Principal Research Analyst - Information Security

ISACA

United States

On-site

USD 114,000 - 170,000

Full time

39 hours ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

ISACA is seeking a Principal Research Analyst to lead content development across articles, whitepapers, and practitioner aids, coordinating with leadership to ensure alignment with strategy.

The role recruits volunteer SME groups, represents ISACA at events, and maintains up-to-date expertise while driving brand visibility and credibility in a global ecosystem.

Qualifications

  • Bachelor’s degree in a relevant field; equivalent experience considered.
  • Minimum 8 years in a similar role with a track record of success.
  • Experience responding to stakeholder inquiries with expert guidance.
  • Proven cross-functional collaboration with business teams.
  • Public-facing thought leadership: conferences, webinars, or articles.
  • 5+ years of enterprise information security program experience; recent hybrid environments.

Responsibilities

  • Lead content creation and delivery of content including articles, audit programs, whitepapers, secondary research reports, and practitioner aids.
  • Recruit, mobilize, and guide volunteer SME groups to co-develop and validate content.
  • Represent ISACA at industry events, panels, podcasts, and webinars to promote the organization’s research and frameworks.
  • Respond to member and partner technical inquiries within area of practice; monitor trends.
  • Collaborate with ISACA leadership to align content with organizational priorities across conferences, webinars, publications.
  • Travel may be required to attend industry conferences and external meetings.

Skills

Critical thinking
Collaboration
Cross-functional stakeholder
Business writing
Verbal presentations

Education

Bachelor's Degree
Master’s Degree

Job description

About ISACA

ISACA® (www.isaca.org) champions the global workforce advancing trust in technology. For more than 55 years, ISACA has empowered its community of 195,000+ members with the knowledge, credentials, training and network they need to thrive in fields like information security, governance, assurance, risk management, data privacy and emerging tech. With a presence in more than 195 countries and with more than 230 chapters worldwide, ISACA offers resources tailored to every stage of members' careers - helping them to thrive in a rapidly changing digital landscape, drive trusted innovation and ensure a more secure digital world. Through the ISACA Foundation, ISACA also expands IT and education career pathways, fostering opportunities to grow the next generation of technology professionals.

About ISACA

ISACA® (www.isaca.org) champions the global workforce advancing trust in technology. For more than 55 years, ISACA has empowered its community of 195,000+ members with the knowledge, credentials, training and network they need to thrive in fields like information security, governance, assurance, risk management, data privacy and emerging tech. With a presence in more than 195 countries and with more than 230 chapters worldwide, ISACA offers resources tailored to every stage of members' careers - helping them to thrive in a rapidly changing digital landscape, drive trusted innovation and ensure a more secure digital world. Through the ISACA Foundation, ISACA also expands IT and education career pathways, fostering opportunities to grow the next generation of technology professionals.

Overview

A Principal Research Analyst at ISACA leads the development, delivery, and continuous enhancement of high-quality forward-thinking content, guidance, and practitioner aids for their assigned area of expertise, ensuring alignment with ISACA's Professional Practices Program Strategy and industry standards. This role partners closely with business units, marketing, events teams, and ISACA leadership to integrate practice‑area content consistently across conferences, webinars, publications, and other member-facing initiatives. Serving as a subject matter expert in their assigned practice area. This Principal Research Analyst recruits, mobilizes, and guides volunteer SME groups to co‑develop and validate content, while providing expert guidance throughout content and research project cycles. The position represents ISACA externally at industry events, panels, and webinars, evaluates conference proposals, and ensures presentations meet technical and strategic standards. Additionally, the role supports knowledge advancement by responding to member inquiries, monitoring trends, and maintaining up-to-date expertise, and contributes to ISACA’s brand and marketing efforts to strengthen organizational visibility and credibility. This position requires consistent demonstration of critical thinking, collaboration, strong communication, analytical skills, and the ability to manage multiple priorities, embodying ISACA’s values of People First, Curiosity, Passion, and Collaboration.

Responsibilities
Content Leadership & Development

Lead the creation, review, and delivery of content including articles, audit programs, whitepapers, secondary research reports, and practitioner aids. Ensure content aligns with ISACA's Professional Practices Program Strategy and industry standards. Provide input on materials, frameworks, and references to maintain high-quality outputs. Use AI responsibly and in compliance with organizational policies.

Subject Matter Expertise & Volunteer Engagement

Serve as internal SME within assigned professional practice (e.g., audit, emerging tech, GRC, information security, privacy). Recruit, mobilize, and manage volunteer SME groups to co-develop and validate ISACA content. Provide guidance and leadership during content and research project cycles e.g., exam prep materials, journal articles.

External Representation & Thought Leadership

Represent ISACA at industry events, panels, podcasts, and webinars to promote the organization’s research and frameworks. Evaluate conference proposals and review final presentations for technical and strategic accuracy.

Knowledge Advancement & Inquiry Support

Respond to member and partner technical inquiries within area of practice. Maintain up-to-date knowledge by attending professional seminars, reviewing literature, and monitoring trends.

Cross-Functional Collaboration

Partner with business units, marketing, and events teams to ensure consistent, relevant integration of practice‑area content across conferences, webinars, podcasts, and publications. Collaborate with ISACA leadership to align professional practice content with organizational messaging and priorities.

Strategic and Brand Support

Support ISACA’s marketing and brand‑building efforts through strategic communication and collaboration. Participate in activities that foster partnerships and elevate ISACA’s visibility and credibility in the global ecosystem.

Travel may be required to attend industry conferences, professional events, workshops, and external meetings. Travel is primarily domestic, with occasional international travel depending on event participation and organizational priorities.

Qualifications
Required Field of Study
  • Bachelor’s Degree in a relevant field of study from an accredited university, or an equivalent combination of education and experience.
Minimum Years Of Experience Required
  • Minimum of 8 years of experience in a similar role or capacity, with a demonstrated record of success.
  • Experience responding to stakeholder inquiries, providing expert guidance and practical interpretation of industry practices and trends.
  • Proven experience collaborating cross-functional with business teams
Required Experience
  • Experience conducting secondary research and reporting
  • Track record of public-facing thought leadership: conference speaking, webinars, podcasts, or published articles
  • Additional 5+ years of enterprise information security program experience; must include recent experience (within past 24 months) securing modern, hybrid enterprise environments.
  • Familiarity with common frameworks and taxonomies (NIST CSF, MITRE ATT&CK, ISO 27001, CIS controls)
  • Deep working knowledge of core cybersecurity domains (network, endpoint, IAM, cloud, application security, incident response)
  • Knowledge of cloud platforms and cloud control frameworks (AWS/Azure/GCP and cloud audit considerations)
Preferred Field Of Study
  • Master’s Degree in Cybersecurity, Computer Science, Information Systems, or related field from an accredited university.
Preferred Years Of Experience
  • 10+ years of experience in a similar role or capacity, with a demonstrated record of success.
Description Of Preferred Experience
  • Related experience in regulated industries (finance, healthcare, energy) or working with regulators and compliance programs
  • Direct involvement with procurement, implementation, and operationalization of AI technologies
  • Experience with threat intelligence, detection engineering, or malware/attack analysis
  • Experience performing threat modeling
Required Certifications
  • CISM or CISSP
Preferred Certifications
  • AAISM
Required Competencies/Skills
  • Working knowledge of artificial intelligence technologies, current applications within assigned area of expertise, identification of appropriate use cases, and related risk.
  • Vendor and market research - evaluating products, mapping capabilities, and performing competitive analysis
  • Critical thinking, collaboration, and cross-functional stakeholder engagement
  • Business writing
  • Proven ability to translate research into content deliverables: verbal presentations or written reports
Equal Opportunity Employer (EEO)

ISACA is proud to be an equal opportunity employer. ISACA is committed to building an environment of diversity, equity, and inclusion where equal employment opportunities are available to all applicants and employees without regard to race, color, religion, sex (including pregnancy and gender identity), national origin, age, ancestry, disability, genetic information, citizenship, sexual orientation, veteran status, marital status, familial status, military discharge status, or any other characteristic or status protected by federal, state, or local law. We support an inclusive workplace where employees excel based on merit, qualifications, experience, and ability.

Posted Salary Range

USD $113,503.00 - USD $170,309.00 /Yr.

Benefits Information

Benefits Information available below:

ISACA Career Opportunities and Benefits

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Sr Information Security Analyst II - IT
Sr Information Security Analyst II - IT

Federal Reserve Board of Governors • Washington

On-site
USD 130,000 - 180,000
Strategic Account Executive, Global Sales
Strategic Account Executive, Global Sales

ISACA • United States

Remote
USD 123,000 - 150,000
Approved Training Programs Intake Coordinator
Approved Training Programs Intake Coordinator

ISACA • United States

On-site
USD 45,000 - 63,000
Sr Information Security Analyst II - IT
Sr Information Security Analyst II - IT

Federal Reserve System • Washington

On-site
USD 141,000 - 243,000
Relocation provided
Senior Associate/Cybersecurity Consultant Due Diligence Advisory (Forensic Services practice)
Senior Associate/Cybersecurity Consultant Due Diligence Advisory (Forensic Services practice)

Charles River Associates • Washington

Hybrid
USD 130,000 - 153,000
Wellness programs
Commuter benefits
Senior Associate/Cybersecurity Consultant Due Diligence Advisory (Forensic Services practice)
Senior Associate/Cybersecurity Consultant Due Diligence Advisory (Forensic Services practice)

Charles River Associates • Houston (TX)

Hybrid
USD 130,000 - 153,000
Bonus potential
Comprehensive benefits
401(k) match
+1
Senior Associate/Cybersecurity Consultant Due Diligence Advisory (Forensic Services practice)
Senior Associate/Cybersecurity Consultant Due Diligence Advisory (Forensic Services practice)

Charles River Associates • New York (NY)

Hybrid
USD 130,000 - 153,000
100 hours of training annually
Comprehensive benefits package
Immigration support
+1
Senior Associate/Cybersecurity Consultant Due Diligence Advisory (Forensic Services practice)
Senior Associate/Cybersecurity Consultant Due Diligence Advisory (Forensic Services practice)

Charles River Associates • Chicago (IL)

Hybrid
USD 130,000 - 153,000
Benefits package
Wellness programs
Commuter benefits
Senior Associate/Cybersecurity Consultant Due Diligence Advisory (Forensic Services practice)
Senior Associate/Cybersecurity Consultant Due Diligence Advisory (Forensic Services practice)

Charles River Associates • Oakland (CA)

On-site
USD 130,000 - 153,000
Senior Associate/Cybersecurity Consultant Due Diligence Advisory (Forensic Services practice)
Senior Associate/Cybersecurity Consultant Due Diligence Advisory (Forensic Services practice)

Charles River Associates • United States

Hybrid
USD 130,000 - 153,000