Subscription Business & Infrastructure Security
โข Own the end-to-end security posture of the companyโs subscription platform, including customerfacing applications, APIs, and underlying cloud infrastructure.
โข Define and enforce security architecture standards for cloud environments (AWS, Azure, GCP), ensuring proper network segmentation, identity and access management (IAM), and data protection controls.
โข Lead vulnerability management, penetration testing, and red team exercises to proactively identify and remediate risk across production systems.
โข Establish and maintain a Security Operations Center (SOC) capability โ whether in-house, managed, or hybrid โ to ensure continuous monitoring, threat detection, and incident response readiness.
โข Oversee data security controls to protect subscriber PII and payment information in compliance with applicable regulations (PCI-DSS, CCPA, GDPR, etc.).
โข Define and rehearse incident response plans, leading the organization through security events from detection through post-mortem.
Software Development & DevSecOps
โข Embed security throughout the software development lifecycle (SDLC), partnering with Engineering and Product to shift security left without slowing delivery velocity.
โข Own the security of CI/CD build pipelines, including secrets management, pipeline integrity, dependency scanning, and supply chain security controls.
โข Drive adoption of SAST, DAST, SCA, and container/image scanning tools across development teams.
โข Define and maintain secure coding standards, conducting regular developer security training and threat modeling workshops.
โข Establish controls to detect and prevent dependency confusion, code injection, and software supply chain attacks in build and deployment processes.
โข Partner with platform and infrastructure engineering teams to ensure IaC (Terraform, Pulumi, etc.) follows security best practices and is reviewed prior to deployment.
Governance, Risk & Compliance โข Build and maintain a cybersecurity governance framework.
โข Own the companyโs risk register for cybersecurity, providing clear, quantified risk reporting to executive leadership and the board as appropriate.
โข Lead and manage third-party security assessments, customer security questionnaires, and audit responses (SOC 2 Type II, penetration test reports, etc.).
โข Develop and enforce security policies, standards, and procedures across the organization.
โข Drive vendor and third-party risk management, ensuring security requirements are embedded in procurement and contract processes.
โข Maintain awareness of the evolving regulatory landscape and ensure the companyโs practices remain compliant with applicable laws and industry standards.
โข Champion a culture of security awareness through company-wide training programs, phishing simulations, and ongoing communication.