Role Description
A Principal Research Analyst at ISACA leads the development, delivery, and continuous enhancement of high-quality forward-thinking content, guidance, and practitioner aids for their assigned area of expertise, ensuring alignment with ISACA’s Professional Practices Program Strategy and industry standards. This role partners closely with business units, marketing, events teams, and ISACA leadership to integrate practice-area content consistently across conferences, webinars, publications, and other member-facing initiatives.
-
Serve as a subject matter expert in their assigned practice area.
-
Recruit, mobilize, and guide volunteer SME groups to co-develop and validate content.
-
Provide expert guidance throughout content and research project cycles.
-
Represent ISACA externally at industry events, panels, and webinars.
-
Evaluate conference proposals and ensure presentations meet technical and strategic standards.
-
Support knowledge advancement by responding to member inquiries, monitoring trends, and maintaining up-to-date expertise.
-
Contribute to ISACA’s brand and marketing efforts to strengthen organizational visibility and credibility.
-
Demonstrate critical thinking, collaboration, strong communication, analytical skills, and the ability to manage multiple priorities.
Qualifications
-
Bachelor’s Degree in a relevant field of study from an accredited university, or an equivalent combination of education and experience.
-
Minimum of 8 years of experience in a similar role or capacity, with a demonstrated record of success.
-
Experience responding to stakeholder inquiries, providing expert guidance and practical interpretation of industry practices and trends.
-
Proven experience collaborating cross-functionally with business teams.
-
Experience conducting secondary research and reporting.
-
Track record of public-facing thought leadership: conference speaking, webinars, podcasts, or published articles.
-
Additional 5+ years of enterprise information security program experience; must include recent experience (within past 24 months) securing modern, hybrid enterprise environments.
-
Familiarity with common frameworks and taxonomies (NIST CSF, MITRE ATT&CK, ISO 27001, CIS controls).
-
Deep working knowledge of core cybersecurity domains (network, endpoint, IAM, cloud, application security, incident response).
-
Knowledge of cloud platforms and cloud control frameworks (AWS/Azure/GCP and cloud audit considerations).
Requirements
-
Master’s Degree in Cybersecurity, Computer Science, Information Systems, or related field from an accredited university (preferred).
-
10+ years of experience in a similar role or capacity, with a demonstrated record of success (preferred).
-
Related experience in regulated industries (finance, healthcare, energy) or working with regulators and compliance programs (preferred).
-
Direct involvement with procurement, implementation, and operationalization of AI technologies (preferred).
-
Experience with threat intelligence, detection engineering, or malware/attack analysis (preferred).
-
Experience performing threat modeling (preferred).
-
CISM or CISSP (required certifications).
-
AAISM (preferred certification).
-
Working knowledge of artificial intelligence technologies, current applications within assigned area of expertise, identification of appropriate use cases, and related risk.
-
Vendor and market research – evaluating products, mapping capabilities, and performing competitive analysis.
-
Critical thinking, collaboration, and cross-functional stakeholder engagement.
-
Business writing.
-
Proven ability to translate research into content deliverables: verbal presentations or written reports.
-
Travel may be required to attend industry conferences, professional events, workshops, and external meetings.
Benefits
-
ISACA Career Opportunities and Benefits.
Company Description
ISACA® (www.isaca.org) champions the global workforce advancing trust in technology. For more than 55 years, ISACA has empowered its community of 195,000+ members with the knowledge, credentials, training, and network they need to thrive in fields like information security, governance, assurance, risk management, data privacy, and emerging tech.
-
Presence in more than 195 countries and over 230 chapters worldwide.
-
Offers resources tailored to every stage of members’ careers.
-
Helps members thrive in a rapidly changing digital landscape.
-
Drives trusted innovation and ensures a more secure digital world.
-
Expands IT and education career pathways through the ISACA Foundation.