Career

Every Security Leader Is a Diplomat. The Good Ones Know It

Aditi Sharma
Director, Strategy & GTM
April 16, 2026
8 MIn read

Ready to secure your identity surface?

About the author

Aditi leads Go-to-Market (GTM) and Business Strategy at Zluri, where she helps mid-market organizations modernize their identity governance and access management practices. Prior to Zluri, she was a Management Consultant at McKinsey & Company advising large enterprises on digital transformation, and part of the enterprise software investment team at B Capital. She holds an engineering degree from IIT Kharagpur and an MBA from Harvard Business School.

Diplomacy is the craft of getting your way without authority: a diplomat cannot order the other side of the table to do anything, and the skilled ones win anyway, through preparation, translation, calculated concession, and composure under provocation. That craft has been studied, taught, and refined for centuries. Security leaders practice it every day without the name, the training, or the toolkit, and the name changes everything.

There's a role in every organization whose entire function is influence over territory it will never control. It can't compel the other parties to do anything. It succeeds through relationships, translation, and negotiation, and when it fails, the failure looks like being technically correct and completely ignored.

In international affairs, that role is called a diplomat, and centuries of practice have turned its methods into a teachable discipline: know the counterpart's interests better than they've stated them, phrase every position in the listener's language, trade what costs you little for what matters to them, build the coalition before the summit, and stay composed when the other side isn't.

In companies, that role is called a security leader, and the discipline mostly goes unnamed. Which is why so many security leaders experience the job as a frustrating anomaly, and why the diagnosis of that frustration, the belief that more authority would fix it, gets its own piece: "I don't have the authority" is the wrong complaint. This piece is the other half: the diplomat's toolkit, translated move by move for the security floor.

The Parallel, Made Precise

The comparison isn't a metaphor. Map what diplomats actually do against what effective security leadership actually requires, and the correspondence is nearly one-to-one:

The security leaders everyone describes as "just knowing how to get things done" are running this exact toolkit, usually without a name for it. The ones stuck in permanent friction are usually running its opposite: enforcement-first, translation never, escalation as the default move.

Why the Job Is Built This Way

The diplomatic shape of security leadership isn't an accident of weak org design. It follows from what security is.

Security's remit covers everything; its control covers almost nothing. The risks live in finance's vendor payments, HR's onboarding flow, engineering's repos, sales's CRM exports, and every SaaS tool any team ever adopted. Security is accountable for all of it and administers nearly none of it. A role accountable for territory it doesn't control has exactly one effective mode of operation, and it isn't command.

Everyone security deals with is optimizing for their own goals. Finance for predictable spend. IT for stability and ticket volume. Department heads for velocity. Employees for getting the job done with minimal friction. None of them are wrong; each is correctly pursuing what their function exists to pursue. That's not an obstacle to work around. It's the permanent terrain, and diplomats are precisely the professionals trained to treat other parties' self-interest as terrain rather than as offense.

The relationships are repeated games. Security negotiates with the same departments quarter after quarter, forever. One-time wins extracted through force poison the next ten negotiations. Compounding goodwill through fair dealing is the only strategy that survives the time horizon, which is exactly why career diplomats obsess over relationships and reputations rather than individual victories.

A security mandate is a treaty nobody helped write. It gets the compliance treaties: technical adherence, creative interpretation, and quiet violation the moment enforcement looks away.

The Toolkit, Translated to the Security Floor

Know the counterpart's brief better than they've stated it. Before any significant ask, learn what the other team is measured on this quarter, what recently burned them, what they've been complaining about. A ten-minute conversation does it. The payoff is the ability to frame the security initiative as relief for a pain they already feel: the access review pitched as ending half-day spreadsheet sessions, the governance platform pitched to finance as the spend visibility they've wanted for years.

Translate every position into the listener's interests. "We need to reduce standing access risk" is a position. "Your managers get their half-day back, and the audit finding that would land on your department doesn't happen" is the same position, translated. Diplomats never present demands in their own domestic language; security leaders shouldn't either:

  • To IT: the access tickets flooding their queue stop at the source, because provisioning and deprovisioning run themselves
  • To compliance: the evidence auditors ask for exists on demand, and the findings that would have surfaced get prevented before the audit instead of explained after it
  • To finance: the initiative surfaces unused licenses and duplicate spend, often enough to offset its own cost
  • To HR: new hires productive on day one, and the access complaints stop reaching them
  • To department heads: twenty-minute reviews, faster tool access for their teams, no incident that costs a sprint
  • To executives: what the board would ask after a breach, and the ninety-day plan that answers it

Concede visibly, and early. Give up the pieces that cost little, out loud: "You're right, we'll exempt that workflow." Visible concession proves negotiation is real, which is what keeps the other side at the table instead of routing around it. The department of no gets that name by never conceding anything, and earns the workarounds it then has to chase.

Build the coalition before the meeting. Budget meetings and steering committees ratify decisions made earlier, in one-on-ones. Walking into the room with finance already convinced by the offset math and compliance already sold on the evidence preview isn't manipulation. It's how anything at stake has ever been agreed.

Never force a counterpart to choose between the agreement and their own survival. Diplomats know a deal that requires the other side to fail cannot hold. The security equivalent: a rollout that genuinely cuts a sales team's velocity will be resisted, correctly, forever, and no messaging fixes it. When the plan collides with what a team is measured on, change the plan.

Composure is the uniform. Stakeholders will stall, dismiss, and personalize. The diplomatic read of a heated objection is that it points directly at the interest the plan failed to account for, which makes it intelligence, delivered rudely. The calmest person in a tense meeting controls it, and the reputation compounds: people bring real concerns to the composed negotiator and performative ones to the reactive one.

What This Looks Like When It Works

Take the hardest common case: rolling out identity governance, a program that touches every team in the building at once.

The enforcement version is familiar: select the platform, announce the process, mandate the reviews, escalate non-compliance. It reliably produces a rollout that technically deployed and practically stalled: rubber-stamped certifications, workaround tools, and a security team the organization treats as weather.

The diplomatic version starts months earlier and mostly consists of listening. Finance sees the SaaS waste the platform will surface, and arrives at the budget meeting as an advocate. IT hears the ticket queue shrinking and stops bracing for a new tool to babysit. HR co-designs the onboarding flow instead of receiving it. One respected department head pilots the twenty-minute review before anyone is asked to trust a memo. Compliance previews the audit evidence and starts pulling the project forward. Employees get a sanctioned path faster than their workarounds, which is the only argument that has ever beaten shadow IT.

Same platform, same end state on paper. Different outcomes entirely, and the difference was never technical. It was that someone worked the problem like a diplomat: learned what every party needed, and made the program answer those needs on its way to answering security's own.

The Good Ones Know It

The title of this piece has a second half, and it's the operative one. Every security leader is a diplomat by the shape of the role; the good ones know it, and the knowing changes how they spend their effort.

They stop experiencing other teams' self-interest as obstruction and start studying it as terrain. They stop waiting for authority and start banking influence. They measure themselves less on policies published and more on whether the organization says yes to them quickly. And they treat the map of what every team wants, kept current, the way a diplomat treats their briefing book: as the most valuable document they own.

Knowing what everyone else needs isn't a soft skill on the edge of security work. In a role where nearly everything requires someone else's voluntary cooperation, it is the work.

Frequently Asked Questions

How is this different from just "having good stakeholder management skills"?

Stakeholder management, as usually practiced, means keeping people informed and unblocking approvals. The diplomatic model is more demanding and more rewarding: it means knowing each party's actual interests before the ask, translating every initiative into their terms, trading concessions deliberately, and building coalitions before decisions get ratified. It's the difference between managing a process and working a negotiation, and security's hardest problems are negotiations.

Does the diplomatic model mean security should never use authority or escalate?

No, and real diplomats don't renounce force either; they make it credible by making it rare. The security leader who escalates only after visibly trying to accommodate gets taken seriously on the day it matters. The one who escalates by default gets tuned out. The working ratio: diplomacy constantly, authority rarely, and the rarity is what gives the authority its weight.

Where should a security leader start if the "department of no" reputation is already entrenched?

Start with an unprompted gift: fix something a department has been complaining about, surface data finance has wanted, shorten a process HR has flagged, before asking for anything. Reputations built on years of enforcement only move when the counterparty experiences the new mode first-hand and unprompted. One visible, uncompensated win for another team does more than any announcement of a friendlier posture.

How does a small security team find time for this kind of relationship work?

Scale it to the stakes. A minor request needs no campaign. But for anything significant, a rollout, a process change, a budget ask, the pre-conversations aren't overhead on the project, they're the critical path. Small teams can least afford the alternative: a stalled rollout costs a five-person team far more, proportionally, than the week of conversations that would have prevented it.

Ready to secure your identity surface?