372,254open jobs
9,642companies
49,764added this week
Browse all
Salary
$126k – $251k per year (Estimated)
Location
Remote (United States)
Seniority
Principal · 5+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match
Ferguson is a major North American value-added distributor of plumbing, HVAC, waterworks, appliances, and industrial building supplies. Headquartered in Newport News, Virginia, the enterprise serves commercial and residential contractors, civil infrastructure developers, and institutional facilities managers through an extensive distribution network.

Job Posting:

Since 1953, Ferguson has been a source of quality supplies for a variety of industries. Together We Build Better infrastructure, better homes and better businesses. We exist to make our customers’ complex projects simple, successful, and sustainable. We proactively solve problems, adapt and grow to continuously serve our customers, communities and each other. Ferguson, a Fortune 500 company, is proud to provide best-in-class products, service and capabilities across the following industries: Commercial/Mechanical, Facilities Supply, Fire and Fabrication, HVAC, Industrial, Residential Trade, Residential Building and Remodel, Waterworks and Residential Digital Commerce. Ferguson has approximately 36,000 associates across 1,700 locations. Ferguson is a community of proud associates who operate with the shared purpose of building something meaningful. You will build a career that you are proud of, at a company you can believe in.

Principal Information Security Engineer - Governance, Risk & Security Awareness

The Principal Information Security Engineer - Governance, Risk & Security Awareness is an experienced cybersecurity leader responsible for strengthening Ferguson's security posture through enterprise risk management, security governance, third-party risk oversight, and security awareness initiatives. This role serves as a trusted advisor across the organization, helping identify, assess, communicate, and reduce cybersecurity risks while advancing security maturity and risk management practices.

A primary focus of this role is leading Ferguson's phishing simulation and security awareness program, driving a proactive approach to human risk management. This includes developing and executing risk-informed phishing campaigns, measuring program effectiveness, analyzing user behavior trends, and implementing targeted awareness strategies that strengthen cybersecurity knowledge and behavior across the enterprise. The role also leads enterprise risk assessments, third-party security reviews, governance initiatives, and executive reporting that support informed decision-making and risk-based prioritization.

Partnering closely with peers across Information Security, Technology, Internal Audit, Procurement, Legal, HR, Communications, and business leadership, the Principal Information Security Engineer translates complex cybersecurity risks into actionable business insights and recommendations. The ideal candidate brings deep expertise in cybersecurity governance, enterprise risk management, security awareness, and threat mitigation, combined with strong communication, stakeholder influence, and program leadership skills.

Location: This role is approved to be fully remote and can be based anywhere in the continental United States.

Duties & Responsibilities:

  • Lead cybersecurity risk assessments and security maturity evaluations using industry frameworks, including NIST CSF, identifying control gaps, emerging risks, and opportunities to strengthen Ferguson's security posture.
  • Develop risk mitigation strategies, remediation plans, and governance recommendations, partnering with business and technology teams to drive sustainable risk reduction.
  • Support the development and continuous improvement of cybersecurity governance processes, security roadmaps, risk registers, and program performance metrics.
  • Coordinate and support internal and external audits, independent security assessments, regulatory reviews, and risk management initiatives.
  • Lead Ferguson's enterprise simulated phishing exercises and cybersecurity education program, developing risk-based campaigns and targeted training initiatives that improve employee awareness and cyber resilience.
  • Analyze phishing simulation results, reporting trends, and awareness metrics to identify risks, measure efficiency, and drive ongoing improvement of security culture.
  • Partner with business leaders, Human Resources, Corporate Communications, and Information Security teams to reduce phishing susceptibility and increase employee engagement in security procedures.
  • Conduct security assessments of vendors, suppliers, and technology partners as part of Ferguson's third-party risk management program.
  • Review security questionnaires, SOC reports, penetration test results, compliance certifications, and other security documentation to evaluate vendor risk.
  • Identify, assess, and communicate third-party security risks, providing recommendations to support informed business decisions and remediation efforts.
  • Collaborate with Procurement, Legal, and business customers to help ensure appropriate security requirements are incorporated into third-party engagements.
  • Develop and maintain cybersecurity dashboards, scorecards, important metrics, KRIs, and executive reporting that provide access to risk, compliance, and program performance.
  • Apply reporting and automation tools to improve the efficiency, effectiveness, and scalability of Governance, Risk, and Compliance (GRC) activities.
  • Translate technical risks into business-focused insights, helping leaders understand risk exposure, prioritize remediation efforts, and make informed decisions.
  • Serve as a trusted advisor on cybersecurity governance, risk management, and compliance matters, building strong partnerships across business and technology teams.
  • Communicate security risks, recommendations, and program outcomes effectively to both technical and non-technical audiences, including senior leadership.

Qualifications & Requirements:

  • Bachelor's degree in Information Security, Cybersecurity, Information Systems, Computer Science, Business Administration, or a related field; equivalent combination of education and experience will be considered.
  • 5+ years of experience in Information Security, Cybersecurity, IT Risk Management, IT Audit, Governance, Risk & Compliance (GRC), or related disciplines.
  • Experience conducting security risk assessments and evaluating security controls across on-premises, cloud, and third-party environments.
  • Solid understanding of cybersecurity governance, risk management, compliance frameworks, and third-party risk management practices.
  • Extensive knowledge of industry frameworks and standards, including NIST CSF, ISO 27001, COBIT, COSO, and IT General Controls (ITGCs).
  • Experience developing and maintaining security policies, standards, controls, and governance processes.
  • Experience supporting audits, regulatory compliance initiatives, risk assessments, and remediation activities.
  • Ability to identify, assess, prioritize, and communicate risk across applications, infrastructure, cloud services, and vendors.
  • Strong analytical, problem-solving, and critical thinking skills, with the ability to translate sophisticated risks into actionable recommendations.
  • Excellent written, verbal, presentation, and customer management skills, with experience presenting findings and recommendations to technical and business leaders.
  • Experience working with Microsoft technologies, cloud platforms, and security governance or reporting tools preferred.
  • Proven ability to lead complex initiatives, influence interested parties, and drive outcomes through multi-functional collaboration.

Preferred Certifications

  • CISSP, CISM, CRISC, CISA, and/or ISO 27001 Lead Auditor/Lead Implementer certification.

At Ferguson, we care for each other. We value our well-being just as much as our hard work. We are committed to a holistic approach towards benefits plans and programs that support the mental, physical and financial well-being of our associates. Our competitive offering not only includes benefits like health, dental, vision, paid time off, life insurance and a 401(k) with a company match, but our associates also enjoy additional meaningful and inclusive enhancements that are adaptable to their diverse situations and needs, including mental health coverage, gender affirming and family building benefits, paid parental leave, associate discounts, community involvement opportunities and more!

-

Pay Range:

-

Actual pay rate may vary depending upon location. The estimated pay range for this position is below. The specific rate will depend on a candidate’s qualifications and prior experience.

-

$8,470.59 - $14,834.37

-

Estimated Ranges displayed are Monthly for Salaried roles OR Hourly for all other roles.

-

This role is Bonus or Incentive Plan eligible.

-

Ferguson complies with all wage regulations. The starting wage may be higher in certain locations based on local or state wage requirements.

-

The Company is an equal opportunity employer as well as a government contractor that shall abide by the requirements of 41 CFR 60-300.5(a), which prohibits discrimination against qualified protected Veterans and the requirements of 41 CFR 60-741.5(A), which prohibits discrimination against qualified individuals on the basis of disability.

Ferguson Enterprises, LLC. is an equal employment employer F/M/Disability/Vet/SexualOrientation/GenderIdentity.

Equal Employment Opportunity and Reasonable Accommodation Information

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
372,254 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
United States
$149k – $319k per year (Estimated) • In office • 8+ years exp • Tel Aviv
Cybersecurity
GDPR
HIPAA
ISO 27001
NIST CSF
SOC 2
Apply
$27k – $61k per year (Estimated) • Remote • Full-Time • 5+ years exp • Bachelor's Degree • India
PowerShell
Python
DevOps
Azure
Azure DevOps
GitLab
Grafana
Rest API
Cybersecurity
ISO 27001
OWASP SAMM
Threat Modeling
Analytics
Power BI
Tableau
Management
Jira
ServiceNow
Apply
$73k – $180k per year (Estimated) • Remote/Hybrid • Full-Time • Bachelor's Degree • Boadilla del Monte
AI/ML
AI Agents
Anthropic
DevOps
AWS
Cybersecurity
ISO 27001
Apply
$22k – $55k per year (Estimated) • In office • Full-Time • Chennai
Cybersecurity
CIS Benchmarks
ISO 27001
Nessus
Wireshark
Apply
$128k – $216k per year • Equity • In office • Full-Time • 5+ years exp • Bachelor's Degree • Alpharetta • Columbus
DevOps
CI/CD
Git
Cybersecurity
ISO 27001
Least Privilege
PCI DSS
Threat Modeling
Apply
$149k – $270k per year (Estimated) • Remote • Full-Time • 4+ years exp • United States
AI/ML
AI Agents
Copilot
Gemini
Prompt Engineering
RAG
Semantic Search
Vertex AI
Google AI Studio
Human-in-the-Loop
LLM Guardrails
Semantic Search
DevOps
GCP
Management
n8n
Power Automate
Zapier
Apply
$75k – $179k per year (Estimated) • Remote • Full-Time • United States
Apply
$70k – $140k per year (Estimated) • Remote • Full-Time • 3+ years exp • Bachelor's Degree • United States
Management
Airtable
Apply
$144k – $255k per year (Estimated) • In office • Full-Time • 10+ years exp • Bachelor's Degree • Huntersville
Apply
$120k – $244k per year (Estimated) • Remote/Hybrid • Full-Time • 5+ years exp • Bachelor's Degree • United States
Java
Python
Databases
Google BigQuery
AI/ML
Vertex AI
DevOps
AppDynamics
Azure
CI/CD
Datadog
GCP
Platform Engineering
Apply
$106k – $207k per year (Estimated) • Remote/Hybrid • Full-Time • 5+ years exp • Bachelor's Degree • United States
Apply
Lead UX Designer 1 hour ago
$117k – $208k per year (Estimated) • Remote/Hybrid • Full-Time • 8+ years exp • Bachelor's Degree • Charlotte
Apply
$107k – $147k per year • Remote/Hybrid • Full-Time • 6+ years exp • Bachelor's Degree • Columbia
Go
Java
Kotlin
Python
AI/ML
AI Agents
DevOps
Platform Engineering
Cybersecurity
HIPAA
Apply
$126k – $263k per year (Estimated) • In office • Full-Time • 5+ years exp • Bachelor's Degree • Miami • Dallas
DevOps
AWS
Shift-Left
Cybersecurity
PCI DSS
Shift-Left Security
Threat Modeling
Apply
$137k – $228k per year • In office • Full-Time • 8+ years exp • Bachelor's Degree • United States
AI/ML
AI Agents
Copilot
Apply
See all jobs
This is one of many
372,254 more open roles from verified company boards, updated every day.