> Markdown version of [/jobs/ext/3342561-principal-information-security-identity-and-data-security](https://www.wearedevelopers.com/jobs/ext/3342561-principal-information-security-identity-and-data-security). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Principal Information Security - Identity and Data Security - **Company:** Wills and Wills L P - **Location:** Atlanta, GA, United States - **Experience:** Expert - **Salary:** $243,200.0 - $304,000.0 - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Artificial Intelligence, Amazon Web Services, Microsoft Azure, Cyber Security, Data Control, Data Discovery, Data Governance, Data Security, Multi-Factor Authentication, Identity and Access Management, Role-Based Access Control, Single Sign-On, Okta - **Published:** September 21, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=72b83e35212b07b8 ## About the Role * Bachelor's degree in cyber security (or) related degree or equivalent work experience * 10-15 years of experience in Information Security with significant experience in identity security and/or data security, and demonstrated experience identifying systemic gaps and applying risk, control and governance principles to mature security capabilities. * Certified Information Security Systems Professional (CISSP), Certified Information Security Manager (CISM) or Global Information Assurance Certifications (GIAC) certifications are preferred * Experience assessing security risks and control effectiveness, applying and evolving risk scoring methodologies in alignment with risk appetite and influencing stakeholders to prioritize appropriate risk-reduction actions. * Demonstrated ability to lead complex, cross-functional initiatives and influence stakeholders without direct authority. * Strong expertise in enterprise identity security, lifecycle, identity governance, and modern access control models, with experience across workforce, privileged, non-human, and AI enabled identities. * Strong expertise in data security and governance, including data discovery and inventory, classification, access, handling, protection, retention and secure disposal. * Ability to align security and compliance objectives with the broader business goals and growth strategy, developing and executing multi-year security strategies and roadmaps * Proven track record of scaling GRC, identity, and/or data security programs. * Deep knowledge of frameworks such as NIST, ISO 27001, and various regional/industry-specific regulations. * Effectively partner cross-functionally with Legal, HR, Finance, Engineering and IT to embed risk management into day-to-day operations. * Lead teams (directly or indirectly) to automate access request workflows to reduce manual overhead and human error. * Experience with enterprise platforms like AWS, Okta, AD, MS Azure, Lumos, etc. * Hands on experience with Access Management workflows for all identity transactions (Moves, Adds, Transfers, and Changes) ## Description As part of our Identity and Data Security team, you will be accountable for the strategy, security, and governance of digital identities-both human (employees, contractors, business partners) and non-human (agents, bots, service accounts, IoT). In addition, this role will oversee and coordinate BILL's governance, risk, compliance (GRC), and remediation activities related to data security. This position will report directly to the Security GRC Leader. This role addresses all aspects of administration, enforcement, compliance, education, investigation, and contingency planning related to identity and data security, aligning with stakeholders in IT, Privacy Legal, Internal Audit, and Engineering teams to ensure BILL's rigorous data control standards are met. This role is a hands-on IC security leader role with the expectation that work will vary between strategic and operational., This job description intends to provide an overview of the general nature of the work and is not intended to reflect an exhaustive listing of responsibilities or requirements. The company reserves the right to update, modify, discontinue, or change the requirements of any job as determined by business needs with or without prior notice. * Serve as a bridge between technical teams (like IT and Security) and executive leadership, turning complex risk landscapes into clear business insights. * Implement measures and governance frameworks to manage data use in compliance with laws and regulations * Monitor the regulatory and statutory landscape on identity and data security issues, keeping BILL personnel and senior leadership apprised of any relevant developments impacting the company's business goals and objectives, and recommending appropriate courses of action as needed * Review projects, business critical systems and provide guidance and work with process owners to identify and remediate control weaknesses related to identity and data security to ensure compliance with regulatory requirements and ensure client contractual commitments and industry best practices * Develop and advance the multi-year identity security strategy and roadmap, prioritizing improvements based on risk, business needs, technology evolution, and the maturity and effectiveness of existing IAM capabilities * Oversee Identity Governance and Administration (IGA) processes-managing new hires, transfers, and terminations to ensure least-privilege access across the entire enterprise. * Manage Single Sign-On (SSO), Multi-Factor Authentication (MFA), and Adaptive Access policies that determine how users log in and what context-aware security checks are applied. * Secure high-risk privileges for administrators and service accounts to prevent lateral movement during a breach. * Provide security strategy and guidance for customer-facing identity capabilities, including authentication, secure registration, profile management, federated/social login, in partnership with Product and Engineering. * Assess and evolve security requirements for non-human identifies, including service accounts, APIs, AI agents, with appropriate authentication, authorization, least privilege, monitoring and accountability. * Assess sensitive-data security risks and the effectiveness of related controls, leveraging data discovery and DLP capabilities to strengthen protection and prevent inappropriate access or use. * Advance data governance and protection by improving visibility into sensitive data across the ecosystem, such as data inventory, classification, security controls, retention and appropriate use across product environments, corporate environments, third parties and AI enabled use cases. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Crypto-secure Data Management with In-Database Blockchain](https://www.wearedevelopers.com/videos/632-crypto-secure-data-management-with-in-database-blockchain) - [Your Code as a Crime Scene](https://www.wearedevelopers.com/videos/1342-your-code-as-a-crime-scene) - [How to govern Vibe Coding for the Enterprise](https://www.wearedevelopers.com/videos/100290-how-to-govern-vibe-coding-for-the-enterprise) - [Web-based Information Visualization](https://www.wearedevelopers.com/videos/84-web-based-information-visualization) - [AI Sovereignty: What Does It Take?](https://www.wearedevelopers.com/videos/1703-ai-sovereignty-what-does-it-take) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Security Basics for Vibe Coders](https://www.wearedevelopers.com/magazine/598-security-basics-for-vibe-coders) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)