
Principal Research Analyst – Information Security
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in United States.
• Oversee the development, assessment, and distribution of articles, audit programs, whitepapers, secondary research reports, and practical aids for professionals.
• Ensure that all content is in alignment with ISACA’s Professional Practices Program Strategy and adheres to industry standards.
• Contribute insights on materials, frameworks, and references to uphold the quality of outputs.
• Utilize AI responsibly and in accordance with organizational policies.
• Act as an internal subject matter expert in information security and associated professional practices.
• Recruit, mobilize, and supervise volunteer SME groups to collaboratively develop and validate ISACA content.
• Provide leadership and guidance throughout the content and research project cycles.
• Represent ISACA at industry events, panels, podcasts, and webinars.
• Assess conference proposals and review final presentations for technical and strategic accuracy.
• Address technical inquiries from members and partners.
• Maintain up-to-date expertise through participation in professional seminars, literature reviews, and trend monitoring.
• Collaborate with business units, marketing, and events teams to incorporate practice-area content across conferences, webinars, podcasts, and publications.
• Work together with ISACA leadership to ensure content aligns with organizational messaging and priorities.
• Support ISACA’s marketing and brand-building initiatives.
• Engage in activities that promote partnerships and enhance ISACA’s visibility and credibility.
• Bachelor’s Degree in a relevant field from an accredited institution, or an equivalent combination of education and experience.
• At least 8 years of experience in a similar role or capacity, demonstrating a proven record of success.
• Experience in responding to stakeholder inquiries while providing expert guidance and practical interpretations of industry practices and trends.
• Demonstrated ability to collaborate cross-functionally with business teams.
• Experience in conducting secondary research and reporting findings.
• Established track record of public-facing thought leadership, including conference speaking, webinars, podcasts, or published articles.
• An additional 5+ years of experience in enterprise information security programs, including recent experience within the last 24 months in securing modern, hybrid enterprise environments.
• Familiarity with NIST CSF, MITRE ATT&CK, ISO 27001, and CIS Controls.
• In-depth working knowledge of network, endpoint, IAM, cloud, application security, and incident response domains.
• Knowledge of AWS, Azure, or GCP along with cloud control frameworks and audit considerations.
• Required certifications: CISM or CISSP.
• Working knowledge of artificial intelligence technologies, their current applications, appropriate use cases, and associated risks.
• Experience in evaluating vendors and markets, mapping capabilities, and performing competitive analysis.
• Strong critical thinking, collaboration, and cross-functional stakeholder engagement skills.
• Proficient in business writing.
• Proven capability to translate research into verbal presentations or written reports.
• Master’s Degree in Cybersecurity, Computer Science, Information Systems, or a related field is preferred.
• Over 10 years of experience in a similar role or capacity is preferred.
• Preferred experience in regulated industries or with regulatory and compliance programs.
• Preferred experience in the procurement, implementation, and operationalization of AI technologies.
• Preferred experience with threat intelligence, detection engineering, malware/attack analysis, and threat modeling.
• Preferred AAISM certification.
• Remote work options available.
• Opportunities for travel to industry conferences, professional events, workshops, and external meetings.
• Occasional international travel based on event participation and organizational priorities.
DigitalOcean
DigitalOcean
Ascension
Arbiter
Get handpicked remote jobs straight to your inbox weekly.