The role and job scope of a security team also depend on the stage of the business. It can be part of the IT team at the beginning; a dedicated security team for infrastructure security monitoring, moving toward a specialized security function team for security tool development and security policy management; or a security testing team, and so on.
Let's look at two kinds of typical scenario to discuss the role and the scope that an organization may have. One is the security engineering team under a CTO, and the other is a dedicated CSO with full, specialized functions of a security team.