Cyber Security Principal
- Salary
- $150K–$175K
- Hiring from
- United States
- Work type
- Hybrid
- Posted
Show job descriptionHide job description
The Cyber Security Principal is a senior, client-facing cybersecurity advisor who performs the function of a virtual Chief Information Security Officer (vCISO) for assigned Tusker clients. The role leads executive advisory relationships and helps clients build, govern, and mature cybersecurity programs that align security investment with business priorities, regulatory obligations, and risk tolerance.
The Cyber Security Principal owns the strategic direction and operating cadence of assigned engagements while coordinating the broader Tusker team responsible for assessment, architecture, implementation, managed services, and program support. Success requires executive presence, practical judgment, strong program discipline, and the ability to convert complex cyber risk into clear decisions, sequenced roadmaps, and measurable outcomes.
Key Responsibilities
Client Executive Advisory and Engagement Leadership
-
Serve as the primary trusted cybersecurity advisor to client executives, leadership teams, and boards for assigned accounts.
-
Establish engagement objectives, governance, decision rights, meeting cadence, success measures, and executive reporting expectations.
-
Translate technical findings, threat conditions, and compliance obligations into business impact, clear choices, and prioritized actions.
-
Build durable client relationships through proactive communication, sound judgment, transparency, and follow-through.
-
Manage multiple client programs while maintaining quality, consistency, and responsiveness.
Cybersecurity Strategy, Governance, and Maturation
-
Assess current-state program maturity and define target-state capabilities using the framework most appropriate to each client.
-
Develop and maintain multi-year cybersecurity maturation roadmaps aligned to business strategy, budgets, risk tolerance, and regulatory requirements.
-
Create or improve governance structures, policies, standards, risk registers, performance measures, and reporting mechanisms.
-
Guide security budgeting, investment prioritization, and risk-treatment decisions.
-
Define meaningful key risk and performance indicators and use them to demonstrate progress and support executive decisions.
Risk, Compliance, Resilience, and Third-Party Oversight
-
Lead or guide cybersecurity risk assessments, gap assessments, and remediation planning.
-
Advise clients on alignment with NIST CSF, NIST 800-53/171, CIS Controls, ISO 27001, CMMC, PCI DSS, HIPAA, and SOC 2, as applicable.
-
Support audit and assessment readiness without representing Tusker as the independent auditor or attestation body.
-
Lead third-party risk discussions, vendor due diligence, and risk-based review of critical service providers.
-
Develop, review, and exercise incident response and cyber resilience plans, including executive and board-level tabletop exercises.
-
Advise on the secure adoption of cloud, AI, and emerging technologies.
Tusker Delivery and Growth Collaboration
-
Coordinate with Tusker Solution Architects, technical delivery teams, Managed Services, Advisory, Sales, and external partners to translate roadmaps into executable work.
-
Clarify ownership, dependencies, timing, and expected outcomes across strategic and technical workstreams.
-
Provide cybersecurity subject-matter expertise during qualified sales pursuits, client workshops, renewals, and expansion discussions.
-
Help shape repeatable vCISO methods, templates, reporting, service standards, and quality controls.
-
Mentor colleagues and strengthen the ability of Tusker teams to identify advisory needs and engage the right resources.
Required Qualifications
-
12 or more years of progressive cybersecurity experience, including significant responsibility for cybersecurity strategy, governance, risk, compliance, and program leadership.
-
Experience serving as a CISO, vCISO, deputy CISO, security executive, or equivalent senior cybersecurity leader.
-
Demonstrated ownership of cybersecurity programs, budgets, risk decisions, executive reporting, and board-level communication.
-
Proven ability to lead strategic assessments, create multi-year roadmaps, and guide security-program maturation.
-
Strong working knowledge of NIST CSF, NIST 800-53/171, CIS Controls, ISO 27001, CMMC, PCI DSS, HIPAA, and SOC 2.
-
Experience leading incident response planning, executive exercises, third-party risk activities, and governance or policy programs.
-
Executive-level communication, facilitation, writing, and presentation skills, with the ability to communicate clearly to technical and non-technical audiences.
-
Ability to lead through influence across client teams, Tusker teams, and external providers.
-
Ability to manage multiple concurrent client engagements and operate effectively in ambiguous situations.
-
High ethical standards, discretion, and professional integrity.
-
Candidate should reside within approximately two hours driving distance of Chicago and be able to travel periodically based on client and business needs.
Preferred Qualifications
-
Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, Business, or a related field; advanced degree is a plus.
-
One or more relevant certifications, including CISSP, CISM, CRISC, CISA, CDPSE, or CIPP.
-
Experience delivering vCISO, cybersecurity advisory, consulting, MSP, or MSSP services to mid-market clients.
-
Experience in regulated industries such as healthcare, financial services, manufacturing, education, public sector, or organizations in the defense industrial base.
-
Familiarity with GRC platforms, compliance automation, common security operations capabilities, and the commercial realities of outsourced service delivery.
Tusker is an equal opportunity employer that is committed to diversity and inclusion in the workplace. We prohibit discrimination and harassment of any kind based on race, color, sex, religion, sexual orientation, national origin, disability, genetic information, pregnancy, or any other protected characteristic as outlined by federal, state, or local laws.
We seek team members from all backgrounds to join our organization, and we encourage our employees to bring their authentic, unique, and best selves to work.
This policy applies to all employment practices within our organization, including hiring, recruiting, promotion, termination, layoff, recall, leave of absence, compensation, benefits, and training.
Tusker makes hiring decisions based solely on qualifications, merit, and business needs at the time.