Unknown Company

Principal Consultant, Security Governance

new york, ny • Posted 6 days ago
Remote Contract Management & Strategy

Overview

Presidio, Where Teamwork and Innovation Shape the Future At Presidio, we're at the forefront of a global technology revolution, transforming industries through cutting‑edge digital solutions and next‑generation AI. We empower businesses – and their internal customers – to achieve more through innovation, automation, and intelligent insights.

Role Summary

A Principal Security Governance Consultant is expected to have deep expertise and a vast knowledge base in core information security governance, risk, compliance, and privacy domains. The consultant must present complex solutions concisely, blend multiple service offerings, and deliver a single aggregate final risk report/deliverable and executive presentation for audiences at all levels and skillsets. The consultant will review, understand, and interpret risk‑management and compliance frameworks, security standards, and privacy models. They must possess a practical understanding of Information Technology, including implementation of technical and administrative controls across various industry verticals and company sizes, assess those controls, and assist in strategically aligning security goals with business objectives. As a PCI QSA company, the role expands the pool of PCI Qualified Security Assessors (QSAs) and CMMC Registered Practitioners (RPs) on the Information Security Governance team to meet client demand. The ideal consultant holds certifications from both List A and List B of the QSA qualification requirements. If certification is not yet attained, the consultant is expected to achieve it within the first three months of employment, register for PCI QSA training within six months, and complete annual CPEs. If not yet a CMMC RP, certification must be obtained within three months of achieving PCI QSA certification.

Responsibilities

  • Lead client engagements and project execution providing information security consultation and assessment services, helping clients meet compliance obligations by evaluating their business, technology, and operations against industry security standards.
  • Educate, mentor, advise, and share expertise with clients and colleagues to aid decision‑making on topics such as Artificial Intelligence, organizational security strategy, and services scope; provide consultative guidance on complex projects.
  • Provide clear, organized findings and recommendations to clients and track progress toward resolution and compliance.
  • Consult with C‑level security leaders (CISO, CSO, CIO, etc.) and the Board of Directors of valued strategic clients.
  • Develop strategic, operational, and tactical recommendations tailored to each client to improve security posture and compliance.
  • Create detailed security roadmaps with short‑term, mid‑term, and long‑term goals that prioritize remediation and address all non‑compliance instances per regulatory, statutory, contractual, and organizational obligations.
  • Lead large security engagements in concert with other cybersecurity practices and Presidio teams.
  • Develop security policies, standards, and procedures custom‑tailored to each client’s culture, goals, and objectives using industry best practices and compliance requirements.
  • Review, analyze, and assess key factors—such as inherent risk, mitigating controls, business impact, likelihood—to determine organizational security risk.
  • Ensure and assess client alignment to, and/or compliance with, applicable regulatory, federal, state, local, contractual, and organizational requirements and best‑practice standards such as ISO 27001, NIST CSF, PCI DSS, HIPAA, FERPA, NIST 800‑171, and CMMC.
  • Partner with organizations to build a best‑of‑breed security program architecture reference model using frameworks such as ISO 27001, NIST 800‑53, and NIST CSF.
  • Collaborate with seasoned Principal Security Consultants to support execution of key services including Cloud Governance, Advisory Services, security program development, documentation review, and security consulting services.
  • Execute tabletop exercises, produce After‑Action Reports, and deliver PCI and CMMC advisory services (gap analysis, SAQs, ROCs, AOCs, readiness assessments).
  • Assist leadership in cybersecurity administrative functions such as documentation maintenance, peer review, and internal cybersecurity activities.

Travel Requirements

This is a remote role located in the Continental United States. Travel up to 30% to client locations may be required to deliver professional services.

Additional Professional Experience and Service Delivery Requirements

  • Strong professional expertise in information security with the ability to thoroughly understand complex principles and apply them practically.
  • Deliver consulting services on time and on budget.
  • Comfortably present security concepts and/or findings to both highly technical and non‑technical audiences.
  • Be analytical, detail‑oriented, innovative, and recognize opportunities to provide value‑added consulting services.
  • Manage multiple and simultaneous clients, tasks, and responsibilities; work alone or in small teams; achieve goals and proactively communicate progress.
  • Work collaboratively or independently as required by engagement needs.
  • Be flexible and embrace change, continuously evolving approaches based on changing requirements, new information, or updated guidance.

Required Skills and Experience

  • Bachelor's Degree in Information Security, IT, Computer Science, Engineering, or equivalent work or military experience.
  • 5–8 years previous consulting experience.
  • 5–8 years experience conducting security risk and compliance assessments.
  • 5–8 years evaluating compliance with regulatory and key IT standards such as HIPAA, PCI DSS, NIST CSF, ISO 27001, and similar.
  • Cloud experience with AWS, Azure, or Google Cloud Platform, or non‑foundational certification for any of these cloud platforms, or one of: Certified Cloud Security Professional (CCSP), Certificate of Cloud Security Knowledge (CCSK), GIAC Cloud Security Essentials (GCLD).
  • Possess at least one accredited, industry‑recognized professional certification from each list:
    • List A:
      • ISC² Certified Information Systems Security Professional (CISSP)
      • ISACA Certified Information Security Manager (CISM)
      • Certified ISO 27001 Lead Implementer
    • List B:
      • ISACA Certified Information Systems Auditor (CISA)
      • GIAC Systems and Network Auditor (GSNA)
      • Certified ISO 27001 Lead Auditor, Internal Auditor 1
      • IRCA ISMS Auditor or higher (e.g., Auditor/Lead Auditor, Principal Auditor)
      • IIA Certified Internal Auditor (CIA)

Preferred Skills and Experience

  • One or more AI certifications (e.g., ISO 42001, ISACA AAISM, ISACA AAIR, IAPP AIGP).
  • Experience leading AI security assessments, maturity reviews, and developing remediation roadmaps for clients.
  • Ability to translate technical AI risks into executive‑level recommendations and measurable controls.

Career Growth

Joining Presidio means stepping into a culture of trailblazers—thinkers, builders, and collaborators—who push the boundaries of what’s possible. With AI‑driven analytics, cloud solutions, cybersecurity, and next‑gen infrastructure, we enable businesses to stay ahead in an ever‑evolving digital world. Here, your impact is real: harness Generative AI, architect resilient digital ecosystems, or drive data‑driven transformation while shaping the future.

About Presidio

Presidio is committed to hiring the most qualified candidates to join our amazing culture. We attract and hire top talent from all backgrounds, including underrepresented and marginalized communities. We encourage women, people of color, people with disabilities, and veterans to apply. Diversity of skills and thought is a key component to our business success. We are a trusted ally for organizations across industries with a decades‑long history of building traditional IT foundations and deep expertise in AI, automation, security, networking, digital transformation, and cloud computing. We fill gaps, remove hurdles, optimize costs, and reduce risk by developing custom applications, providing managed services, and delivering actionable data insights.

EEO Statement

Applications will be accepted on a rolling basis.

Presidio has a strong commitment to the community we serve and our employees. As an Equal Opportunity Employer, we strive to have a workforce that includes the community we serve.

Presidio is an Equal Opportunity Employer Disability/Vets. We evaluate qualified applicants without regard to race, color, religion, sex, age, national origin, disability, veteran status, genetic information, and other legally protected categories.

The “Know Your Rights” Poster is available here:

Presidio EEO Policy Statement is available here:

Presidio is committed to working with and providing reasonable accommodations to individuals with disabilities. If you need a reasonable accommodation because of a disability for any part of the employment process, please send an e‑mail to and let us know the nature of your request and your contact information.

Presidio is a VEVRAA Federal Contractor requesting priority referrals of protected veterans for its openings. State Employment Services, please provide priority referrals to.

Notice of Massachusetts Candidates: It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.

Recruitment Agencies, Please Note: Presidio does not accept unsolicited agency resumes/CVs. Do not forward resumes/CVs to our career’s email address, Presidio employees or any other means. Presidio is not responsible for any feeds related to unsolicited resumes/CVs.

#J-18808-Ljbffr
Back to Job Search