Có tâm, đủ tầm, phát triển, vươn xa, ...
Principal Security Consultant
Location
United States
Posted
144 days ago
Salary
$160K - $210K / year
Seniority
Lead
Job Description
Principal Security Consultant
ePlus Technology Solutions
• Business objectives; identified cyber risks, data risks, and regulatory requirements. Map these to ePlus security and data governance services to achieve measurable improvements in security posture, compliance, and information lifecycle management. Leverage the broader team to support these services as appropriate. • Effectively lead engagements as a subject matter expert (SME) to deliver client projects. Lead meetings, track team tasks, and present deliverables to client stakeholders across executive, operational, and technical audiences. • Conduct security and data governance program assessments and measure the effectiveness of client environments as it relates to: • Existing technical and administrative controls • Data classification and handling practices • Data lifecycle management • Privacy and regulatory compliance requirements • Alignment to industry security and governance frameworks • Design, develop, and operationalize Data Governance Programs, including: • Governance charters and operating models • Data ownership and stewardship models • Data classification frameworks • Data retention and disposition standards • Policy and control documentation • Risk scoring methodologies for sensitive and regulated data • Integration of data governance into existing security and compliance programs • Develop tailored consulting engagements specific to a client’s security and data governance maturity, risk profile, regulatory exposure, and budget constraints. • Develop and produce comprehensive engagement deliverables tailored to both technical and managerial audiences, fully detailing; • Technical execution • Identified control and governance deficiencies • Business and regulatory impact • Risk prioritization • Practical and sustainable remediation strategies • Establish credibility with the ePlus sales team and customers as a trusted advisor focused on risk identification, mitigation, and strategic program development across both cybersecurity and data governance domains • Conduct customer-facing presentations on ePlus’ core competencies, including security advisory services, governance strategy, compliance alignment, and data governance program development. • Assist the sales team with overall account planning as it relates to security and data governance program development services. • Assist the sales team with identifying and capturing customer business, regulatory, and data management requirements during the sales cycle and determining ePlus’ recommended solution approach. • Contribute to marketing and thought leadership initiatives via publishing research, speaking at industry conferences, authoring blog articles and whitepapers, hosting webinars, and developing repeatable security and data governance processes and templates. • Assist with practice development, including improving existing offerings, creating new service offerings (including emerging governance and AI/data risk services), and mentoring team members. • Foster client relationships by providing strategic guidance, proactive insight, and ongoing advisory support. • Lead technical scoping and review sessions with Client Security Principals, Account Executives, and sales teams, as well as customer stakeholders, to develop and finalize services proposals and Statements of Work. • Function as a subject matter expert (SME) for customer staff regarding proposed services and their design, purpose, delivery methodology, and measurable outcomes. • Conduct knowledge transfers with solution architect colleagues and sales teams regarding discovered technical and service opportunities, lessons learned from engagements, and emerging governance or regulatory trends. • As appropriate, assist the sales team in addressing customer satisfaction issues related to recommended solutions and assist in developing structured remediation or “get well” plans. • Identify emerging product or service candidates to sales and services management as new solution areas for ePlus to potentially develop or invest in, particularly in areas related to data governance, regulatory evolution, and risk management. • Complete and/or register for training and maintain relevant certifications in cybersecurity, governance, privacy, and regulatory frameworks as requested and approved by management. • Participate in weekly service pipeline and progress calls with the Managing Security Consultant Manager and be prepared to review: • Current pipeline opportunities • 60-day revenue forecast • Win probability • Estimated delivery timelines.
Job Requirements
- Bachelor’s degree preferred (Cyber Security and/or Computer Science)
- 5 to 10 years of applicable Security Consulting experience
- Hold certifications (CRISC, CISA, CISSP) commensurate with the technology and solutions focused on Security as well as Governance, Risk & Compliance (GRC)
- Security Consulting experience
- IT Audit General Controls knowledge
- Solutions selling sales cycle understanding
- Generating and presenting customer facing presentations
- Familiar with account planning, pipeline management and forecasting
- Ability to draft/compile well written proposals and statements of work and customer deliverables
- Advanced written and oral communication skills
- Seasoned in technical strategy and architecture steering, review, and documentation
- Well versed in threat modeling, attack frameworks, and industry standard program frameworks such as NIST, ISO 27001, CIS 20 and PCI
- Flexibility to accommodate changing schedules of client and project needs and willingness to work extended hours when needed
- Ability to discuss and sell Security Consulting engagements, based on Customer business needs, compliance standards and take ownership of closing and completing these engagements.
Benefits
- ePlus offers a full range of medical, financial, and/or other benefits (including 401(k) eligibility, employee stock purchase program and various paid time off benefits, such as vacation, sick time, and personal leave)
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
This description is a summary of our understanding of the job description. Click on 'Apply' button to find out more. Role Description This role is responsible for making our software secure by design and keeping it secure throughout its lifecycle — from architecture and development to deployment and operations. The Architect will define security standards, embed security into engineering workflows, and ensure our SaaS platform meets enterprise-grade security and compliance expectations. - Define and maintain secure architecture patterns for cloud-native SaaS systems - Review and approve system designs for security risks - Lead threat modeling for new features and platform components - Design secure multi-tenant isolation models - Architect secure API frameworks and integration patterns - Ensure tenant data isolation and encryption strategies - Continuously improve Secure SDLC practices - Define secure coding standards and guardrails - Architect secure cloud environments - Define IAM, least-privilege access models, and service-to-service authentication - Participate in security audits and customer security reviews - Lead security incident root-cause analysis for application-layer incidents - Improve detection and monitoring for application-level threats - Collaborate with SRE to ensure security does not compromise reliability Qualifications - 8+ years in software engineering, security engineering, or cloud architecture - Strong expertise in cloud-native architecture (microservices, containers, Kubernetes) - Deep understanding of application security (OWASP Top 10, secure coding) - Strong knowledge of IAM, authentication protocols (OAuth2, OIDC, SAML) - Experience designing secure multi-tenant SaaS systems - Hands-on experience with one major cloud provider (AWS preferred) Preferred Qualifications - Experience in enterprise SaaS environments - Experience with regulated industries (FedRAMP, CMMC) - Knowledge of tenant-based encryption models - Experience implementing zero-trust architecture - Background in vulnerability disclosure or bug bounty programs Salary The salary range for this role is $240,000 - $260,000. Actual compensation packages within this range are based on a wide array of factors unique to each candidate and role requirements, including but not limited to skill set, years and depth of experience, certifications, and specific location. Benefits - Medical, Dental, Vision Plans and HSA and FSA accounts - Basic Life and AD&D insurance; disability coverage where applicable - Retirement 401(k) Plan Option with Altium match - Employee Assistance Program - Paid holidays plus a “Choice Day” off per quarter - Paid time-off on arising schedule upon key milestones - Sick time for Dr. appointments or family health needs - Family medical, maternity, paternity, and military leave - Employee referral program - Remote working abroad program - Professional development support and resources - Free lunch, snacks, and drinks in the office - Free parking
Rejoignez Exposant 3 (E3) : La puissance de l’humain au cœur de la technologie ! Exposant 3 est une firme de services-conseils en gestion des affaires et technologies de l'information, dédiée à accompagner les entreprises et organismes dans leur transformation numérique et organisationnelle. 👉 Votre carrière chez Exposant 3 Nous croyons fermement en une gestion saine et humaine, où la confiance, la compétence, et le plaisir de réussir ensemble sont au centre de nos valeurs. Nous vous offrons bien plus qu’un simple emploi : rejoignez une équipe innovante où l’intelligence artificielle, l’automatisation des processus, et la modernisation technologique font partie du quotidien. Chez Exposant 3, nous mettons l’humain au cœur de tout ce que nous entreprenons. 🚀 Notre vision ? Vous permettre de déployer "la puissance de l’humain exposant 3" : - La puissance de l’individu : Un environnement où votre engagement est valorisé. - La puissance de l’équipe : Une collaboration forte où l’entraide et les réussites sont partagées. - La puissance de l’entreprise : Une vision commune pour des objectifs ambitieux et collectifs. Si vous cherchez à évoluer dans un cadre dynamique et à contribuer à des projets d’envergure, tout en grandissant au sein d’une entreprise humaine, innovante et en pleine croissance, alors Exposant 3 est fait pour vous ! Nous cherchons notre futur Technicien en sécurité de l’information, niveau intermédiaire, spécialisé en gestion des identités et des accès (GIA) pour rejoindre nos équipes. 🎯 Vos missions - Créer, supprimer ou modifier les comptes à privilèges élevés - Gérer les profils des comptes dans les annuaires de sécurité hébergés sur place (« on-premises ») et infonuagique - Octroyer et retirer les privilèges d’accès en conformité avec les processus et les règles établis - Assurer le suivi et le contrôle des différents répertoires de sécurité et des comptes à privilèges élevés - Réaliser les tâches de conformité sur les infrastructures dans le respect des procédures établies - Prendre en charge et résoudre les incidents de sécurité en GIA - Valider les demandes de services liées à la sécurité, évaluer les besoins, proposer des solutions pour y répondre et faire autoriser les demandes d’accès aux ressources informatiques par les détenteurs, gestionnaires et pilotes appropriés, selon les processus établis - Prendre en charge les demandes avec diligence, en recueillant l’information nécessaire auprès des intervenants concernés, pour améliorer la qualité du service et fournir un résultat complet dans les niveaux de service et de qualité attendus - Réaliser les actions nécessaires pour valider le résultat de ses actions en appliquant des mesures d’assurance qualité et assurer le suivi des demandes de la clientèle, de la qualité du résultat et de leur satisfaction - S’assurer du respect des processus et des normes établies en matière de sécurité de l’information et de GIA - Participer à l’amélioration, la modernisation et l’évolution des pratiques de gestion des identités et des accès en fonction du cadre de référence en gestion des identités et des accès (GIA) ainsi que des besoins de l’organisation - Collaborer aux exercices de révision des privilèges d’accès - Assurer l’exploitation des solutions de sécurité utilisées en GIA - Maintenir à jour les documents de référence (guides, procédures, etc.) - Assurer le transfert d’expertise au personnel désigné par le client - Prendre en charge toute autre responsabilité relevant d’un technicien en sécurité de l’information - Assurer le transfert des connaissances aux ressources désignées du client - Prendre en charge tout autre travail relevant d’un nom du profil sans spécialité 📝 Votre profil - Cinq années d’expérience dans le domaine des technologies de l’information, dont trois années à titre de technicien en sécurité de l’information spécialisé en gestion des identités et des accès (GIA) - Présenter deux mandats de 100 j-p chacun au cours des trois dernières années, pour des travaux en GIA à l’aide des annuaires de sécurité Microsoft Active Directory et/ou Microsoft Entra ID
IT Infrastructure, Security Engineer
Efovinity IncConnecting talent and technology https://lnkd.in/eEWE_dhk
• Automate and maintain deployment workflows to streamline robot cell rollouts, reduce manual setup, and eliminate recurring operational issues. • Containerise and stabilise our robotics software stack to ensure consistent, reproducible environments across development, cloud and deployed production systems. • Standardise and manage Linux and Windows environments, establishing repeatable configuration and provisioning practices. • Provision and maintain cloud infrastructure, including secure access, permissions and identity management (SSO, SSH), with clear ownership of reliability and recovery practices. • Configure and manage networking infrastructure, including VPNs and secure remote access. • Own endpoint security and system hardening across internal machines and deployed systems. • Design and operate monitoring and alerting systems, leading incident response, root cause analysis and preventative improvements. • Own operational intake and prioritisation of infrastructure issues, ensuring clear communication and structured resolution. • Maintain clear documentation of environments, incident learnings, processes and recovery procedures to ensure continuity.
• Provides rich and engaging synchronous and asynchronous learning experiences for students • Augments course content according to prescribed policies and procedures using appropriate asynchronous and synchronous tools under guidance from principal and coach • Prepares students for high stakes standardized tests • Understands that a primary responsibility is to establish and maintain positive rapport with families and regularly communicates with and responds to students and learning coaches/parents in a timely manner • Supports learning coaches/parents with student curricular and instructional issues, as well as basic troubleshooting in a virtual classroom environment that is in line with academy policies and procedures • Travels as required (on average once per month and/or approximately 20% of the time) for face-to-face professional development, student testing, and as required by school



