Act as the accountable security executive to validate and sign compliance documentation and represent the company during enterprise vendor-risk reviews. Oversee the hardening of the Statement of Applicability, manage external penetration tests, and provide quarterly compliance reviews.