ISACA

Principal Research Analyst - Information Security

ISACA$113K — $170K *
US-AnywhereRemote in United States
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in relevant field or equivalent experience.
  • At least 8 years in a similar role, with a successful track record.
  • Experience in responding to stakeholder inquiries and providing expert guidance.
  • Experience in conducting secondary research and reporting.
  • Proven thought leadership experience in public forums such as conferences and publications.
  • Minimum 5 years in enterprise information security, with recent experience in hybrid environments.
  • Deep knowledge of core cybersecurity domains and cloud control frameworks.

Responsibilities

  • Lead the creation and delivery of high-quality content like articles and reports.
  • Ensure content aligns with ISACA's standards and practices.
  • Manage volunteer expert groups for content co-development and validation.
  • Represent ISACA at industry events and evaluate conference materials.
  • Respond to technical inquiries from members and stakeholders.
  • Collaborate across teams for integration of content in various platforms.
  • Support marketing and branding efforts for enhanced organizational visibility.

Benefits

  • Career advancement opportunities within ISACA.
  • Participation in industry conferences and events.
  • Exposure to cutting-edge research and practices in cybersecurity.
  • Possibility of flexible work arrangements.
  • Networking opportunities within a global professional community.
Full Job Description
Overview

A Principal Research Analyst at ISACA leads the development, delivery, and continuous enhancement of high-quality forward-thinking content, guidance, and practitioner aids for their assigned area of expertise, ensuring alignment with ISACA's Professional Practices Program Strategy and industry standards. This role partners closely with business units, marketing, events teams, and ISACA leadership to integrate practice-area content consistently across conferences, webinars, publications, and other member-facing initiatives. Serving as a subject matter expert in their assigned practice area. This Principal Research Analyst recruits, mobilizes, and guides volunteer SME groups to co-develop and validate content, while providing expert guidance throughout content and research project cycles. The position represents ISACA externally at industry events, panels, and webinars, evaluates conference proposals, and ensures presentations meet technical and strategic standards.

Additionally, the role supports knowledge advancement by responding to member inquiries, monitoring trends, and maintaining up-to-date expertise, and contributes to ISACA's brand and marketing efforts to strengthen organizational visibility and credibility. This position requires consistent demonstration of critical thinking, collaboration, strong communication, analytical skills, and the ability to manage multiple priorities, embodying ISACA's values of People First, Curiosity, Passion, and Collaboration.

Responsibilities

Content Leadership & Development

Lead the creation, review, and delivery of content including articles, audit programs, whitepapers, secondary research reports, and practitioner aids.

Ensure content aligns with ISACA's Professional Practices Program Strategy and industry standards.

Provide input on materials, frameworks, and references to maintain high-quality outputs.

Use AI responsibly and in compliance with organizational policies

Subject Matter Expertise & Volunteer Engagement

Serve as internal SME within assigned professional practice (e.g., audit, emerging tech, GRC, information security, privacy).

Recruit, mobilize, and manage volunteer SME groups to co-develop and validate ISACA content.

Provide guidance and leadership during content and research project cycles e.g., exam prep materials, journal articles.

External Representation & Thought Leadership

Represent ISACA at industry events, panels, podcasts, and webinars to promote the organization's research and frameworks.

Evaluate conference proposals and review final presentations for technical and strategic accuracy.

Knowledge Advancement & Inquiry Support

Respond to member and partner technical inquiries within area of practice.

Maintain up-to-date knowledge by attending professional seminars, reviewing literature, and monitoring trends.

Cross-Functional Collaboration

Partner with business units, marketing, and events teams to ensure consistent, relevant integration of practice-area content across conferences, webinars, podcasts, and publications.

Collaborate with ISACA leadership to align professional practice content with organizational messaging and priorities.

Strategic and Brand Support

Support ISACA's marketing and brand-building efforts through strategic communication and collaboration.

Participate in activities that foster partnerships and elevate ISACA's visibility and credibility in the global ecosystem.

Qualifications

Required Field of Study:
  • Bachelor's Degree in a relevant field of study from an accredited university, or an equivalent combination of education and experience.

Minimum Years of Experience Required:
  • Minimum of 8 years of experience in a similar role or capacity, with a demonstrated record of success.
  • Experience responding to stakeholder inquiries, providing expert guidance and practical interpretation of industry practices and trends.
  • Proven experience collaborating cross-functionally with business teams

Required Experience:
  • Experience conducting secondary research and reporting
  • Track record of public-facing thought leadership: conference speaking, webinars, podcasts, or published articles
  • Additional 5+ years of enterprise information security program experience; must include recent experience (within past 24 months) securing modern, hybrid enterprise environments.
  • Familiarity with common frameworks and taxonomies (NIST CSF, MITRE ATT&CK, ISO 27001, CIS controls)
  • Deep working knowledge of core cybersecurity domains (network, endpoint, IAM, cloud, application security, incident response)
  • Knowledge of cloud platforms and cloud control frameworks (AWS/Azure/GCP and cloud audit considerations)

Preferred Field of Study:
  • Master's Degree in Cybersecurity, Computer Science, Information Systems, or related field from an accredited university.

Preferred Years of Experience:
  • 10+ years of experience in a similar role or capacity, with a demonstrated record of success.

Description of Preferred Experience:
  • Related experience in regulated industries (finance, healthcare, energy) or working with regulators and compliance programs
  • Direct involvement with procurement, implementation, and operationalization of AI technologies
  • Experience with threat intelligence, detection engineering, or malware/attack analysis
  • Experience performing threat modeling

Required Certifications:
  • CISM or CISSP

Preferred Certifications:
  • AAISM

Required Competencies/Skills:
  • Working knowledge of artificial intelligence technologies, current applications within assigned area of expertise, identification of appropriate use cases, and related risk.
  • Vendor and market research - evaluating products, mapping capabilities, and performing competitive analysis
  • Critical thinking, collaboration, and cross-functional stakeholder engagement
  • Business writing
  • Proven ability to translate research into content deliverables: verbal presentations or written reports

Travel may be required to attend industry conferences, professional events, workshops, and external meetings. Travel is primarily domestic, with occasional international travel depending on event participation and organizational priorities.

Posted Salary Range

USD $113,503.00 - USD $170,309.00 /Yr.

Benefits Information

Benefits Information available below:

ISACA Career Opportunities and Benefits

About ISACA

ISACA is an international professional association focused on IT governance. The association was founded in 1969 and has over 200,000 members in more than 180 countries. ISACA provides education, certification, and advocacy for IT professionals. The association is known for its COBIT framework, which is a set of best practices for IT governance. ISACA also offers certifications such as CISA, CISM, and CRISC. The association is headquartered in Rolling Meadows, Illinois.
Learn more about ISACA
Size
500 employees
Industry

Similar Jobs

More Jobs at ISACA

More Information Technology Jobs

Find similar Principal Research Analyst - Information Security jobs: