Responsibilities
- Lead and supervise the Governance, Risk, Compliance, and Security Engineering teams, setting strategic direction, managing staff, and ensuring performance goals are met.
- Oversee governance, risk, and compliance initiatives, maintaining ISO 27001 certification and ensuring audit preparedness for HIPAA and other regulatory frameworks.
- Manage the lifecycle of security policies, conduct control testing, and ensure ongoing compliance with established standards.
- Administer a vendor risk program, including assessments, due diligence, contract security terms, and ongoing monitoring of third parties.
- Provide security evaluations and guidance related to artificial intelligence technologies, defining acceptable use policies and risk controls.
- Assess risks associated with AI models and data usage, and recommend safeguards for AI-integrated systems.
- Guide the development of secure cloud and enterprise architectures in coordination with engineering teams.
- Collaborate on secure design principles for AWS, Azure, identity systems, networking, and data protection strategies.
- Manage security engineering operations, including endpoint detection and response using CrowdStrike, SIEM systems, and automated response workflows.
- Oversee cloud security posture management, vulnerability tracking, and security automation platforms.
- Lead incident response planning and execution, including simulations, investigations, and post-incident analysis.
- Manage security budgets, long-term planning, vendor agreements, and cost efficiency while maintaining control integrity.
- Report security program health and risk levels to executive leadership and board members using defined metrics.
- Define and monitor key performance and risk indicators to track program effectiveness.
- Work with engineering leadership to implement secure software development practices and SDLC controls.
- Develop and maintain a security roadmap aligned with organizational objectives and maturity goals.
Team
Structure: Manages the GRC and Security Engineering teams.