Sr Security Principal - Local Risk Environment
Hewlett Packard EnterpriseAbout the role
This role has been designated as ‘Remote/Teleworker’, which means you will primarily work from home.
Who We Are:
Hewlett Packard Enterprise is the global edge-to-cloud company advancing the way people live and work. We help companies connect, protect, analyze, and act on their data and applications wherever they live, from edge to cloud, so they can turn insights into outcomes at the speed required to thrive in today’s complex world. Our culture thrives on finding new and better ways to accelerate what’s next. We know varied backgrounds are valued and succeed here. We have the flexibility to manage our work and personal needs. We make bold moves, together, and are a force for good. If you are looking to stretch and grow your career our culture will embrace you. Open up opportunities with HPE.
Job Description:
As Senior Security Principal, you'll play a critical role in protecting the integrity of HPE’s labs and non-production environments, collectively known as Local Risk Environments (LREs), which are intentionally segmented from the corporate network to enable innovation while effectively managing risk.
You’ll be responsible for ensuring these environments are designed, operated, and decommissioned in alignment with our security policies, risk frameworks, and regulatory obligations. This role strikes a balance between strategic leadership, strong risk management and business enablement - helping teams move fast without compromising security.
Reporting directly to the Senior Director of Governance, Risk, and Compliance (GRC), you’ll be a core member of the GRC leadership team with meaningful influence over enterprise security strategy, architecture decisions, and tooling investments.
With full ownership of the security program, you’ll lead its vision, execution, and ongoing evolution—including budget planning, control selection, and cross-functional alignment. This role offers a unique opportunity to shape how risk is governed in dynamic, high-velocity environments that power our innovation.
What You’ll Do
In this role, you’ll lead the design and delivery of a global security program that supports both risk reduction and business agility in these environments.
Defining the program’s vision, roadmap, and success metrics will be part of your strategic mandate, working cross-functionally with engineering, infrastructure, legal, and enterprise risk to bring it to life.
As chair of LRE risk forum, you guide leaders through complex, risk-based decisions and ensure alignment across stakeholders. You also serve as the voice of the environment's security in enterprise architecture and technology planning—shaping future solutions through a security-first lens.
Establishing risk frameworks for the entire lifecycle—from creation and operation to decommissioning—is core to the role. These frameworks will align with internal policies and standards such as NIST, ISO 27001, SOX, and GDPR.
You'll drive compliance by leading audits, performing assessments, and maintaining an accurate view of the environment' security posture. Regular reporting to senior leadership, the CISO, and audit bodies will help ensure accountability and transparency.
Working closely with local environment owners, you’ll help classify risks, configure environments securely, and ensure ongoing monitoring and resilience planning are in place. When incidents occur, your role includes supporting investigations and driving root cause remediation.
Collaboration is key - this role serves as a critical link between business units, IT, and security, ensuring that governance practices are practical, scalable, and support operational success.
Your subject matter expertise will be vital across projects involving new or evolving environments ensuring “secure-by-design” principles are embedded from the start.
Finally, you’ll continuously improve governance processes, evolving them to meet shifting business needs, regulatory changes, and emerging threats.
Key Competencies:
Strategic risk management - Thinks holistically about security and business needs, balancing risk mitigation with organizational goals and resources.
Network security & segmentation - Skilled in designing and governing secure network architectures, with a focus on segmentation, zero trust, and reducing lateral movement risks in isolated environments.
Technical communication - Translates complex security concepts into clear, business-focused language tailored for non-technical audiences.
Defense-in-depth implementation - Designs and integrates layered secu
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s