Practice / Security leadership
Security leadership and program design
In my experience, the framework usually isn't the problem. It's how the team works, who can make decisions and whether the work addresses the real risks. Here's how I approach those gaps.
What security leadership actually covers
Controls are where everyone starts and they're not really the hard bit. The hard bit is deciding what the company will actually defend, naming who's accountable when that fails and making sure bad news reaches the people who can act on it while there's still time to act. Most of the technical work follows from those three.
So when a program is struggling, I don't start with which tool is missing. I start with which decisions are being made by people who lack the context. Usually there's also a risk the business has quietly accepted and never said out loud. That one tends to be the interesting one.
- Security program design, from a first hire through an established function
- Operating models: centralized, embedded, or a partnership with engineering
- Technical risk and compliance readiness without theater
- Fractional or interim security leadership when a team needs experienced coverage
Repairing a program that already exists
Repairing a program is different from building one. People, history and trust matter alongside budget. The fix can create another problem: a reorg that stalls delivery, a control engineers quietly work around, a metric that rewards the wrong behavior.
Often the useful work is finding the few decisions holding everything else up, making them explicit and giving somebody the authority to make them.
Where this comes from
25+ years in security across Microsoft, Netflix and Meta, moving from engineering into executive leadership. I helped create the Netflix SIRT, helped grow the security organization there from 4 engineers to 100+, and as Principal Security Engineering Manager for CodeQL at Microsoft I ran the program that took code scanning from minimal coverage to 90%+ across Windows, Xbox, Office 365 and other codebases.
LinkedIn, linked from my About page, carries the roles and dates.
Read the original writing
Ongoing long-form writing on leadership, cybersecurity and decision-making, published openly. Read First Order (opens in a new tab)