> Markdown version of [/jobs/ext/183719-principal-cybersecurity-advisor-information-security-strategy-analytics-hybrid](https://www.wearedevelopers.com/jobs/ext/183719-principal-cybersecurity-advisor-information-security-strategy-analytics-hybrid). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Principal Cybersecurity Advisor - Information Security Strategy & Analytics (Hybrid) - **Company:** AbbVie Inc. - **Location:** Springfield, IL, United States - **Experience:** Expert - **Salary:** $81,108.0 - $150,876.0 - **Contract:** Permanent contract - **Skills:** Cyber Security, Zero Trust Network Access, Cyber Warfare - **Published:** May 23, 2026 - **Apply:** https://www.careerjet.com/jobad/usb24c3d3c5dfe6adc7486f0640b0e48a2 ## About the Role Bachelor's Degree and 8 years of experience OR Master's Degree and 7 years of experience OR PhD and 3 years of experience. Significant demonstrated experience in information security strategy, security program leadership, or security transformation within a large, complex organization, with enough practitioner depth to engage credibly on priorities, risk tradeoffs, and investment decisions. Exceptional written communication skills, with a demonstrated track record of developing executive-level strategy documents, roadmaps, decision papers, and governance narratives that influence senior leadership. Strong writing ability is a defining requirement of this role. Exceptional executive communication and stakeholder engagement skills, with demonstrated ability to influence at the CISO and senior leadership level across technical and non-technical audiences without direct authority. Demonstrated ability to translate complex technical, operational, financial, and risk information into clear strategic options and actionable recommendations. Demonstrated experience working with security maturity assessment frameworks such as NIST CSF, including translating assessment findings into strategic priorities, roadmap inputs, and trackable remediation plans. Strong understanding of security concepts, principles, and frameworks (e.g., NIST CSF, ISO 27001, Zero Trust) and the ability to apply them in strategic planning and investment decisions. Demonstrated ability to manage ambiguity, synthesize competing priorities, and support high-quality decision-making in fast-moving environments. Preferred: Experience in a security strategy, transformation, chief-of-staff, or portfolio leadership role within an Information Security, Cybersecurity, or IT Risk organization. Experience supporting CISO-level governance, executive planning forums, or enterprise risk discussions. Experience developing multi-year security roadmaps, service strategies, operating model materials, or investment cases. Experience in a technical security leadership, security architecture, engineering, or cyber defense role that required deep understanding of security technologies, control domains, and implementation considerations. Familiarity with data and analytics concepts, metrics frameworks, or reporting practices sufficient to engage as an active partner to analytics and reporting teams. Experience supporting globally distributed teams and stakeholders. ## Description The Principal Cybersecurity Advisor, Information Security Strategy & Analytics is a senior individual contributor who partners with the ISRM leadership team, including the CISO, to shape the function's strategic direction and build the narrative, documentary, and measurement foundation that enables sound executive decision-making. This role translates business priorities, risk insights, regulatory drivers, and delivery realities into security strategy, multi-year roadmaps, investment recommendations, and portfolio narratives that guide leadership decisions. This role has two defining requirements. First, the ability to communicate complex security strategy clearly, compellingly, and credibly to senior and executive audiences, both in writing and in person. Second, deep enough security practitioner experience to engage with credibility on strategic priorities, risk tradeoffs, and investment decisions without requiring translation. The ideal candidate has lived the work they will now help shape. Responsibilities Define and maintain ISRM's strategic direction, including strategic priorities, target state, and multi-year roadmap, in close partnership with ISRM leadership. Translate business priorities, threat and risk insights, regulatory drivers, and security delivery realities into strategic recommendations, investment proposals, and tradeoff analyses for leadership decision-making. Own ISRM's strategic narrative by developing and continuously improving strategy documentation, roadmap materials, executive communications, and leadership presentations that clearly articulate the function's direction, progress, and value. Serve as the primary subject matter expert and content architect for ISRM strategic communications, partnering with enterprise communications teams to ensure strategic messaging is developed and delivered effectively. Lead the development of ISRM's strategic inputs to annual planning activities, including Long-Range Planning (LRP) and capital planning, ensuring strategic priorities, investment rationale, and multi-year direction are clearly articulated and satisfied by execution roadmaps and activities. Synthesize portfolio data, delivery performance, and resource realities into prioritization recommendations, providing leadership with a clear analytical basis for investment and sequencing decisions. Track ISRM's security maturity progress against established frameworks such as NIST CSF, partnering with technical teams on assessment preparation and ensuring findings are accurately reflected in strategic priorities, roadmap inputs, and remediation planning. Actively partner with the ISRM metrics and reporting team to identify, define, and drive meaningful measurement initiatives, such as security hygiene tracking and operational risk reporting, ensuring the metrics roadmap reflects ISRM's strategic priorities and produces reporting that is decision-relevant at the leadership level. Evolve ISRM's strategic planning and prioritization practices, including decision frameworks, investment governance, and planning cadences, in close partnership with the Portfolio Manager who owns delivery governance and PMO standards. Define and maintain ISRM's service catalog, establishing clear service definitions, maturity frameworks, and engagement models that accurately reflect ISRM's capabilities and communicate them effectively to stakeholders. ## Related Videos - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Developing ASP.NET Core Microservices with Dapr: A practical guide](https://www.wearedevelopers.com/videos/1528-developing-asp-net-core-microservices-with-dapr-a-practical-guide) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Synthetic Insiders: The New AI Risk to Your Org](https://www.wearedevelopers.com/videos/100057-synthetic-insiders-the-new-ai-risk-to-your-org) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Coffee with Developers - Maria Apazoglou - Making AI understandable for all in production](https://www.wearedevelopers.com/magazine/475-coffee-with-developers-maria-apazoglou-making-ai-understandable-for-all-in-production) - [Best Companies to work for in London: Top 25 Companies in 2023](https://www.wearedevelopers.com/magazine/187-best-companies-to-work-for-in-london-top-25-companies-in-2023)