Head of Cyber - Harry
The Design Authority
"If I take this out, what gap am I opening — and can I prove it?"
Quick facts
| Title | Head of Cyber, Chief Security Architect, Director of Security Engineering |
| Company profile | 10,000+ employees, $1bn+ revenue |
| Budget authority | De facto — controls allocation across the portfolio, doesn't hold the signature |
| Reports to | Simon the CISO |
| Direct report | Sasha the Security Architect (and her peers) |
| Primary motivation | Walk into every decision with a recommendation he can defend against the architecture, not just the invoice |
Note on title variance
This title is used inconsistently across the market and it's worth not over-fitting the persona to one org chart shape. Job-description research explicitly gives this role budget influence and hiring authority — heads of cyber security set the roadmap, decide which tools to invest in, and how risk is reported to the board[1] — but at some companies "Head of Cyber Security" reports straight to the CIO and is the top security seat with no CISO above it, explicitly positioned as a stepping stone toward a future CISO title. The two-layer structure assumed here (Simon the CISO above, Sasha the Security Architect below) is the more common shape at 10,000+ employee / $1bn+ enterprises, but treat it as the common case, not a universal rule.
Role
Owns the security tooling portfolio/stack strategy. Translates the risk appetite of Simon the CISO into an actual set of products, coverage, and spend. Runs the team of Security Architects, including Sasha the Security Architect. The single point where technical reality, commercial reality, and board narrative are all supposed to meet — usually the one person expected to hold all three in his head at once.
A day/week in his calendar
- Mix of portfolio strategy, vendor meetings, internal stakeholder management, and firefighting.
- Regularly blindsided by renewals Paige the Procurement Officer surfaces with too little runway to make a good decision.
- Spends a disproportionate amount of time assembling narrative and evidence for Simon the CISO / the board rather than doing architecture work.
- Chases Sasha the Security Architect and her peers for status on tools he inherited and doesn't fully trust.
Objectives
- Build a portfolio that's genuinely defensible against a framework (MITRE, NIST CSF, internal control set), not just "purchased."[2][3]
- Find and kill duplicate/overlapping spend before Paige the Procurement Officer or the CFO finds it first.
- Walk into every decision window with a recommendation already costed, not scrambling at T-minus-30.
- Give Simon the CISO a story he can tell upward without getting caught out.
Pain points
- Institutional knowledge about what's actually deployed lives in individual engineers' heads and walks out the door when they leave. APQC research found only 8% of organizations consistently capture knowledge from departing employees, while 16% make no attempt at all[4].
- Manual consolidation analysis is weeks of spreadsheet work per category, done reactively, always racing a renewal clock. Tool-count estimates vary by methodology: 45 cybersecurity tools on average with analysts actively using fewer than half on any given day[5], versus 61 security tools each watching its own slice[6]. Do not collapse these into one fake average.
- Notice periods and renewal dates are scattered across contracts Paige the Procurement Officer holds, not natively visible to security until it's nearly too late — 69% of software contracts carry an auto-renew clause with a 30–90 day notice window[7]; Gartner data cited by Varisource indicates ~75% of SaaS vendors rely on auto-renewal as retention[8].
- Personally exposed if Simon the CISO gets blindsided in the board — this is the job that absorbs that risk on his behalf.
The Paige the Procurement Officer ↔ Harry the Head of Cyber scramble (procurement flags a security-tool renewal, architecture cannot answer in time, leverage is lost) is a synthesis, not a named survey. See Paige the Procurement Officer.
Relationships
- Simon the CISO: reports up, translates ground truth into board-ready evidence and a defensible number.
- Sasha the Security Architect: manages down, relies on her for on-the-ground verification but often distrusts the completeness of what surfaces informally.
- Paige the Procurement Officer: the core decision-window relationship — Paige the Procurement Officer flags a contract coming up for renewal, Harry the Head of Cyber has to answer what residual risk a cut or keep creates, fast, with evidence, or the default is auto-renew.
Empathy Mapping
Says
| "If I take this out, what gap am I opening — and can I prove it?" |
| "I need this costed, mapped, and evidenced before I take it upstairs." |
| "Why am I finding out about this renewal now?" |
| "Don't show me a vendor heatmap. Show me where we're actually covered." |
Does
| Owns portfolio strategy, acts as security design authority |
| Constantly reconciles technical reality with commercial reality |
| Builds the narrative/evidence Simon the CISO presents |
| Chases architects and vendors for ground truth |
Thinks
| "I'm the one who actually has to know, and I don't, not fully." |
| "If I miss this overlap, Paige the Procurement Officer or the CFO will find it, and that's worse." |
| "I inherited half of this stack — I don't trust what I didn't build." |
| "Every renewal is a test of whether I actually know my own estate." |
Feels
| Perpetually a step behind the renewal clock |
| Caught between technical truth and boardroom narrative |
| Quiet anxiety about institutional knowledge walking out the door |
| Motivated by control and being ahead of the problem, not behind it |
Design & marketing angle
This is the primary champion and likely economic influencer for ESProfiler even though Simon the CISO signs off.
Speak to Harry the Head of Cyber directly about decision windows, evidence assembly, and framework mapping — this is the person who will actually log in, run the baseline, and bring the recommendation upward.
Dollar-figure overlap findings land hardest here because it's his personal risk being reduced. Frame the product as the estate description he must already have when consultancy, audit, or the clock owned by Paige the Procurement Officer arrives — not as another tool in the sprawl he is trying to kill. See the Problem Statement.
Sources
- [1] Digital Waffle, Head of Cyber Security Job Description — sets the roadmap, decides which tools to invest in, how risk is reported to the board
- [2] SABSA — a control that cannot be traced to a business risk is not required
- [3] AttackIQ, What Does MITRE ATT&CK Coverage Really Mean? — untested coverage is unknown, not green
- [4] APQC via Argus Labs, The Tribal Knowledge Problem — 8% capture departing knowledge; 16% make no attempt
- [5] Secure.com, security tool sprawl — 45 tools; analysts use fewer than half on a given day
- [6] NHIMG / Securiti, tool sprawl and context loss — 61 security tools
- [7] BetterCloud — auto-renewals; 69%; 30–90 day notice
- [8] Varisource citing Gartner — ~75% of SaaS vendors rely on auto-renewal

