> Markdown version of [/jobs/ext/2043069-principal-corporate-information-security](https://www.wearedevelopers.com/jobs/ext/2043069-principal-corporate-information-security). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Principal, Corporate Information Security - **Company:** CoreLogic, Inc. - **Location:** Irving, TX, United States - **Experience:** Expert - **Salary:** $134,400.0 - $165,000.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Control Objectives for Information and Related Technology (COBIT), Cyber Security, Power BI, Sherwood Applied Business Security Architecture, Tableau (Software), Google Data Studio, Veracode, Information Technology, RSA Archer Platform, Looker Analytics, Data Pipelines, Qualys - **Published:** August 13, 2026 - **Apply:** https://www.disabledperson.com/jobs/74204967-principal-corporate-information-security ## About the Role Enterprise Risk & Architecture Deep hands on experience in enterprise risk management and internal security architecture. You know how to threat model internal applications, design compensating controls, and ensure defense in depth principles are applied before a system goes into production. * Executive Presence & Negotiation You are comfortable sitting in a room with a VP who is pushing to launch a project quickly. You have the backbone to hold the line on critical security requirements, but the business acumen to help them find a "secure yes" rather than just saying "no.", A strong working grasp of governance frameworks like COBIT, NIST CSF, or ISO 27001. More importantly, you know how to operationalize these frameworks so they are actively used by the business, not just sitting in a binder. * Security Design Familiarity with security design models like SABSA is a huge plus. You know how to trace a high-level business objective down to a specific technical control, ensuring security serves the business strategy. * Collaborative Mindset & Culture Building You are a collaborative problem solver who brings diverse perspectives to the table. You act as a bridge between the engineering teams and the business units, actively mentoring others and fostering a security first culture across the organization., Vulnerability & Scan Management (Required): Hands-on expertise using Qualys (must-have) and Veracode to evaluate scan outputs, track vulnerabilities, and guide technical teams on remediation. Experience with Black Duck is highly preferred. * Data & Reporting Visualization (Required): Proficiency in building executive risk dashboards using Google Looker / Looker Studio. Tableau, or Power BI to present actionable security metrics to leadership. * GRC & Security Ratings (Required): Direct experience working within enterprise GRC platforms (e.g., Archer GRC) and leveraging third-party security rating platforms like BitSight or SecurityScorecard. * AI Security & Emerging Threats (Strong Differentiator): Ability to evaluate security controls for enterprise AI adoption, including assessing risk around prompt injection, rogue AI, AI agents/zombie agents, and AI data pipeline governance. Education and Certifications * Education: Bachelor's degree in IT, Cybersecurity, Computer Science, or a related field (or 8+ years of equivalent senior security experience). * Certifications: CISSP is required (rare exceptions considered only for exceptionally qualified candidates, so please still apply). CISM or SABSA certifications are additional pluses. ## Description We are looking for a Principal, Corporate Information Security to step in as a true Business Information Security Officer (BISO) for our internal business verticals. Think of this role as InfoSec Quality Assurance. You will sit directly between our technical security teams and business units-initially focusing on our Insurance business vertical-to evaluate security postures, assess risk maturity, and transition operations from an ad-hoc state to a defined, managed model. We want someone who can wear the CISO hat, guide executive teams to make smart risk decisions, and eventually expand coverage across additional business verticals. We are building a dynamic team and highly encourage professionals from all backgrounds to apply. What You Will Do You will act as the primary security advisor for business leaders across assigned verticals. For example, if a team wants to launch a new application or policy, you are the one reviewing architecture, assessing vulnerability data, and evaluating risk maturity before go-live. You will review internal security exceptions, track remediations, and translate technical vulnerabilities into actual business impact so executives understand the risk. You will also run governance reviews to ensure identity and access controls align with enterprise policies, while actively participating in incident response and change control oversight. It is all about finding ways to help the business move fast while staying completely secure. ## Related Videos - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) - [Beyond Dashboards: Fixing Text-to-SQL with Semantic RAG](https://www.wearedevelopers.com/videos/2036-beyond-dashboards-fixing-text-to-sql-with-semantic-rag) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [REST, GraphQL, gRPC, and more: A comparison of modern API styles](https://www.wearedevelopers.com/videos/100247-rest-graphql-grpc-and-more-a-comparison-of-modern-api-styles) - [Real-World Security for Busy Developers](https://www.wearedevelopers.com/videos/1545-real-world-security-for-busy-developers) - [Data Analytics with Microsoft Fabric: End-to-End Use Case with Data Agents](https://www.wearedevelopers.com/videos/1547-data-analytics-with-microsoft-fabric-end-to-end-use-case-with-data-agents) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence](https://www.wearedevelopers.com/magazine/736-best-us-ai-conferences-for-ctos-in-2026-build-vs-buy-vendor-evaluation-and-peer-intelligence) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Got AI ideas but no money? Here are 10 free ways to level up your AI skills with Google Cloud](https://www.wearedevelopers.com/magazine/600-got-ai-ideas-but-no-money-here-are-10-free-ways-to-level-up-your-ai-skills-with-google-cloud)