STIGroup Logo

STIGroup

Principal Consultant, Cyber Security

Posted 24 Days Ago
Be an Early Applicant
In-Office or Remote
Hiring Remotely in Glen Rock, NJ
185K-215K Annually
Expert/Leader
In-Office or Remote
Hiring Remotely in Glen Rock, NJ
185K-215K Annually
Expert/Leader
Lead end-to-end cyber security and GRC engagements as a hands-on principal consultant: perform technical assessments, framework-aligned audits (SOC 2, NIST, ISO, HIPAA), validate controls, design remediation roadmaps, advise on SIEM/MDR and IR, author policies, brief executives, and grow accounts through trusted advisory. Operate autonomously across multiple concurrent client engagements in regulated industries.
The summary above was generated by AI

About STIGroup

STIGroup (Secure Technology Integration Group) is a SOC 2 Type II certified MSSP and cyber advisory firm headquartered in Mahwah, NJ. Founded in 2000, we serve clients nationally, with a concentration in Metro NY/NJ, across managed security, GRC, and advisory services. Our work spans regulated industries including financial services, healthcare, life sciences, and critical infrastructure, and we operate as an embedded extension of our clients' teams.

Role summary

STIGroup is hiring a Principal Consultant who can operate credibly across hands-on technical assessment and framework-aligned GRC advisory. You will own engagements end to end across managed security, GRC, and advisory, working with CISOs and operators to mature their programs. In addition, this Principal Consultant will be expected to help expand existing client relationships by identifying follow-on opportunities, contributing to account growth, and serving as a trusted primary point of contact throughout the engagement lifecycle. This is a senior individual contributor role, not a people-management position.

What you will do

  • Serve as the primary trusted advisor for assigned accounts, building senior client relationships, shaping ongoing security strategy, and translating emerging needs into scoped follow-on work.
  • Maintain executive-level client relationships across the engagement lifecycle, align stakeholders on priorities, and proactively identify opportunities for additional advisory, GRC, and managed security support.
  • Lead end-to-end delivery of cyber security and GRC engagements: security assessments, control design, architecture review, gap analyses, roadmaps, and remediation plans.
  • Do the hands-on technical work: review client environments, read logs and packet captures, validate controls through active testing, and design across endpoint, network, identity, cloud, and perimeter security.
  • Run framework-aligned assessments against SOC 2, NIST CSF, NIST 800-53, ISO 27001, HIPAA, and CMMC as applicable, and turn findings into prioritized remediation plans.
  • Author policies, standards, and procedures, build risk registers and control libraries, and support third-party risk and audit-readiness work.
  • Advise on managed security operations (SIEM/MDR coverage, log sources, detection gaps, vulnerability management, IR readiness) and support active incident response when needed.
  • Brief executive and board audiences when the engagement calls for it, in language that connects technical findings to business impact.
  • Own account growth through trusted advisory work: spot follow-on consulting, GRC, and managed-service opportunities, partner with leadership to scope and close them, and treat expansion as a measure of engagement quality.
  • Produce clear client-facing deliverables (assessment reports, executive readouts, status updates) without heavy editorial oversight.

What you bring (required)

  • 10+ years of progressive cyber security experience, including 5+ in client-facing consulting or MSSP delivery with end-to-end engagement ownership.
  • Executive stakeholder management and consultative communication skills, with the ability to build credibility quickly with CISOs, IT leadership, and business stakeholders.
  • Experience identifying client needs, shaping solution scopes, and contributing to follow-on consulting or managed security opportunities in a way that aligns to client outcomes.
  • Strong commercial judgment, including the ability to balance delivery quality, client trust, and account growth.
  • Workshop facilitation and discovery skills, including leading client interviews, surfacing priorities, and translating ambiguous requirements into actionable plans.
  • Technical depth across several of: vulnerability management, SIEM/MDR/SOC operations, incident response, IAM/MFA/PAM, endpoint and network, cloud (AWS, Azure, M365), and security architecture.
  • Hands-on experience applying NIST CSF and NIST 800-53 to client assessments; working fluency with ISO 27001, SOC 2, HIPAA, and CIS Controls; you sequence remediation, not just identify gaps.
  • Track record owning multiple concurrent engagements as the primary delivery lead from scoping through closure.
  • Direct experience in at least one regulated vertical: healthcare, financial services, or critical infrastructure (transportation, utilities, energy).
  • Strong written and verbal communication; able to move between a technical SOC conversation and a board readout without losing either audience.
  • Autonomy: you manage your own engagement portfolio and exercise sound judgment under pressure.
  • Based in or commutable to the Metro New York area, with on-site client work across the region as needed.

Nice to have

  • Big 4 or tier-1 advisory experience (Deloitte, PwC, EY, KPMG) and/or boutique MSSP or cyber consulting experience.
  • CISSP, CISM, CISA, CRISC, or ISO 27001 Lead Auditor / Lead Implementer certifications.
  • Multi-year vCISO, fractional CISO, or executive-sponsor program advisory (board reporting, roadmap ownership) for regulated clients.
  • Hands-on familiarity with CrowdStrike, Microsoft Defender / Sentinel, Splunk, Qualys / Tenable, Palo Alto, Fortinet, Okta, ServiceNow / Jira.
  • Direct experience supporting transit or transportation clients (e.g., agencies the size of NJ Transit) is a strong plus.

Compensation and logistics

  • Employment type: W2, full time.
  • Location: Metro New York area; hybrid (remote with on-site client work). Travel up to 25%.
  • Compensation: $185,000 to $215,000 base, plus performance bonus, commensurate with experience and regulated-industry depth.
  • Reporting line: CISO

Similar Jobs

8 Minutes Ago
Remote
United States
170K-190K Annually
Senior level
170K-190K Annually
Senior level
Fintech • Information Technology • Software
Owns and builds SentiLink’s FCRA compliance program for its consumer reporting business. Responsibilities include dispute intake and reinvestigation, permissible-purpose controls, accuracy monitoring, consumer complaints, client diligence, regulatory inquiries, litigation support, and partnering with Engineering and Product to automate compliance workflows.
Top Skills: APIsCfpb PortalE-OscarMetro 2
15 Minutes Ago
Remote or Hybrid
United States
126K-213K Annually
Senior level
126K-213K Annually
Senior level
Artificial Intelligence • Cloud • Sales • Security • Software • Cybersecurity • Data Privacy
Leads technical customer engagements for strategic enterprise accounts, combining solution engineering, software implementation, consulting, and sales support. Responsibilities include discovering requirements, designing and documenting SailPoint solutions, conducting foundational implementations and proof-of-value engagements, educating customers on architecture and best practices, and developing AI-enabled demonstrations and agentic solutions. The role collaborates across sales, product, professional services, partners, and customer success, and may require up to 15% travel.
Top Skills: Active DirectoryAgentic AiAngularApplication ServersArtificial IntelligenceAWSAzureCassandraClaude CodeCSSCursorDatabasesGCPGithub CopilotGoogle AntigravityHTMLJavaJavaScriptJSONKiroLdapLinuxMachine LearningMicrosoft Sql ServerMongoDBMySQLNode.jsOne IdentityOpenai CodexOracleOracle Identity ManagerPeoplesoftPowershellReactRedisRsa AveksaSaaSSailpointSAPSaviyntServicenowSoapSpmlSpring BootSpring MvcSQLSybaseTypescriptUnixVirtualizationVueWeb ServicesWindowsXML
15 Minutes Ago
Remote or Hybrid
United States
126K-213K Annually
Senior level
126K-213K Annually
Senior level
Artificial Intelligence • Cloud • Sales • Security • Software • Cybersecurity • Data Privacy
Build and evolve SailPoint’s AWS-based internal migration platform through hands-on full-stack development, cloud infrastructure, AI agents, APIs, testing, CI/CD, observability, and security. The role uses Angular, FastAPI, Python, AWS CDK, and numerous AWS services. Responsibilities include architectural contributions, mentoring engineers, troubleshooting, stakeholder collaboration, and improving automation, reliability, developer productivity, and customer migration outcomes.
Top Skills: AiobotocoreAmazon BedrockAmazon EcsAngularApi GatewayAsyncioAws CdkAws CodeartifactAws FargateChart.JsCloudfrontCognitoDynamoDBEventbridgeFastapiGithub ActionsHtml2CanvasJasmineJspdfJszipJwtKarmaKmsLambdaOauth2PulumiPytestPythonRagRxjsS3Server-Sent EventsSqsStructlogTerraformTypescript

What you need to know about the Chicago Tech Scene

With vibrant neighborhoods, great food and more affordable housing than either coast, Chicago might be the most liveable major tech hub. It is the birthplace of modern commodities and futures trading, a national hub for logistics and commerce, and home to the American Medical Association and the American Bar Association. This diverse blend of industry influences has helped Chicago emerge as a major player in verticals like fintech, biotechnology, legal tech, e-commerce and logistics technology. It’s also a major hiring center for tech companies on both coasts.

Key Facts About Chicago Tech

  • Number of Tech Workers: 245,800; 5.2% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: McDonald’s, John Deere, Boeing, Morningstar
  • Key Industries: Artificial intelligence, biotechnology, fintech, software, logistics technology
  • Funding Landscape: $2.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Pritzker Group Venture Capital, Arch Venture Partners, MATH Venture Partners, Jump Capital, Hyde Park Venture Partners
  • Research Centers and Universities: Northwestern University, University of Chicago, University of Illinois Urbana-Champaign, Illinois Institute of Technology, Argonne National Laboratory, Fermi National Accelerator Laboratory

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account