Operational backbone of the department, ensuring the Information Security program runs efficiently and measurably by coordinating initiatives across all security functions, producing executive reporting, and managing the operational cadence so the VP, IT & Security can focus on strategy, customer security relationships, board engagement, and regulatory matters.
This is not a hands-on engineering role, but the ideal candidate has built credibility working within an Information Security organization and understands how Security Operations, Vulnerability Management, Identity & Access Management, Cloud Security, Incident Response, and Security Engineering teams operate and partner together. Success in this role comes from translating operational security priorities into executive action, cross-functional execution, and measurable program outcomes.
To perform this job successfully, an individual must be able to perform each essential duty satisfactorily. The requirements listed below are representative of the knowledge, skill, and/or ability required. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
Program & Project Coordination
Own the security program roadmap at the execution level across all security functions
Track initiatives, timelines, and blockers without requiring VP involvement day-to-day
Coordinate cross-functional dependencies across Security Operations, Vulnerability Management, Security Engineering, Identity & Access Management, Cloud Security, IT, Legal, and Compliance.
Act with delegated authority from the VP on operational execution matters
Metrics, Reporting & Dashboards
Build and maintain the security metrics framework — vulnerability SLA compliance, incident-response timelines, audit-finding closure, and training completion
Produce dashboards for board reporting, SEC disclosure prep, audit-committee updates, and customer security reviews
Translate raw tool and team data into a coherent program narrative for executive and external audiences
Security Operations & Security Program Coordination
Partner with Security Operations, Engineering, and IT teams to coordinate security initiatives, remediation efforts, and operational follow-through across the security program.
Coordinate security team evidence collection for SOC 2, ISO 27001, PCI-DSS, and customer audits.
Serve as the security team's interface to the General Counsel's Compliance team during audits and regulatory activities.
Track audit findings, operational remediation activities, and follow issues through closure to improve the organization's overall security posture.
Security Governance & Operational Enablement
Own the security policy lifecycle: annual review, version control, approval, accessibility
Own the security awareness and training program including phishing simulations
Manage security-tool contracts, renewals, license utilization, and MSSP relationship logistics
This job description reflects management’s assignment of essential functions; and nothing in this herein restricts management’s right to assign or reassign duties and responsibilities to this job at any time.
Managerial Responsibilities
Non-Manager: No oversight or accountability for others, an individual contributor.