategy — define the roadmap, prioritize investment, and align security controls with business objectives across cloud, corporate applications, and data platforms.
▸ Establish and maintain a Zero Trust security architecture spanning AWS, Azure, and GCP environments.
▸ Oversee threat intelligence, vulnerability management (CVE reduction), and incident response programs.
▸ Drive Cloud Security Hardening initiatives and set security standards within the Cloud Center of Excellence (CCoE).
AI Security & Risk Management
▸ Build and own Dynata’s AI Security governance framework — establish policies, controls, and risk guardrails for the company’s growing AI/ML portfolio including MS Fabric, Snowflake, Copilot, and LLM-based tools.
▸ Lead AI risk assessment and model governance aligned with NIST AI RMF, EU AI Act, and emerging regulatory requirements.
▸ Define controls for LLM-specific threats: prompt injection, data exfiltration via AI, model inversion, and adversarial inputs.
▸ Partner with the EDMS and Engineering teams to embed AI security-by-design in DataHub, lakehouse architectures, and AI product development.
Compliance & Regulatory Oversight
▸ Own and manage all major compliance certifications and audits: SOC 2 Type II, ISO 27001, GDPR, CCPA/CPRA, and HIPAA where applicable.
▸ Monitor the regulatory landscape — proactively identify and respond to emerging privacy and AI regulation in the US and EU.
▸ Manage third-party and vendor risk management programs across Dynata’s technology supply chain.
▸ Partner with Legal and Finance to respond to client security questionnaires, audits, and contractual security requirements.
Security Operations Center (SOC) & Audit Management
▸ Own and manage Dynata’s Security Operations Center (SOC) — including 24/7 monitoring coverage, alert triage, escalation protocols, and continuous improvement of detection and response capabilities.
▸ Lead all internal and external security audits — coordinate audit preparation, evidence collection, control testing, and finding remediation across all compliance frameworks (SOC 2, ISO 27001, GDPR, CCPA).
▸ Manage relationships with external auditors, assessors, and penetration testing partners; ensure audit readiness is a continuous state, not a seasonal event.
▸ Drive SIEM/SOAR optimization — tune alerting, reduce false positives, and improve analyst efficiency across Splunk, Microsoft Sentinel, CrowdStrike, or equivalent platforms.
▸ Establish SOC KPIs and SLAs: MTTD, MTTR, alert-to-ticket ratio, and analyst utilization — reported to leadership monthly.
Governance Committees & Strategic Leadership
▸ Serve as a standing member of Dynata’s Data Governance Committee — providing the security and privacy lens on data classification, access policies, retention standards, and data lineage across the enterprise.
▸ Serve as a standing member of Dynata’s AI Governance Committee — defining AI risk thresholds, responsible AI standards, and security controls for all AI/ML models and agents moving into production.
▸ Participate in strategic task forces as designated by senior leadership — contributing security expertise to emerging initiatives, M&A due diligence, vendor evaluations, and regulatory response efforts.
▸ Represent security interests in the Cloud Center of Excellence (CCoE) — ensuring that cloud architecture decisions are made with security guardrails built in from day one.
Cross-Functional Partnership — Product, Engineering & Technology
▸ Partner with Product and Engineering teams to embed security into the software development lifecycle (SDLC) — from threat modeling and secure design reviews through code scanning, staging validation, and production release gates.
▸ Collaborate with Technology leadership (Cloud Ops, EDMS, Corporate Applications) to ensure security controls are woven into platform architecture, data pipelines, and enterprise application rollouts — not bolted on after the fact.
▸ Serve as the trusted security advisor for all major technology programs — including D365 CE/F&O, MS Fabric/Lakehouse, Dynata+ Phase 3, and inBrain Azure migration — providing risk assessments and go/no-go input at key milestones.
▸ Engage with front-end and application teams to assess and remediate security risks in web applications, APIs, and customer-facing platforms — including penetration testing oversight and vulnerability triage coordination.
Team Leadership & Culture
▸ Recruit, develop, and retain a high-performing Security & Compliance team of 6–15 FTEs.
▸ Foster a security-first culture across Technology Operations and the broader organization through training, awareness programs, and executive engagement.
▸ Present to executive leadership and the board — deliver quarterly security posture reviews, risk dashboards, and compliance status updates with clarity, confidence, and business context.
▸ Serve as the executive sponsor for security in cross-functional programs including BOS → D365 migration, inBrain Azure migration, and Dynata+ Phase 3.