Monitor and advise information security issues related to systems and workflow to ensure internal security controls are appropriate and operating as intended. Self-directed knowledge gathering from a combination of public and internal sources – able to answer questions that haven’t been asked before.