Effectively designed, scaled, and operated relevant functions in the past : candidate appreciates and understands the challenges related functions face from a staffing, coordination, cross-functional collaboration, and orchestrating many functions to achieve common long range outcomes. They have held a similar scoped role in the past or have directly supported 2 or more functions in which they will support in this role e.g. been a Mgr. AppSec and Mgr. of EntSec before. They have demonstrated leading their direct and cross-functional partner teams through similar transitions.
People and engineering leadership : candidate has established and demonstrated experience leading engineering functions and demonstrated strong people management skills commensurate with the target level. They have supported senior ICs and managers alike in similar in-domain areas.
Security Experience : given the breadth of this role and the primary focus on 1 & 2 above having higher weightings, we may not be able to find the unicorn we’re looking for that would also have the in-domain security experience and/or experience leading a program management function in security that also satisfies 1 & 2. Therefore, the security experience isn’t a must, and the weighting on this will be lower when evaluating candidates assuming the candidate has demonstrated successfully supporting others in multi-disciplined, technical fields. Further, adjacent experience in Privacy, Trust and Safety, Integrity, etc. functions w/ similar problem spaces will be a good proxy for success in InfoSec.
Security Culture: the person is not a security zealot. Their expectations and approaches are practical and take business needs into consideration first to solve the security challenges. They limit friction and only introduce it as a last resort. They have a customer mindset and attempt to find the path to yes and dont see security’s role today no or to police. They are comfortable that when the business makes a decision that may not be the most secure and see it as an opportunity to help mitigate the risk while achieving business objectives.
Your Expertise:
8+ years managing people with at least 3 of those years supporting other managers
Demonstrated ability to support, scale, and advance like functions
Deep understanding of strategic approaches and methodologies across the lifecycle of prevention, detection, response, and validation and how your teams fit in and are responsible for across these pillars and various programs that comprise Information Security.
Experience of disciplines spans corporate and product infrastructure as well as third party tooling and infrastructure.