Own the operational effectiveness and lifecycle strategy for security platforms, including SIEM, SOAR and automation, endpoint and network detection and response, email security, threat intelligence, case management, and vulnerability management; drive automation where it improves speed and consistency while retaining human review for high-impact actions and patient-care-sensitive environments. Direct enterprise incident response and cyber crisis management for ransomware, identity compromise, data exposure, business email compromise, cloud and supply-chain events, and threats affecting clinical operations; lead tabletop and technical simulation exercises with executive, legal, privacy, clinical, and business continuity stakeholders; ensure root-cause analysis results in assigned and verified corrective actions.