Principal, Security Alignment
GuidePoint Security provides trusted cybersecurity expertise, solutions and services that help organizations make better decisions and minimize risk. By taking a three-tiered, holistic approach for evaluating security posture and ecosystems, GuidePoint enables some of the nation’s top organizations, such as Fortune 500 companies and U.S. government agencies, to identify threats, optimize resources and integrate best-fit solutions that mitigate risk.
The Principal, Security Alignment reports directly to the Chief Information Security Officer (CISO) and serves as the primary security advisor and strategic partner between Corporate Information Security and regional business operations.
The organization operates a federated business model where corporate functions establish enterprise capabilities, standards, and guardrails while regional teams maintain autonomy in executing their business objectives. This role exists to ensure regional execution aligns with enterprise security expectations while enabling business velocity and operational flexibility.
The Principal, Security Alignment will partner with regional leadership teams to understand business processes, professional services delivery models, customer commitments, internally developed solutions, data handling practices, and operational workflows. The role will provide the CISO organization with visibility into regional practices, identify areas of risk, drive alignment to enterprise standards, and establish sustainable accountability mechanisms.
Success requires the ability to operate as a trusted business advisor — influencing without direct authority, translating security requirements into practical business outcomes, and helping regions mature without creating unnecessary friction.
Key Responsibilities
Regional Security Partnership & Advisory
- Establish trusted relationships with regional executives and operational leaders.
- Serve as the primary security advisor connecting regional business operations with the Enterprise Information Security organization.
- Understand regional priorities, customer requirements, delivery practices, and operational challenges.
- Help regional teams interpret and operationalize enterprise security standards.
- Ensure security considerations are incorporated into regional decision-making processes.
Business Process & Operational Risk Visibility
- Assess regional business practices to identify potential security, privacy, compliance, and operational risks.
- Evaluate areas including:
- Professional services delivery practices
- Customer data handling
- Customer environment access
- Internally developed tools and automation
- AI adoption and usage
- Third-party/vendor usage
- Data movement and storage practices
- Customer contractual security obligations
- Identify inconsistencies between regional execution and enterprise expectations.
Security Governance & Accountability
- Develop a scalable governance model that balances corporate oversight with regional autonomy.
- Define clear ownership expectations between corporate security and regional leadership.
- Create visibility mechanisms that allow risks to be identified proactively.
- Establish regional security operating rhythms, reporting, and accountability structures.
- Ensure exceptions, deviations, and business-driven decisions are documented and understood.
CISO Risk Visibility & Executive Reporting
- Provide the CISO with ongoing visibility into regional security maturity, emerging risks, and operational trends.
- Develop executive-level reporting around:
- Regional alignment
- Key risk indicators
- Security maturity
- Remediation progress
- Areas requiring leadership escalation
- Escalate material concerns where business practices create unacceptable enterprise risk.
Security Enablement & Continuous Improvement
- Identify opportunities to simplify adoption of corporate security capabilities.
- Reduce friction between security requirements and regional execution.
- Create reusable playbooks, processes, and frameworks.
- Promote consistency without eliminating appropriate regional flexibility.
- Build a culture where security is viewed as a business enabler.
First Six-Month Objectives
Within the first six months, this leader will:
- Complete security/business assessments across all eight regions.
- Establish relationships with regional leadership teams.
- Create a regional security maturity baseline.
- Identify high-priority risks and improvement opportunities.
- Define the corporate/regional responsibility model.
- Establish recurring governance and reporting cadence.
- Implement regional security scorecards.
- Deliver a prioritized roadmap for long-term maturity.
Required Experience
- 10+ years of experience in information security, risk management, technology leadership, consulting, or business operations.
- Experience operating in federated, decentralized, or matrixed organizations.
- Strong understanding of enterprise security governance, risk management, and operational controls.
- Experience partnering with executive business stakeholders.
- Ability to influence teams without direct reporting authority.
- Experience translating security concepts into business outcomes.
- Strong executive communication and reporting skills.
Ideal Candidate Profile
- The ideal candidate is a business-minded security executive who understands that effective security requires partnership, influence, and operational awareness.
- This individual can move comfortably between executive conversations and operational details, identifying where business execution creates risk while helping teams achieve objectives securely.
- They are equally comfortable advising regional leaders, discussing customer delivery models, reviewing business workflows, and briefing the CISO on enterprise-level risk.
- This role is not designed to centralize regional decision-making — it is designed to create alignment, visibility, accountability, and trust.
We use Greenhouse Software as our applicant tracking system and Zoom Scheduler for HR screen request scheduling. At times, your email may block our communication with you. Please be sure to check your SPAM folder so that you don't miss updates on your application.
Why GuidePoint?
GuidePoint Security is a rapidly growing, profitable, privately-held value added reseller that focuses exclusively on Information Security. Since its inception in 2011, GuidePoint has grown to over 1,200 employees, established strategic partnerships with leading security vendors, and serves as a trusted advisor to more than 6,200 customers.
Firmly-defined core values drive all aspects of the business, which have been paramount to the company’s success and establishment of an enjoyable workplace atmosphere. At GuidePoint, your colleagues are knowledgeable, skilled, and experienced and will seek to collaborate and provide mentorship and guidance at every opportunity.
This is a unique and rare opportunity to grow your career along with one of the fastest growing companies in the nation.
Some added perks….
- Remote workforce primarily (U.S. based only, some travel may be required for certain positions, working on-site may be required for Federal positions)
- Group Medical Insurance options: Zero Deductible PPO Plan (GuidePoint pays 90% of the premium for employees and 70% for family plans (spouse/children/family) or High Deductible Health Plan with HSA (GuidePoint pays 100% of the employees premiums and 75% for family plans (spouse/children/family). If you choose the High Deductible / HSA plan, GPS will contribute in 4 equal quarterly installments: ($850 per EE annually / $1750 per family annually (includes spouse/children/family options)
- Group Dental Insurance: GuidePoint pays 100% of the premium for employees and 75% of family plans
- 12 corporate holidays and a Flexible Time Off (FTO) program
- Healthy mobile phone and home internet allowance
- Eligibility for retirement plan after 2 months at open enrollment
- Pet Benefit Option