Jobs and Careers
PR

Principal Consultant, Security Governance

Presidio
Remote, United States, United StatesRemotefull_timeVerifiedPosted 1 Jul 2026

About the role

Presidio, Where Teamwork and Innovation Shape the Future
At Presidio, we're at the forefront of a global technology revolution, transforming industries through cutting-edge digital solutions and next-generation AI. We empower businesses - and their internal customers - to achieve more through innovation, automation, and intelligent insights.

The Role
A Principal Security Governance Consultant is expected to have a deep level of expertise and vast knowledge base in core information security governance, risk, compliance, and privacy domains. It is critical that a Principal Security Governance Consultant be able to present complex solutions and topics in a concise manner. The consultant must be comfortable blending multiple service offerings and deliverables into a single aggregate final risk report/deliverable and executive presentation for audiences of all levels and skillsets.

The consultant will have experience in reviewing, understanding, and interpreting risk management and compliance frameworks, security standards, and privacy models. The consultant must have a professional and practical understanding of Information Technology, including how technical and administrative controls are implemented across various industry verticals and company sizes. The candidate should be well versed in assessing said controls, understand how controls should be governed, and be able to assist in the strategic development of aligning security goals to business objectives. 

As a PCI QSA company, we are expanding the pool of PCI Qualified Security Assessors (QSAs) and CMMC Registered Practitioners (RPs) on the Information Security Governance (ISG) team to meet client demand.  The ideal consultant will have a certification from both List A and List B from the QSA qualification requirements listed below. If a certification has not yet been attained from either List A or List B, the consultant will be expected to attain a certification within the first 3 months of employment in order to register for PCI QSA training within 6 months of hire date and complete CPEs annually to renew certifications. If the consultant is not yet a CMMC RP, the consultant will be expected to attain CMMC RP certification within 3 months of attaining PCI QSA certification.

Travel Requirements: 

This is a remote role located in the Continental US.  You will be required to travel up to 30% to client locations to deliver professional services when needed.

Responsibilities Include:

  • Lead client engagements and project execution providing information security consultation and assessment services, helping our clients meet their compliance obligations by evaluating their business, technology, and operations against industry security standards 
  • Educate, mentor, advise, and share your expertise with clients and colleagues to aid in making decisions on topics like Artificial Intelligence, organizational security strategy and services scope as well provide consultative guidance on complex projects 
  • Providing clear, organized findings and recommendations to clients and tracking progress towards resolution and compliance 
  • Consult/advise with C-level Security Leaders (CISO, CSO, CIO, etc.) and the Board of Directors with our most valued and strategic clients  
  • Develop strategic, operational, and tactical recommendations tailored to each client with the intent to improve a client’s security posture and compliance position 
  • Create detailed strategic security roadmaps with short-term, mid-term, and long-term goals that prioritize remediation recommendations and address all instances of non-compliance with applicable regulatory, statutory, contractual, and organizational obligations 
  • Lead large security engagements in concert with other cybersecurity practices and Presidio teams 
  • Develop security policies, standards, and procedures that are custom-tailored to each client’s unique culture, security goals, and organizational objectives using industry best practices and compliance requirements 
  • Review, analyze, and assess key factors, including inherent risk, mitigating controls, business impact, likelihood and other key elements to determine organizational security risk 
  • Ensure and assess client alignment to, and/or compliance with, applicable regulatory, federal, state, local, contractual, and organizational requirements and best practices standards such as ISO 27001, NIST Cyber Security Framework (CSF), PCI DSS, HIPAA, FERPA, NIST 800-171, CMMC, etc.

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Presidio

View company profile →