Principal Research Analyst – Information Security

Posted 1ds ago

Employment Information

Education
Salary
Experience
Job Type

Report this job

Job expired or something wrong with this job?

Job Description

Principal Research Analyst leading ISACA’s information security research, frameworks, and practitioner content. Representing the global technology association through thought leadership, events, and member guidance.

Responsibilities:

  • Lead the creation, review, and delivery of articles, audit programs, whitepapers, secondary research reports, and practitioner aids
  • Ensure content aligns with ISACA’s Professional Practices Program Strategy and industry standards
  • Provide input on materials, frameworks, and references to maintain high-quality outputs
  • Use AI responsibly and in compliance with organizational policies
  • Serve as an internal subject matter expert in information security and related professional practices
  • Recruit, mobilize, and manage volunteer SME groups to co-develop and validate ISACA content
  • Provide guidance and leadership during content and research project cycles
  • Represent ISACA at industry events, panels, podcasts, and webinars
  • Evaluate conference proposals and review final presentations for technical and strategic accuracy
  • Respond to member and partner technical inquiries
  • Maintain current expertise through professional seminars, literature review, and trend monitoring
  • Partner with business units, marketing, and events teams to integrate practice-area content across conferences, webinars, podcasts, and publications
  • Collaborate with ISACA leadership to align content with organizational messaging and priorities
  • Support ISACA marketing and brand-building efforts
  • Participate in activities that foster partnerships and elevate ISACA’s visibility and credibility

Requirements:

  • Bachelor’s Degree in a relevant field of study from an accredited university, or an equivalent combination of education and experience
  • Minimum of 8 years of experience in a similar role or capacity, with a demonstrated record of success
  • Experience responding to stakeholder inquiries and providing expert guidance and practical interpretation of industry practices and trends
  • Proven experience collaborating cross-functionally with business teams
  • Experience conducting secondary research and reporting
  • Track record of public-facing thought leadership: conference speaking, webinars, podcasts, or published articles
  • Additional 5+ years of enterprise information security program experience, including recent experience within the past 24 months securing modern, hybrid enterprise environments
  • Familiarity with NIST CSF, MITRE ATT&CK, ISO 27001, and CIS Controls
  • Deep working knowledge of network, endpoint, IAM, cloud, application security, and incident response domains
  • Knowledge of AWS, Azure, or GCP and cloud control frameworks and audit considerations
  • Required CISM or CISSP certification
  • Working knowledge of artificial intelligence technologies, current applications, appropriate use cases, and related risks
  • Experience evaluating vendors and markets, mapping capabilities, and performing competitive analysis
  • Critical thinking, collaboration, and cross-functional stakeholder engagement
  • Business writing skills
  • Proven ability to translate research into verbal presentations or written reports
  • Master’s Degree in Cybersecurity, Computer Science, Information Systems, or related field is preferred
  • 10+ years of experience in a similar role or capacity is preferred
  • Preferred experience in regulated industries or with regulators and compliance programs
  • Preferred experience with procurement, implementation, and operationalization of AI technologies
  • Preferred experience with threat intelligence, detection engineering, malware/attack analysis, and threat modeling
  • Preferred AAISM certification

Benefits:

  • Remote work
  • Travel opportunities to industry conferences, professional events, workshops, and external meetings
  • Occasional international travel depending on event participation and organizational priorities