Deep expertise in safeguarding sensitive data, systems, and networks against cyber threats
Expertise in Application Security, SecDevOps, Security Engineering, Cloud Security, and Vulnerability Detection and Assessment
Knowledge of integrating security into CI/CD pipelines and software development lifecycle (SDLC)
Familiarity with security testing tools and processes (e.g., SAST, DAST)
Understanding of regulatory requirements, industry standards, and best practices (e.g., NIST, PCI, SOC)
Ability to stay updated on emerging threats, vulnerabilities, and industry trends
Strong leadership skills to build and manage teams, operating models, and foster employee growth and accountability
Principled leadership, sound business ethics, and consistency in principles, values, and behavior
Excellent communication skills to interact with all levels of management and stakeholders
Responsibilities
Lead a global team responsible for developing, implementing, and maturing cyber security areas including Application Security, SecDevOps, Security Engineering, Cloud Security, and Vulnerability Detection and Assessment
Lead implementation of security within the software development and IT build lifecycle, integrating security into CI/CD pipelines
Collaborate with development and operations teams to foster a security culture and enhance security posture
Oversee deployment and execution of enterprise security controls
Determine risk and exposure of security gaps and provide guidance to key stakeholders
Build, oversee, and maintain an enterprise Secure DevOps program aligned with business, technology, and security goals
Build, oversee, and maintain the Cyber Enablement organization providing hands-on security execution, risk management, governance, and compliance services
Design and implement processes to embed security into every stage of SDLC and CI/CD pipelines
Drive automation of security processes, controls, testing (SAST, DAST), and compliance checks
Identify, evaluate, and mitigate security risks and vulnerabilities in applications and infrastructure
Support security incident response activities, including post-incident analysis and lessons learned
Foster security culture by providing guidance on secure coding practices, design principles, and controls
Develop and maintain metrics to monitor and report on security controls, processes, and program performance
Build and prepare updates/reports to advise senior leadership on security posture, issues, risks, and program state
Ensure compliance with regulatory requirements, industry standards, and best practices
Collaborate with executive leadership, IT teams, and stakeholders to ensure confidentiality, integrity, and availability of information assets
Proactively recommend and implement security measures based on emerging threats and trends
Build and manage an operating model promoting employee growth, accountability, and effective delivery of security processes
Communicate security risks, effectiveness, completeness, and program needs to all levels of management
Build and maintain strong relationships with key stakeholders to establish a culture of engagement