Championing security risk quantification, the full-time remote Principal Security Analyst will manage compliance activities, develop Key Risk Indicators, and lead internal and external security assessments to enhance the organization's governance and risk management processes. Key responsibilities Lead the security risk quantification program to facilitate informed decision-making across the organization Develop and report Key Risk Indicators to stakeholders, including the Executive Leadership Team and Board of Directors Coordinate security assessments and serve as the primary liaison with assessors and stakeholders to ensure successful completion of compliance activities Required qualifications 8+ years of experience in Information Technology and/or Security 3+ years of experience leading audit/assessment projects 3+ years of experience with risk management frameworks (e.g., NIST CSF) Experience with corporate GRC solutions (e.g., Archer, ServiceNow) Industry certifications such as CISSP, CRISC, CISM/CISA, or AWS/Azure certifications