Principal Technical Consultant – Cloud and Application Security
Principal Technical Consultants are seasoned experts in information security, cloud security, application security and DevSecOps, threat management, and related technologies, with the ability to secure applications and APIs across the cloud-native software delivery lifecycle. Successful candidates support the Security team in Delivery, Business Development, and Practice Development.
Principal Technical Consultants collaborate with a diverse team of consultants with varying skills to meet and exceed client expectations through scoped engagements. They effectively facilitate and lead client engagements remotely by guiding engagements toward scoped objectives and troubleshooting to effectively resolve project risks or issues. Principal Technical Consultants effectively lead client delivery engagements by executing the necessary project tasks, producing expected collateral, and presenting artifacts at any time throughout an engagement, while acting in a leadership capacity to the project team(s).
Principal Technical Consultants also support business development activities alongside a sales specialist to qualify client needs and expectations or demonstrate a capability or skillset. They may be directly engaged in client-facing interactions to identify client needs and to produce and/or present sales proposals, leading client-visioning, or discovery sessions. Principal Technical Consultants may also collaborate with other AHEAD Practice areas to identify complex, cross-practice solution sets to achieve a client’s desired state or outcome.
AHEAD Principal Technical Consultants leverage their visibility and experience to contribute to the continuous improvement and maturation of in-practice service offerings and capabilities. This includes proposing ideas for new offerings and/or changes to existing offerings or initiatives, as well as their corresponding GTM efforts. They are considered a technical leader within the practice and expected to positively impact the services portfolio and individuals on the team through thought leadership and mentorship.
Duties and Responsibilities
-
The following are the expectations of a Principal Technical Consultant:
Client Delivery
-
Lead sessions of strategy, roadmap, design, and planning workshops for small to medium sized service engagements
-
Execute on project/program objectives, requirements gathering, project tasks/milestone, project status, dependencies, and timelines, to ensure engagements are delivered successfully and on time while meeting the business objectives
-
Creation and finalization of project deliverables, may perform peer review for collateral developed by others on a delivery team
-
Effective presentation of deliverables to project team members.
-
Knowledge of AHEAD’s project lifecycle management activities to effectively support delivery engagements throughout the duration of a project
-
Define and operationalize application security delivery plans, including secure SDLC controls, risk-based finding prioritization, developer enablement, metrics, and executive reporting.
-
Lead application security and threat modeling workshops covering secure architecture, abuse cases, application and API risks, and remediation planning.
Technical Mastery
-
Proficiency in technical troubleshooting; the ability to critically think about a problem and generate a creative solution with minimal oversight.
-
Deep knowledge of scripting, particularly with PowerShell and/or Python, and the ability to troubleshoot developed code.
-
Ability to triage and validate application security findings (SAST, DAST, SCA, secrets), distinguish exploitable issues from false positives, and recommend practical remediations.
-
Ability to effectively communicate aspects of a technical solution to a non-technical individual.
-
Capability to conduct research and utilize available resources to fill in technical knowledge gaps where ambiguity presents itself.
Business Development
-
Support business development pursuits through client discovery meetings
-
Represent service offerings during the sales cycle, including project scoping, proposal development, and presenting proposals to clients
-
Knowledge of AHEAD’s sales management lifecycle to effectively support sales opportunities throughout the duration of a proposal
-
Lead client discovery and/or visioning workshops to identify opportunities for cross-practice collaboration
-
Familiarity with AHEAD’s enterprise service portfolio to identify opportunities for cross-practice collaboration
Practice Development & Thought Leadership
-
Maintain subject matter expertise in a minimum of eight security domains or three security solutions
-
Participate in the development, enhancement, and standardization of AHEAD in-practice service offerings
-
Owns and/or enables more than one service capability
-
Process-focused technology thought leader and evangelist
-
Maintain a broad knowledge and understanding of current and future state IT trends, technologies, and standards
-
Lend support and mentorship to others
-
Domain experience required
-
Cloud Security Architecture & Risk Strategy
-
Proven experience in reviewing and implementing secure cloud reference architectures and landing zones.
-
Experience designing Zero Trust and network segmentation architectures for cloud environments, including micro-segmentation, private connectivity, and egress controls.
-
Ability to translate risk strategy by mapping traditional lift-and-shift approaches into cloud-native security controls.
-
Strong understanding of multi-cloud governance models, including Infrastructure-as-Code (IaC), policy-as-code (PaC), tagging standards, and multi-account strategies.
-
Experience operationalizing a secure cloud SDLC by embedding IaC scanning, policy-as-code guardrails, and drift detection into multi-account and multi-cloud deployment pipelines.
CNAPP Tooling
-
5+ years of combined hands-on experience with CNAPP tools (Wiz preferred)
-
Expertise in integrating CNAPP solutions with enterprise tooling such as ServiceNow, CI/CD pipelines, and ticketing/alerting workflows.
-
Experience extending CNAPP coverage into the SDLC by integrating with source repositories, CI/CD pipelines, and developer workflows to shift application security left.
-
Able to clearly and concisely communicate CNAPP (criticality, risk, remediation) to technical and business stakeholders.
-
Ability to unify application-layer findings (SAST, DAST, SCA, ASPM) with cloud posture and runtime context to prioritize remediation by real exploitability and business risk.
-
Strong track record in deploying and instantiating CNAPP solutions
-
Hands-on experience leveraging the application security and ASPM capabilities within CNAPP platforms — including code and IaC scanning, container image scanning, secrets detection, and code-to-cloud traceability from source to running workload.
Cloud Platforms & Native Security Controls
-
5+ years of experience working with GCP and cloud-native services (AWS and Azure experience optional)
-
Deep understanding and specialist expertise with cloud-native security services such as Google Security Command Center, AWS Security Hub, and/or Microsoft Defender for Cloud).
-
Familiarity with securing managed cloud AI/ML services (e.g., Vertex AI, Amazon Bedrock, Azure OpenAI), including identity and access scoping, data protection, and guardrails.
-
Hands-on knowledge of cloud identity (IAM, Federation, RBAC) across multi-cloud environments.
-
Familiarity with IDaaS solutions such as Okta and Entra ID.
-
Demonstrated experience with leading secure cloud migration projects/programs.
Security Frameworks & Governance
-
Strong knowledge of security standards and frameworks: e.g. CIS Benchmarks, NIST, FedRAMP, ISO 27001, GDPR.
-
Ability to design and map cloud-specific controls for audit and compliance needs.
-
Experience with SIEM integration (Splunk, Sentinel, Chronicle) and cloud-native detection capabilities (optional).
DevSecOps and Application Security
-
Strong understanding of DevSecOps and secure coding best practices, including the ability to assess, implement, and mature application security programs against relevant industry frameworks and maturity models (e.g. OWASP SAMM, DSOMM)
-
Proficiency in application threat modeling (e.g., STRIDE, abuse-case and attack-surface analysis) conducted at design time and integrated into cloud-native and microservices architectures.
-
Experience with reviewing and remediating insecure CI/CD pipelines
-
Experience with Application Security Posture Management (ASPM) and risk-based vulnerability prioritization — correlating and de-duplicating findings across SAST, DAST, and SCA and orchestrating remediation at scale.
-
Hands-on knowledge of DevSecOps and Application Security tooling, including DAST, SAST, SCA, secrets detection, and related solutions.
-
Expertise in API security (REST and GraphQL), including the OWASP API Security Top 10, authentication/authorization and API gateway controls, and testing of APIs exposed by cloud-native and serverless workloads.
-
Ability to read, understand, and apply Infrastructure-as-Code (Terraform, Bicep, AWS CloudFormation).
-
Familiarity with policy-as-code tooling (OPA, Sentinel) and IaC scanning in CI/CD pipelines.
-
Proficiency in scripting (Python, PowerShell, Bash) to automate security tasks.
-
Ability to perform secure code review and secure design/architecture reviews across common languages and frameworks, translating findings into actionable developer guidance.
-
Experience with containerization (Docker, Kubernetes) and securing workloads at scale.
-
Experience securing the software supply chain, including SBOM generation and management, open-source and dependency risk governance, and artifact integrity and provenance (e.g., signing, SLSA).
-
Qualifications
-
-
Undergraduate degree in Computer Sciences or Business Management preferred, but not required
-
Minimum of
-
3+ years of leadership experience
-
10+ years consulting experience, or commensurate work experience
-
Professional and/or technical certifications, including industry-recognized certifications which align to AHEAD’s Security service portfolio are preferred (e.g. CISSP, CCSP)
-
Application security certifications such as CSSLP, GIAC GWEB/GWAPT, OSCP, or equivalent are preferred.
-
Demonstrated experience establishing or maturing application security programs and mentoring engineers and security practitioners.
-
Excellent verbal and written communication skills
-
Comfortable addressing groups of people in virtual or in-person settings
-
Demonstrated Business Acumen
-
Ability to solve complex, abstract problems
-
Excellent interpersonal skills, good listener, ability to connect with different personalities
-
Exhibit Executive presence with leadership characteristics
-
Demonstrated experience as a technology change agent.
-
Skills
- AI
- Analytics
- API
- Api Security
- Authentication
- Automation
- AWS
- AWS Bedrock
- Azure
- Bash
- Bicep
- Business Development
- CI/CD
- Cissp
- Cloud
- Cloud Native
- Cloud Security
- CloudFormation
- Containerization
- DAST
- DevSecOps
- Docker
- Entra ID
- Fedramp
- GCP
- Gdpr
- GraphQL
- IAM
- Infrastructure as Code
- ISO 27001
- Kubernetes
- Machine Learning
- Microservices
- Nist
- Okta
- OpenAI
- OWASP
- PowerShell
- Python
- RBAC
- Requirements Gathering
- SAST
- SDLC
- Secure Coding
- Serverless
- ServiceNow
- SIEM
- Splunk
- Terraform
- Vertex AI
- Zero Trust
As published by lever · 11 questions · 1 written answer
Basics
Resume/CV, Full name, Pronouns, Email, Phone, Current location, Current company, LinkedIn URL, Twitter URL, GitHub URL, Portfolio URL, Other website
Short answers (7)
- Where do you currently reside? (City/State)?
- What % of travel are you open to?
- If so, where would you be open to relocating?
- Do you hold any industry related certifications?
- Expected Salary?
- Primary Residence Address
- Work Authorization status (US Citizen, Green Card Holder, etc.)
Pick from a list (3)
- Are you willing to relocate if needed?
- Confirm the ability to perform the requisite duties of the role with or without reasonable accommodations optional
- AHEAD will consider the contents of an uploaded resume or LinkedIn profile only insofar as it pertains to employment history, and any data that contains or could be a proxy for data that would indicate a person’s age, race, gender, disability status, veteran status, national origin, religion, or other protected characteristic will be disregarded optional
Written answers (1)
- Provide All Post-Secondary Education Attained - Formatted as: College Name; Degree Obtained (e.g.: University of Somewhere; Bachelor of Science). Please include only educational programs from which you graduated. **Any additional information provided, such as dates/year of graduation, will be disregarded.**