For Employers

AHEAD

Principal Technical Consultant – Cloud and Application Security

Posted 2 hours ago
$250K - $300K per year
10+ years experience
Apply Now

Please mention DailyRemote when applying

Not sure your resume will pass? Check your ATS score free

?/100
Resume Match Score

Match your resume skills with our AI powered skill match!

Get professional review
AI Summary

The Principal Technical Consultant leads client delivery engagements, including strategy, design, and implementation of cloud and application security solutions. They also support business development activities and contribute to the maturation of service offerings through thought leadership and mentorship.

AHEAD builds platforms for digital business. By weaving together advances in cloud infrastructure, automation and analytics, and software delivery, we help enterprises deliver on the promise of digital transformation.

 

At AHEAD, we prioritize creating a culture of belonging, where all perspectives and voices are represented, valued, respected, and heard. We create spaces to empower everyone to speak up, make change, and drive the culture at AHEAD. 

 

We are an equal opportunity employer, and do not discriminate based on an individual's race, national origin, color, gender, gender identity, gender expression, sexual orientation, religion, age, disability, marital status, or any other protected characteristic under applicable law, whether actual or perceived. 

 

We embrace all candidates that will contribute to the diversification and enrichment of ideas and perspectives at AHEAD. 


Principal Technical Consultants are seasoned experts in information security, cloud security, application security and DevSecOps, threat management, and related technologies, with the ability to secure applications and APIs across the cloud-native software delivery lifecycle. Successful candidates support the Security team in Delivery, Business Development, and Practice Development. 

 

Principal Technical Consultants collaborate with a diverse team of consultants with varying skills to meet and exceed client expectations through scoped engagements. They effectively facilitate and lead client engagements remotely by guiding engagements toward scoped objectives and troubleshooting to effectively resolve project risks or issues. Principal Technical Consultants effectively lead client delivery engagements by executing the necessary project tasks, producing expected collateral, and presenting artifacts at any time throughout an engagement, while acting in a leadership capacity to the project team(s).  

 

Principal Technical Consultants also support business development activities alongside a sales specialist to qualify client needs and expectations or demonstrate a capability or skillset. They may be directly engaged in client-facing interactions to identify client needs and to produce and/or present sales proposals, leading client-visioning, or discovery sessions. Principal Technical Consultants may also collaborate with other AHEAD Practice areas to identify complex, cross-practice solution sets to achieve a client’s desired state or outcome. 

 

AHEAD Principal Technical Consultants leverage their visibility and experience to contribute to the continuous improvement and maturation of in-practice service offerings and capabilities. This includes proposing ideas for new offerings and/or changes to existing offerings or initiatives, as well as their corresponding GTM efforts. They are considered a technical leader within the practice and expected to positively impact the services portfolio and individuals on the team through thought leadership and mentorship. 

\n


Duties and Responsibilities
  • The following are the expectations of a Principal Technical Consultant: 

     

    Client Delivery 

    • Lead sessions of strategy, roadmap, design, and planning workshops for small to medium sized service engagements  

    • Execute on project/program objectives, requirements gathering, project tasks/milestone, project status, dependencies, and timelines, to ensure engagements are delivered successfully and on time while meeting the business objectives  

    • Creation and finalization of project deliverables, may perform peer review for collateral developed by others on a delivery team  

    • Effective presentation of deliverables to project team members. 

    • Knowledge of AHEAD’s project lifecycle management activities to effectively support delivery engagements throughout the duration of a project  

    • Define and operationalize application security delivery plans, including secure SDLC controls, risk-based finding prioritization, developer enablement, metrics, and executive reporting. 

    • Lead application security and threat modeling workshops covering secure architecture, abuse cases, application and API risks, and remediation planning. 

    Technical Mastery 

    • Proficiency in technical troubleshooting; the ability to critically think about a problem and generate a creative solution with minimal oversight. 

    • Deep knowledge of scripting, particularly with PowerShell and/or Python, and the ability to troubleshoot developed code. 

    • Ability to triage and validate application security findings (SAST, DAST, SCA, secrets), distinguish exploitable issues from false positives, and recommend practical remediations. 

    • Ability to effectively communicate aspects of a technical solution to a non-technical individual. 

    • Capability to conduct research and utilize available resources to fill in technical knowledge gaps where ambiguity presents itself. 

     

    Business Development 

    • Support business development pursuits through client discovery meetings 

    • Represent service offerings during the sales cycle, including project scoping, proposal development, and presenting proposals to clients 

    • Knowledge of AHEAD’s sales management lifecycle to effectively support sales opportunities throughout the duration of a proposal  

    • Lead client discovery and/or visioning workshops to identify opportunities for cross-practice collaboration 

    • Familiarity with AHEAD’s enterprise service portfolio to identify opportunities for cross-practice collaboration 

     

    Practice Development & Thought Leadership 

    • Maintain subject matter expertise in a minimum of eight security domains or three security solutions 

    • Participate in the development, enhancement, and standardization of AHEAD in-practice service offerings 

    • Owns and/or enables more than one service capability 

    • Process-focused technology thought leader and evangelist 

    • Maintain a broad knowledge and understanding of current and future state IT trends, technologies, and standards 

    • Lend support and mentorship to others 


Domain experience required
  • Cloud Security Architecture & Risk Strategy 

    • Proven experience in reviewing and implementing secure cloud reference architectures and landing zones. 

    • Experience designing Zero Trust and network segmentation architectures for cloud environments, including micro-segmentation, private connectivity, and egress controls. 

    • Ability to translate risk strategy by mapping traditional lift-and-shift approaches into cloud-native security controls. 

    • Strong understanding of multi-cloud governance models, including Infrastructure-as-Code (IaC), policy-as-code (PaC), tagging standards, and multi-account strategies. 

    • Experience operationalizing a secure cloud SDLC by embedding IaC scanning, policy-as-code guardrails, and drift detection into multi-account and multi-cloud deployment pipelines. 

    CNAPP Tooling 

    • 5+ years of combined hands-on experience with CNAPP tools (Wiz preferred) 

    • Expertise in integrating CNAPP solutions with enterprise tooling such as ServiceNow, CI/CD pipelines, and ticketing/alerting workflows. 

    • Experience extending CNAPP coverage into the SDLC by integrating with source repositories, CI/CD pipelines, and developer workflows to shift application security left. 

    • Able to clearly and concisely communicate CNAPP (criticality, risk, remediation) to technical and business stakeholders. 

    • Ability to unify application-layer findings (SAST, DAST, SCA, ASPM) with cloud posture and runtime context to prioritize remediation by real exploitability and business risk. 

    • Strong track record in deploying and instantiating CNAPP solutions 

    • Hands-on experience leveraging the application security and ASPM capabilities within CNAPP platforms — including code and IaC scanning, container image scanning, secrets detection, and code-to-cloud traceability from source to running workload. 

    Cloud Platforms & Native Security Controls 

    • 5+ years of experience working with GCP and cloud-native services (AWS and Azure experience optional) 

    • Deep understanding and specialist expertise with cloud-native security services such as Google Security Command Center, AWS Security Hub, and/or Microsoft Defender for Cloud). 

    • Familiarity with securing managed cloud AI/ML services (e.g., Vertex AI, Amazon Bedrock, Azure OpenAI), including identity and access scoping, data protection, and guardrails. 

    • Hands-on knowledge of cloud identity (IAM, Federation, RBAC) across multi-cloud environments. 

    • Familiarity with IDaaS solutions such as Okta and Entra ID. 

    • Demonstrated experience with leading secure cloud migration projects/programs. 

    Security Frameworks & Governance 

    • Strong knowledge of security standards and frameworks: e.g. CIS Benchmarks, NIST, FedRAMP, ISO 27001, GDPR. 

    • Ability to design and map cloud-specific controls for audit and compliance needs. 

    • Experience with SIEM integration (Splunk, Sentinel, Chronicle) and cloud-native detection capabilities (optional). 

    DevSecOps and Application Security 

    • Strong understanding of DevSecOps and secure coding best practices, including the ability to assess, implement, and mature application security programs against relevant industry frameworks and maturity models (e.g. OWASP SAMM, DSOMM) 

    • Proficiency in application threat modeling (e.g., STRIDE, abuse-case and attack-surface analysis) conducted at design time and integrated into cloud-native and microservices architectures. 

    • Experience with reviewing and remediating insecure CI/CD pipelines 

    • Experience with Application Security Posture Management (ASPM) and risk-based vulnerability prioritization — correlating and de-duplicating findings across SAST, DAST, and SCA and orchestrating remediation at scale. 

    • Hands-on knowledge of DevSecOps and Application Security tooling, including DAST, SAST, SCA, secrets detection, and related solutions. 

    • Expertise in API security (REST and GraphQL), including the OWASP API Security Top 10, authentication/authorization and API gateway controls, and testing of APIs exposed by cloud-native and serverless workloads. 

    • Ability to read, understand, and apply Infrastructure-as-Code (Terraform, Bicep, AWS CloudFormation). 

    • Familiarity with policy-as-code tooling (OPA, Sentinel) and IaC scanning in CI/CD pipelines. 

    • Proficiency in scripting (Python, PowerShell, Bash) to automate security tasks. 

    • Ability to perform secure code review and secure design/architecture reviews across common languages and frameworks, translating findings into actionable developer guidance. 

    • Experience with containerization (Docker, Kubernetes) and securing workloads at scale. 

    • Experience securing the software supply chain, including SBOM generation and management, open-source and dependency risk governance, and artifact integrity and provenance (e.g., signing, SLSA). 


Qualifications
    • Undergraduate degree in Computer Sciences or Business Management preferred, but not required 

    • Minimum of  

    • 3+ years of leadership experience 

    • 10+ years consulting experience, or commensurate work experience 

    • Professional and/or technical certifications, including industry-recognized certifications which align to AHEAD’s Security service portfolio are preferred (e.g. CISSP, CCSP) 

    • Application security certifications such as CSSLP, GIAC GWEB/GWAPT, OSCP, or equivalent are preferred. 

    • Demonstrated experience establishing or maturing application security programs and mentoring engineers and security practitioners. 

    • Excellent verbal and written communication skills 

    • Comfortable addressing groups of people in virtual or in-person settings 

    • Demonstrated Business Acumen  

    • Ability to solve complex, abstract problems 

    • Excellent interpersonal skills, good listener, ability to connect with different personalities 

    • Exhibit Executive presence with leadership characteristics 

    • Demonstrated experience as a technology change agent. 


\n
$250,000 - $300,000 a year
\n

The compensation range indicated in this posting reflects the On-Target Earnings (“OTE”) for this role, which includes a base salary and any applicable target bonus amount. This OTE range may vary based on the candidate’s relevant experience, qualifications, and geographic location.  

 

Why AHEAD:

 

Through our daily work and internal groups like Moving Women AHEAD and RISE AHEAD, we value and benefit from diversity of people, ideas, experience, and everything in between.

 

We fuel growth by stacking our office with top-notch technologies in a multi-million-dollar lab, by encouraging cross department training and development, sponsoring certifications and credentials for continued learning.

 

USA Employment Benefits include: 

- Medical, Dental, and Vision Insurance 

- 401(k) 

- Paid company holidays 

- Paid time off 

- Paid parental and caregiver leave 

- Plus more! See benefits https://www.aheadbenefits.com/ for additional details. 

 

Use of AI:

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, assessing responses, or to capture recordings and create transcriptions or summaries during interviews. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans.

 

If you would like more information about how your data is processed, please refer to the Candidate Privacy Notice or contact us at privacy@ahead.com

 

You may opt-out of the review or analysis of your application and resume by AI tools by using the General Application. Please include the role you wish to apply for in the Additional Information field. You may also choose to opt-out of recording and transcription at any time, including after joining an interview.  Candidates will not be penalized for choosing to opt-out.

Automatically Apply to the Best Remote Jobs

Stop the endless job search. Our AI finds and applies to the best jobs for you.

Try it Now
Keep looking

Similar Jobs

See all Remote Software Development jobs →

Cloud Infrastructure Engineer (Part-Time, Equity-Only)

Part Time United States Software Development

AD/Sr. AD, Business Analytics - Oncology (Remote)

Full Time United States $170K - $269K per year Software Development

Legal Solutions Engineer

Full Time United States $168K - $235K per year Software Development

Senior Clinical Quality Assurance Associate

Full Time United States Software Development

Senior Oracle Database Administrator

Full Time United States Software Development

Payroll Administrator (Remote)

Full Time United States $23.15 - $29 per hour Software Development
Apply Now

Personalize your Remote Job Search in 3 Easy Steps!

Discover remote opportunities in Software Development

Answer easy questions

Answer easy questions

200,000+ jobs across 15+ categories

Get your best job matches

Get your best job matches

Only hand-screened, legit jobs

Find a remote job faster

Find a remote job faster

No ads, scams, or junk

I was the first applicant for a remote marketing position that got listed on the company website the same day I applied. Had an interview within 48 hours!”

Sarah J. — Sarah J. · Marketing Manager ★★★★★ Verified