Principal Information Security Consultant
$135,000–$216,000 year
RemoteUnited States
Job Summary
Design and review secure architectures, technical designs, and proposed solutions across cloud and on-premises environments for Covered California and CalHEERS. Translate NIST SP 800-53 Rev. 5, ARC-AMPE, and IRS Publication 1075 requirements into concrete engineering controls, hardening baselines, and automated security patterns. Lead security engineering for identity, network, endpoint, cloud, and application security domains, while owning vulnerability management strategies, risk-based prioritization, and remediation validation. Provide senior technical QA on assessments and reports, mentor security professionals, and support incident response, detection, and the on-call rotation. Advise stakeholders on corrective actions and CMS Authority to Connect readiness.
Required Qualifications
- Minimum of 12 years experience with BS/BA
- Minimum of 10 years with MS/MA
- Degree in computer science, engineering, or cybersecurity
- An additional 4 years of experience may be considered in lieu of a degree
- Progressively responsible cybersecurity experience, with significant depth in enterprise security control frameworks and complex regulated environments
- Active CISSP certification
- Demonstrated experience interpreting and applying NIST SP 800-53 Rev. 5 security and privacy controls within a complex enterprise environment, and translating regulatory control requirements into engineering solutions
- Hands-on security architecture and engineering experience across cloud (AWS, Azure, or GCP) and on-premises environments, including identity and access management, network security, endpoint security, and application security
- Hands-on experience with enterprise vulnerability management tooling (for example Tenable or Qualys) and with hardening standards such as CIS Benchmarks or DISA STIGs
- Demonstrated ability to communicate complex cybersecurity risk to both technical and executive audiences, and executive-grade technical writing ability
- US Citizenship
- The ability to pass a California criminal background clearance (Gov. Code §1043 / 10 CCR §6456) before starting work or accessing any confidential information, PII, PHI, federal tax information, or financial information
Desired Qualifications
- CCSP, or a cloud security specialty certification: AWS Certified Security – Specialty, Microsoft Azure SC-100, or Google Professional Cloud Security Engineer
- CISM, CRISC, CGRC, or GSLC
- Experience with ARC-AMPE security and privacy requirements
- Experience with IRS Publication 1075 and FTI-bearing environments
- Experience with CMS security requirements and the Authority to Connect (ATC) process
- Experience with zero-trust architecture, encryption and key management design, and security control automation
- Experience securing or assessing healthcare eligibility and enrollment, Medicaid, or health benefit exchange systems, and large California state government IT or cyber environments
- Experience supporting independent assessments and developing or reviewing Security Assessment Reports, CMS Security Assessment Workbooks (SAWs), and POA&Ms
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.