Principal Research Analyst – Information Security

atISACARemoteUS flagUnited StatesFull-timeSecurity AnalystLead$113.5k – $170.3k/year

Posted 1 day ago

This is a fully remote position, open to applicants in United States.

📋 Description

• Oversee the development, assessment, and distribution of articles, audit programs, whitepapers, secondary research reports, and practical aids for professionals.

• Ensure that all content is in alignment with ISACA’s Professional Practices Program Strategy and adheres to industry standards.

• Contribute insights on materials, frameworks, and references to uphold the quality of outputs.

• Utilize AI responsibly and in accordance with organizational policies.

• Act as an internal subject matter expert in information security and associated professional practices.

• Recruit, mobilize, and supervise volunteer SME groups to collaboratively develop and validate ISACA content.

• Provide leadership and guidance throughout the content and research project cycles.

• Represent ISACA at industry events, panels, podcasts, and webinars.

• Assess conference proposals and review final presentations for technical and strategic accuracy.

• Address technical inquiries from members and partners.

• Maintain up-to-date expertise through participation in professional seminars, literature reviews, and trend monitoring.

• Collaborate with business units, marketing, and events teams to incorporate practice-area content across conferences, webinars, podcasts, and publications.

• Work together with ISACA leadership to ensure content aligns with organizational messaging and priorities.

• Support ISACA’s marketing and brand-building initiatives.

• Engage in activities that promote partnerships and enhance ISACA’s visibility and credibility.


⛳️ Requirements

• Bachelor’s Degree in a relevant field from an accredited institution, or an equivalent combination of education and experience.

• At least 8 years of experience in a similar role or capacity, demonstrating a proven record of success.

• Experience in responding to stakeholder inquiries while providing expert guidance and practical interpretations of industry practices and trends.

• Demonstrated ability to collaborate cross-functionally with business teams.

• Experience in conducting secondary research and reporting findings.

• Established track record of public-facing thought leadership, including conference speaking, webinars, podcasts, or published articles.

• An additional 5+ years of experience in enterprise information security programs, including recent experience within the last 24 months in securing modern, hybrid enterprise environments.

• Familiarity with NIST CSF, MITRE ATT&CK, ISO 27001, and CIS Controls.

• In-depth working knowledge of network, endpoint, IAM, cloud, application security, and incident response domains.

• Knowledge of AWS, Azure, or GCP along with cloud control frameworks and audit considerations.

• Required certifications: CISM or CISSP.

• Working knowledge of artificial intelligence technologies, their current applications, appropriate use cases, and associated risks.

• Experience in evaluating vendors and markets, mapping capabilities, and performing competitive analysis.

• Strong critical thinking, collaboration, and cross-functional stakeholder engagement skills.

• Proficient in business writing.

• Proven capability to translate research into verbal presentations or written reports.

• Master’s Degree in Cybersecurity, Computer Science, Information Systems, or a related field is preferred.

• Over 10 years of experience in a similar role or capacity is preferred.

• Preferred experience in regulated industries or with regulatory and compliance programs.

• Preferred experience in the procurement, implementation, and operationalization of AI technologies.

• Preferred experience with threat intelligence, detection engineering, malware/attack analysis, and threat modeling.

• Preferred AAISM certification.


🏝️ Benefits

• Remote work options available.

• Opportunities for travel to industry conferences, professional events, workshops, and external meetings.

• Occasional international travel based on event participation and organizational priorities.

People also viewed

DigitalOcean11 hours ago

Senior Security Analyst

US flagWashington OnlyFull-timeSecurity Analyst$140.8k – $176k/year
ApplyView job
DigitalOcean11 hours ago

Senior Security Analyst

US flagUnited States OnlyFull-timeSecurity Analyst$140.8k – $176k/year
ApplyView job
Ascension17 hours ago

Senior Analyst – Cybersecurity

US flagUnited States OnlyFull-timeSecurity Analyst$96.2k – $134.1k/year
ApplyView job
Arbiter19 hours ago

Security Analyst

US flagUnited States OnlyFull-timeSecurity Analyst$75k – $85k/year
ApplyView job
Selbetti Tecnologia1 day ago

Senior IT Security Analyst

BR flagBrazil OnlyFull-timeSecurity Analyst
ApplyView job
Cadmus Soluções em TI1 day ago

Mid-Level SAP GRC AC Security Analyst/Consultant

BR flagBrazil OnlyFreelanceSecurity Analyst
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers