Design and lead enterprise-wide security programmes from the ground up
Conduct proper risk assessments, build risk treatment plans, and speak fluent risk to boards and regulators
Architect secure systems and networks using defence-in-depth, zero trust, and secure-by-design principles
Implement and manage identity & access (IAM), encryption, firewalls, IDS/IPS, SIEM, and endpoint protection at scale
Run security operations: incident response, forensics, disaster recovery, and 24/7 monitoring
Perform security assessments, penetration test scoping, vulnerability management, and compliance audits (GDPR, ISO 27001, NIST, PCI-DSS)
Secure the full software development life cycle (DevSecOps, threat modelling, secure coding)
Write, enforce, and train on policies, standards, and handle supply-chain and third-party risk
Lead security governance, legal/compliance requirements, and business continuity planning
Communicate complex security topics clearly to C-suite, auditors, and technical teams alike

