1,161,622open jobs
13,727companies
227,717added this week
Browse all
Salary
$250k – $300k per year
Location
In office
Seniority
Principal · 10+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match
AHEAD helps enterprises build modern, secure, and scalable digital platforms by combining cloud, data, AI, and automation. Their consulting and managed services drive real business impact through smarter IT.

Principal Technical Consultants are seasoned experts in information security, cloud security, application securityand DevSecOps, threat management, and related technologies, with the ability to secure applications and APIs across the cloud-native software delivery lifecycle. Successful candidates support the Security team in Delivery, Business Development, and Practice Development.

Principal Technical Consultants collaborate with a diverse team of consultants with varying skills to meet and exceed client expectations through scoped engagements. They effectively facilitate and lead client engagements remotely by guiding engagements toward scoped objectives and troubleshooting to effectively resolve project risks or issues. Principal Technical Consultants effectively lead client delivery engagements by executing the necessary project tasks, producing expected collateral, and presenting artifacts at any time throughout an engagement, while acting in a leadership capacity to the project team(s).

Principal Technical Consultants also support business development activities alongside a sales specialist to qualify client needs and expectations or demonstrate a capability or skillset. They may be directly engaged in client-facing interactions to identify client needs and to produce and/or present sales proposals, leading client-visioning, or discovery sessions. Principal Technical Consultants may also collaborate with other AHEAD Practice areas to identify complex, cross-practice solution sets to achieve a client’s desired state or outcome.

AHEAD Principal Technical Consultants leverage their visibility and experience to contribute to the continuous improvement and maturation of in-practice service offerings and capabilities. This includes proposing ideas for new offerings and/or changes to existing offerings or initiatives, as well as their corresponding GTM efforts. They are considered a technical leader within the practice and expected to positively impact the services portfolio and individuals on the team through thought leadership and mentorship.

Duties and Responsibilities

  • The following are the expectations of a Principal Technical Consultant:

    Client Delivery

    • Lead sessions of strategy, roadmap, design, and planning workshops for small to medium sized service engagements

    • Execute on project/program objectives, requirements gathering, project tasks/milestone, project status, dependencies, and timelines, to ensure engagements are delivered successfully and on time while meeting the business objectives

    • Creation and finalization of project deliverables, may perform peer review for collateral developed by others on a delivery team

    • Effective presentation of deliverables to project team members.

    • Knowledge of AHEAD’s project lifecycle management activities to effectively support delivery engagements throughout the duration of a project

    • Define and operationalize application security delivery plans, including secure SDLC controls, risk-based finding prioritization, developer enablement, metrics, and executive reporting.

    • Lead application security and threat modeling workshops covering secure architecture, abuse cases, application and API risks, and remediation planning.

    Technical Mastery

    • Proficiency in technical troubleshooting; the ability to critically think about a problem and generate a creative solution with minimal oversight.

    • Deep knowledge of scripting, particularly with PowerShell and/or Python, and the ability to troubleshoot developed code.

    • Ability to triage and validate application security findings (SAST, DAST, SCA, secrets), distinguish exploitable issues from false positives, and recommend practical remediations.

    • Ability to effectively communicate aspects of a technical solution to a non-technical individual.

    • Capability to conduct research and utilize available resources to fill in technical knowledge gaps where ambiguity presents itself.

    Business Development

    • Support business development pursuits through client discovery meetings

    • Represent service offerings during the sales cycle, including project scoping, proposal development, and presenting proposals to clients

    • Knowledge of AHEAD’s sales management lifecycle to effectively support sales opportunities throughout the duration of a proposal

    • Lead client discovery and/or visioning workshops to identify opportunities for cross-practice collaboration

    • Familiarity with AHEAD’s enterprise service portfolio to identify opportunities for cross-practice collaboration

    Practice Development & Thought Leadership

    • Maintain subject matter expertise in a minimum of eight security domains or three security solutions

    • Participate in the development, enhancement, and standardization of AHEAD in-practice service offerings

    • Owns and/or enables more than one service capability

    • Process-focused technology thought leader and evangelist

    • Maintain a broad knowledge and understanding of current and future state IT trends, technologies, and standards

    • Lend support and mentorship to others

Domain experience required

  • Cloud Security Architecture & Risk Strategy

    • Proven experience in reviewing and implementing secure cloud reference architectures and landing zones.

    • Experience designing Zero Trust and network segmentation architectures for cloud environments, including micro-segmentation, private connectivity, and egress controls.

    • Ability to translate risk strategy by mapping traditional lift-and-shift approaches into cloud-native security controls.

    • Strong understanding of multi-cloud governance models, including Infrastructure-as-Code (IaC), policy-as-code (PaC), tagging standards, and multi-account strategies.

    • Experience operationalizing a secure cloud SDLC by embedding IaC scanning, policy-as-code guardrails, and drift detection into multi-account and multi-cloud deployment pipelines.

    CNAPP Tooling

    • 5+ years of combined hands-on experience with CNAPP tools (Wiz preferred)

    • Expertise in integrating CNAPP solutions with enterprise tooling such as ServiceNow, CI/CD pipelines, and ticketing/alerting workflows.

    • Experience extending CNAPP coverage into the SDLC by integrating with source repositories, CI/CD pipelines, and developer workflows to shift application security left.

    • Able to clearly and concisely communicate CNAPP (criticality, risk, remediation) to technical and business stakeholders.

    • Ability to unify application-layer findings (SAST, DAST, SCA, ASPM) with cloud posture and runtime context to prioritize remediation by real exploitability and business risk.

    • Strong track record in deploying and instantiating CNAPP solutions

    • Hands-on experience leveraging the application security and ASPM capabilities within CNAPP platforms - including code and IaC scanning, container image scanning, secrets detection, and code-to-cloud traceability from source to running workload.

    Cloud Platforms & Native Security Controls

    • 5+ years of experience working with GCP and cloud-native services (AWS and Azure experience optional)

    • Deep understanding and specialist expertise with cloud-native security services such as Google Security Command Center, AWS Security Hub, and/or Microsoft Defender for Cloud).

    • Familiarity with securing managed cloud AI/ML services (e.g., Vertex AI, Amazon Bedrock, Azure OpenAI), including identity and access scoping, data protection, and guardrails.

    • Hands-on knowledge of cloud identity (IAM, Federation, RBAC) across multi-cloud environments.

    • Familiarity with IDaaS solutions such as Okta and Entra ID.

    • Demonstrated experience with leading secure cloud migration projects/programs.

    Security Frameworks & Governance

    • Strong knowledge of security standards and frameworks: e.g. CIS Benchmarks, NIST, FedRAMP, ISO 27001, GDPR.

    • Ability to design and map cloud-specific controls for audit and compliance needs.

    • Experience with SIEM integration (Splunk, Sentinel, Chronicle) and cloud-native detection capabilities (optional).

    DevSecOps and Application Security

    • Strong understanding of DevSecOps and secure coding best practices, including the ability to assess, implement, and mature application security programs against relevant industry frameworks and maturity models (e.g. OWASP SAMM, DSOMM)

    • Proficiency in application threat modeling (e.g., STRIDE, abuse-case and attack-surface analysis) conducted at design time and integrated into cloud-native and microservices architectures.

    • Experience with reviewing and remediating insecure CI/CD pipelines

    • Experience with Application Security Posture Management (ASPM) and risk-based vulnerability prioritization - correlating and de-duplicating findings across SAST, DAST, and SCA and orchestrating remediation at scale.

    • Hands-on knowledge of DevSecOps and Application Security tooling, including DAST, SAST, SCA, secrets detection, and related solutions.

    • Expertise in API security (REST and GraphQL), including the OWASP API Security Top 10, authentication/authorization and API gateway controls, and testing of APIs exposed by cloud-native and serverless workloads.

    • Ability to read, understand, and apply Infrastructure-as-Code (Terraform, Bicep, AWS CloudFormation).

    • Familiarity with policy-as-code tooling (OPA, Sentinel) and IaC scanning in CI/CD pipelines.

    • Proficiency in scripting (Python, PowerShell, Bash) to automate security tasks.

    • Ability to perform secure code review and secure design/architecture reviews across common languages and frameworks, translating findings into actionable developer guidance.

    • Experience with containerization (Docker, Kubernetes) and securing workloads at scale.

    • Experience securing the software supply chain, including SBOM generation and management, open-source and dependency risk governance, and artifact integrity and provenance (e.g., signing, SLSA).

Qualifications

    • Undergraduate degree in Computer Sciences or Business Management preferred, but not required

    • Minimum of

    • 3+ years of leadership experience

    • 10+ years consulting experience, or commensurate work experience

    • Professional and/or technical certifications, including industry-recognized certifications which align to AHEAD’s Security service portfolio are preferred (e.g. CISSP, CCSP)

    • Application security certifications such as CSSLP, GIAC GWEB/GWAPT, OSCP, or equivalent are preferred.

    • Demonstrated experience establishing or maturing application security programs and mentoring engineers and security practitioners.

    • Excellent verbal and written communication skills

    • Comfortable addressing groups of people in virtual or in-person settings

    • Demonstrated Business Acumen

    • Ability to solve complex, abstract problems

    • Excellent interpersonal skills, good listener, ability to connect with different personalities

    • Exhibit Executive presence with leadership characteristics

    • Demonstrated experience as a technology change agent.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
1,161,622 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
In your city
$180k – $322k per year • In office • 15+ years exp • Bachelor's Degree • Herndon
Python
DevOps
Ansible
AWS
Azure
CI/CD
FinOps
GCP
Red Hat
Terraform
Cybersecurity
FedRAMP
SOC 2
Zero Trust
Management
Google Workspace
ServiceNow
Apply
$106k – $177k per year • Remote • 13+ years exp • High School Diploma
DevOps
Ansible
AWS
Azure
Configuration Management
Git
GitHub
Red Hat
Terraform
Windows Server
Apply
$109k – $222k per year (Estimated) • Remote • 7+ years exp
AI/ML
Anomaly Detection
LLM
LLM Guardrails
DevOps
AWS
CI/CD
Cybersecurity
Threat Modeling
Apply
In office • 5+ years exp • Bachelor's Degree
Ruby
TypeScript
Ruby
Ruby on Rails
Databases
ElasticSearch
Redis
DevOps
Amazon S3
AWS
AWS Lambda
CDKTF
CI/CD
CircleCI
Docker
GitHub
GitHub Actions
Jenkins
Terraform
Apply
$120k – $135k per year • Remote • 5+ years exp • PhD
Python
Ruby
TypeScript
Ruby
Ruby on Rails
Databases
Amazon Aurora
DynamoDB
MySQL
OpenSearch
PostgreSQL
DevOps
Amazon EC2
Amazon ECS
AWS
AWS Fargate
AWS Lambda
CI/CD
Docker
FinOps
GitHub
IAM
Platform Engineering
Terraform
Terragrunt
Cybersecurity
Least Privilege
Apply
AI Sales Specialist 3 days ago
$360k – $400k per year • Remote/Hybrid • Full-Time • 5+ years exp • Bachelor's Degree • San Ramon
Marketing
Salesforce
Apply
$140k – $170k per year • Remote • Full-Time • 3+ years exp
DevOps
Azure
GCP
IAM
Apply
Data Engineer 6 days ago
$150k – $180k per year • Remote • Full-Time • 3+ years exp • Bachelor's Degree
Python
SQL
Python
Hatch
Databases
Snowflake
AI/ML
AI Agents
dbt
Model Context Protocol
Agentic Workflows
Frontend
GraphQL
DevOps
Azure
CI/CD
Analytics
ETL/ELT
Marketing
Salesforce
Apply
$200k – $225k per year • Remote • Full-Time • 5+ years exp • Bachelor's Degree
DevOps
VMWare
Apply
$160k – $190k per year • Remote • Public Trust • Bachelor's Degree
JavaScript
AI/ML
AI Agents
Function Calling
Hallucination
LLM
Prompt Engineering
RAG
DevOps
Platform Engineering
Vector
Apply
See all jobs
This is one of many
1,161,622 more open roles from verified company boards, updated every day.