Principal Technical Consultant – Cloud and Application Security

AHEAD

Northern (KY)

Hybrid

USD 250,000 - 300,000

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Medical, Dental, Vision Insurance
401(k)
Paid holidays
Paid time off
Parental and caregiver leave

Job summary

AHEAD is hiring a Principal Technical Consultant to lead security-focused engagements across cloud-native platforms. You will guide delivery teams, craft security delivery plans, and mentor engineers while shaping the practice and winning new work.

The role demands deep expertise in CNAPP tooling, cloud security, and DevSecOps, with strong communication and leadership across client delivery, business development, and thought leadership.

Qualifications

  • Undergraduate degree in Computer Science or Business Management preferred.
  • Minimum of 3+ years of leadership experience.
  • Professional certifications aligned to security portfolios are preferred (e.g. CISSP, CCSP, CSSLP, GIAC).
  • Demonstrated experience establishing or maturing application security programs and mentoring engineers.

Responsibilities

  • Leads sessions of strategy, roadmap, design, and planning workshops for small to medium sized service engagements.
  • Execute on project objectives, requirements gathering, milestones, timelines, to ensure engagements are delivered on time.
  • Create and finalize project deliverables and perform peer review for collateral.
  • Present deliverables effectively to project team members.
  • Define and operationalize security delivery plans, including secure SDLC controls and risk-based prioritization.
  • Lead application security and threat modeling workshops.

Skills

Workshop facilitation
Project delivery
Executive reporting
Problem solving

Education

Bachelor's degree in CS or Business Management

Tools

Wiz CNAPP
ServiceNow
CI/CD pipelines
Terraform
Bicep
AWS CloudFormation
Docker
Kubernetes
SAST/DAST/SCA

Job description

AHEAD builds platforms for digital business. By weaving together advances in cloud infrastructure, automation and analytics, and software delivery, we help enterprises deliver on the promise of digital transformation.


AtAHEAD, we prioritize creating a culture of belonging,where all perspectives and voices are represented, valued, respected, and heard. We create spaces to empower everyone to speak up, make change, and drive the culture at AHEAD.


We are an equal opportunity employer, and do not discriminate based on an individual's race, national origin, color, gender, gender identity, gender expression, sexual orientation, religion, age, disability, maritalstatus, or any other protected characteristic under applicable law, whether actual or perceived.


We embrace all candidates that will contribute to the diversification and enrichment of ideas and perspectives atAHEAD.


Principal Technical Consultants are seasoned experts in information security, cloud security, application security and DevSecOps, threat management, and related technologies, with the ability to secure applications and APIs across the cloud-native software delivery lifecycle. Successful candidates support the Security team in Delivery, Business Development, and Practice Development.


Duties and Responsibilities

The following are the expectations of a Principal Technical Consultant:


Client Delivery


  • Leadsessions of strategy, roadmap, design, and planning workshops for small to medium sized service engagements

  • Execute on project/programobjectives, requirements gathering, project tasks/milestone, project status, dependencies, and timelines, to ensure engagements are delivered successfully and on time while meeting the business objectives

  • Creation and finalization of project deliverables, may perform peer review for collateral developed by others on a delivery team

  • Effective presentation of deliverables to project team members.

  • Knowledge of AHEAD’s project lifecycle management activities to effectively support delivery engagements throughout the duration of a project

  • Define and operationalize application security delivery plans, including secure SDLC controls, risk-based finding prioritization, developer enablement, metrics, and executive reporting.

  • Lead application security and threat modeling workshops covering secure architecture, abuse cases, application and API risks, and remediation planning.


Technical Mastery


  • Proficiencyin technical troubleshooting; the ability to critically think about a problem and generate a creative solution with minimal oversight.

  • Deep knowledge of scripting, particularly with PowerShell and/or Python, and the ability to troubleshoot developed code.

  • Ability to triage andvalidateapplication security findings (SAST, DAST, SCA, secrets), distinguish exploitable issues from false positives, and recommend practical remediations.

  • Ability to effectively communicate aspects of a technical solution to a non-technical individual.

  • Capability to conduct research andutilizeavailable resources to fill in technical knowledge gaps where ambiguity presents itself.


Business Development


  • Support business development pursuits through client discovery meetings

  • Represent service offerings during the sales cycle, including project scoping, proposal development, and presenting proposals to clients

  • Knowledge of AHEAD’s sales managementlifecycle to effectively support sales opportunities throughout the duration of a proposal

  • Lead client discovery and/or visioning workshops toidentifyopportunities for cross-practice collaboration

  • Familiarity with AHEAD’s enterprise service portfolio toidentifyopportunities for cross-practice collaboration


Practice Development & Thought Leadership


  • Maintainsubject matterexpertisein a minimum ofeightsecurity domains or three security solutions

  • Participate in the development,enhancement, and standardizationof AHEADin-practiceserviceofferings

  • Owns and/or enables more than one service capability

  • Process-focusedtechnology thought leader and evangelist

  • Maintain a broad knowledge and understanding of current and future state IT trends, technologies, and standards

  • Lend supportand mentorship to others


Domain experience required

Cloud Security Architecture & Risk Strategy


  • Proven experience in reviewing and implementing secure cloud reference architectures and landing zones.

  • Experience designing Zero Trust and network segmentation architectures for cloud environments, including micro-segmentation, private connectivity, and egress controls.

  • Ability to translate risk strategy by mapping traditional lift-and-shift approaches into cloud-native security controls.

  • Strong understanding of multi-cloud governance models, including Infrastructure-as-Code (IaC), policy-as-code (PaC), tagging standards, and multi-account strategies.

  • Experience operationalizing a secure cloud SDLC by embeddingIaCscanning, policy-as-code guardrails, and drift detection into multi-account and multi-cloud deployment pipelines.


CNAPP Tooling


  • 5+ years of combined hands-on experience with CNAPP tools (Wizpreferred)

  • Expertise inintegratingCNAPPsolutionswith enterprise tooling such as ServiceNow, CI/CD pipelines, and ticketing/alerting workflows.

  • Experience extending CNAPP coverage into the SDLC byintegrating withsource repositories, CI/CD pipelines, and developer workflows to shift application security left.

  • Able toclearly and concisely communicateCNAPP(criticality, risk, remediation)to technical and business stakeholders.

  • Ability to unify application-layer findings (SAST, DAST, SCA, ASPM) with cloud posture and runtime context to prioritize remediation by real exploitability and business risk.

  • Strongtrack recordin deploying and instantiatingCNAPP solutions

  • Hands-on experienceleveragingthe application security and ASPM capabilities within CNAPP platforms — including code andIaCscanning, container image scanning,secretsdetection, and code-to-cloud traceability from source to running workload.


Cloud Platforms & Native Security Controls


  • 5+ years of experience working with GCPandcloud-native services (AWS and Azureexperience optional)

  • Deep understanding and specialistexpertisewith cloud-native security services such as Google Security Command Center, AWSSecurityHub, and/or MicrosoftDefender forCloud).

  • Familiarity with securing managed cloud AI/ML services (e.g., Vertex AI, Amazon Bedrock, Azure OpenAI), including identity and access scoping, data protection, and guardrails.

  • Hands-on knowledge of cloud identity (IAM, Federation, RBAC) across multi-cloud environments.

  • Familiarity withIDaaSsolutions such as Okta and Entra ID.

  • Demonstrated experience with leadingsecurecloud migration projects/programs.


Security Frameworks & Governance


  • Strong knowledge of security standards and frameworks: e.g. CIS Benchmarks, NIST, FedRAMP, ISO 27001, GDPR.

  • Ability to design and map cloud-specific controls for audit and compliance needs.

  • Experience with SIEM integration (Splunk, Sentinel, Chronicle) and cloud-native detection capabilities (optional).


DevSecOps and Application Security


  • Strong understanding of DevSecOps and secure coding best practices, including the ability to assess, implement, and mature application security programs against relevant industry frameworks and maturity models (e.g. OWASP SAMM, DSOMM)

  • Proficiency in application threat modeling (e.g., STRIDE, abuse-case and attack-surface analysis) conducted at design time and integrated into cloud-native and microservices architectures.

  • Experience with reviewing and remediating insecure CI/CD pipelines

  • Experience with Application Security Posture Management (ASPM) and risk-based vulnerability prioritization — correlating and de-duplicating findings across SAST, DAST, and SCA and orchestrating remediation at scale.

  • Hands-on knowledge of DevSecOps and Application Security tooling, including DAST, SAST, SCA, secrets detection, and related solutions.

  • Expertise in API security (REST and GraphQL), including the OWASP API Security Top 10, authentication/authorization and API gateway controls, and testing of APIs exposed by cloud-native and serverless workloads.

  • Ability to read, understand, and apply Infrastructure-as-Code (Terraform, Bicep, AWS CloudFormation).

  • Familiarity with policy-as-code tooling (OPA, Sentinel) and IaC scanning in CI/CD pipelines.

  • Proficiency in scripting (Python, PowerShell, Bash) to automate security tasks.

  • Ability to perform secure code review and secure design/architecture reviews across common languages and frameworks, translating findings into actionable developer guidance.

  • Experience with containerization (Docker, Kubernetes) and securing workloads at scale.

  • Experience securing the software supply chain, including SBOM generation and management, open-source and dependency risk governance, and artifact integrity and provenance (e.g., signing, SLSA).


Qualifications


  • Undergraduate degree in Computer Sciences or Business Management preferred, but not required

  • Minimum of

  • 3+years of leadership experience

  • 10+ years consulting experience, or commensurate work experience

  • Professional and/or technical certifications, including industry-recognized certifications which align to AHEAD’s Security service portfolio are preferred (e.g. CISSP, CCSP)

  • Application security certifications such as CSSLP, GIAC GWEB/GWAPT, OSCP, or equivalent are preferred.

  • Demonstrated experience establishing or maturing application security programs and mentoring engineers and security practitioners.

  • Excellent verbal and written communication skills

  • Comfortable addressing groups of people in virtual or in-person settings

  • Demonstrated Business Acumen

  • Ability to solve complex, abstract problems

  • Excellent interpersonal skills, good listener, ability to connect with different personalities

  • Exhibit Executive presence with leadership characteristics

  • Demonstrated experience as a technology change agent.


$250,000 - $300,000 a year


The compensation range indicated in this posting reflects the On-Target Earnings ("OTE") for this role, which includes a base salary and any applicable target bonus amount. This OTE range may vary based on the candidate’s relevant experience, qualifications, and geographic location.


Why AHEAD:

Through our daily work and internal groups like Moving Women AHEAD and RISE AHEAD, we value and benefit from diversity of people, ideas, experience, and everything in between.


We fuel growth by stacking our office with top-notch technologies in a multi-million-dollar lab, by encouraging cross department training and development, sponsoring certifications and credentials for continued learning.


USA Employment Benefits include:


  • Medical, Dental, and Vision Insurance

  • 401(k)

  • Paid company holidays

  • Paid time off

  • Paid parental and caregiver leave

  • Plus more! See benefits https://www.aheadbenefits.com/ for additional details.


Use of AI:

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, assessing responses, or to capture recordings and create transcriptions or summaries during interviews. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans.


If you would like more information about how your data is processed, please refer to the Candidate Privacy Notice or contact us at privacy@ahead.com. You may opt-out of the review or analysis of your application and resume by AI tools by using the General Application. Please include the role you wish to apply for in the Additional Information field. You may also choose to opt-out of recording and transcription at any time, including after joining an interview. Candidates will not be penalized for choosing to opt-out.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Project Manager: Security Services
Project Manager: Security Services

AHEAD • Northern (KY)

Hybrid
USD 140,000 - 170,000
Medical, Dental, and Vision Insurance
401(k)
Paid holidays
+2
Technical Account Manager, Managed Services Security
Technical Account Manager, Managed Services Security

AHEAD • Chicago (IL)

On-site
USD 150,000 - 155,000
Senior Client Solutions Engineer
Senior Client Solutions Engineer

AHEAD • San Ramon (CA)

On-site
USD 150,000 - 190,000
Medical insurance
Dental insurance
Vision insurance
+4
Senior Client Solutions Engineer
Senior Client Solutions Engineer

AHEAD • Sacramento (CA)

On-site
USD 140,000 - 230,000
Medical, Dental, Vision Insurance
401(k)
Paid time off
Senior Client Solutions Engineer
Senior Client Solutions Engineer

AHEAD • San Francisco (CA)

On-site
USD 150,000 - 210,000
Medical, Dental, and Vision Insurance
401(k)
Paid time off
+1
Senior Client Solutions Engineer
Senior Client Solutions Engineer

AHEAD • San Jose (CA)

On-site
USD 140,000 - 210,000
Medical, Dental, and Vision Insurance
401(k)
Paid company holidays
+2
Senior Identity Application Architect, CIAM/IAM
Senior Identity Application Architect, CIAM/IAM

AHEAD • Northern (KY)

Hybrid
USD 145,000 - 175,000
Medical Insurance
401(k)
Paid holidays
+2
Principal Consultant, Internal AI
Principal Consultant, Internal AI

AHEAD • United States

On-site
USD 140,000 - 190,000
Medical, Dental, and Vision Insurance
401(k)
Paid company holidays
+2
Senior AI Services Architect & Delivery Lead
Senior AI Services Architect & Delivery Lead

Medium • Chicago (IL)

On-site
USD 230,000 - 300,000
AI Enterprise Solutions Sales Executive
AI Enterprise Solutions Sales Executive

AHEAD • Boston (MA)

On-site