Risk, policy and third party. Run the information security risk register as a decision-making tool, own the policy lifecycle and exception register, and assess the vendors and partners we integrate with.
Incident response and regulatory notification. Own breach assessment and the notification decision across the jurisdictions we operate in, alongside Legal. In healthcare this is the highest consequence judgement in the role.
Finding what is broken before someone else does. Go looking. Read the infrastructure code, pull the access review output, check that the alert a policy promises is actually configured. When you find a gap, bring it quantified, costed and sequenced.
...
Design and improve clickstream data pipelines—from event ingestion to insight delivery—and contribute to services/tools for understanding user behavior.
...