Subscription Business & Infrastructure Security
• Own the end-to-end security posture of the company’s subscription platform, including customerfacing applications, APIs, and underlying cloud infrastructure.
• Define and enforce security architecture standards for cloud environments (AWS, Azure, GCP), ensuring proper network segmentation, identity and access management (IAM), and data protection controls.
• Lead vulnerability management, penetration testing, and red team exercises to proactively identify and remediate risk across production systems.
• Establish and maintain a Security Operations Center (SOC) capability — whether in-house, managed, or hybrid — to ensure continuous monitoring, threat detection, and incident response readiness.
• Oversee data security controls to protect subscriber PII and payment information in compliance with applicable regulations (PCI-DSS, CCPA, GDPR, etc.).
• Define and rehearse incident response plans, leading the organization through security events from detection through post-mortem.
Software Development & DevSecOps
• Embed security throughout the software development lifecycle (SDLC), partnering with Engineering and Product to shift security left without slowing delivery velocity.
• Own the security of CI/CD build pipelines, including secrets management, pipeline integrity, dependency scanning, and supply chain security controls.
• Drive adoption of SAST, DAST, SCA, and container/image scanning tools across development teams.
• Define and maintain secure coding standards, conducting regular developer security training and threat modeling workshops.
• Establish controls to detect and prevent dependency confusion, code injection, and software supply chain attacks in build and deployment processes.
• Partner with platform and infrastructure engineering teams to ensure IaC (Terraform, Pulumi, etc.) follows security best practices and is reviewed prior to deployment.
Governance, Risk & Compliance • Build and maintain a cybersecurity governance framework.
• Own the company’s risk register for cybersecurity, providing clear, quantified risk reporting to executive leadership and the board as appropriate.
• Lead and manage third-party security assessments, customer security questionnaires, and audit responses (SOC 2 Type II, penetration test reports, etc.).
• Develop and enforce security policies, standards, and procedures across the organization.
• Drive vendor and third-party risk management, ensuring security requirements are embedded in procurement and contract processes.
• Maintain awareness of the evolving regulatory landscape and ensure the company’s practices remain compliant with applicable laws and industry standards.
• Champion a culture of security awareness through company-wide training programs, phishing simulations, and ongoing communication.