Skills and Requirements - 8+ years in information security / technology risk with increasing scope - 5+ years leading teams (hiring, coaching, performance management) - Strong risk management mindset - assess risk, communicate tradeoffs, drive mitigation - Experience building and running security governance (policies, exceptions, metrics, reporting) - Proven ownership of risk programs (assessments, third-party risk, remediation plans) - Incident response leadership (coordination, investigations, continuous improvement) - Ability to influence across IT, engineering, legal, audit, and business stakeholders - Executive-level communication skills (translate risk to business impact) - Strong program management and prioritization across multiple workstreams - Budget and vendor management experience - Working knowledge of core security domains (IAM, network/endpoint, logging, data protection) - Experience partnering with product/engineering on security and risk priorities - Experience leading globally distributed teams - Enterprise-scale security exception governance experience - Background in security awareness / culture programs - Exposure to audit, regulatory, and compliance support - Certifications (CISSP, CISM, CRISC, etc.) - Experience in complex, multi-region or regulated environments - Strong third-party risk program experience - Track record of maturing or scaling security programs - Executive/board-level reporting exposure The manager oversees programs including security risk assessments, exception governance, security awareness, incident coordination and investigations, and security metrics/reporting.