
Principal Security Analyst
Job description
About the role
ZoomInfo is where careers accelerate. You will execute the organization's security audit, compliance, awareness, and training programs while working alongside global security leadership. The role requires conducting technical security assessments, managing third-party vendor risk, and developing audit documentation. You will prepare audit reports and executive summaries tailored for both technical teams and business stakeholders. This position drives security culture through training, policy tracking, and evidence-based findings. You will maintain compliance certifications and close the loop on remediation activities. Success in this role means turning complex security controls into actionable programs across the organization.
Key facts
What you'll do
- Execute security audit programs using established methodologies and detailed audit plans.
- Conduct technical security assessments of systems, applications, and infrastructure components.
- Perform AI third-party vendor security audits and comprehensive risk assessments.
- Document audit findings with supporting evidence, clear narratives, and standardized risk ratings.
- Track audit remediation activities, follow up on open findings, and verify closure accuracy.
- Prepare audit reports and executive summaries that address technical and business audiences.
- Develop and maintain audit templates, checklists, and repeatable procedures for consistency.
- Maintain secure audit documentation and evidence repositories with controlled access.
- Support compliance management for ISO certifications including 27001, 27701, 27017, and 42001.
- Assist with SOC2 Type 2 audit preparation, evidence collection, and testing validation.
- Conduct gap assessments by comparing current practices against compliance framework requirements.
- Coordinate with external auditors and certification bodies to streamline review cycles.
- Monitor compliance with internal security policies, standards, and regulatory baselines.
- Track compliance remediation activities against defined timelines and ownership.
- Prepare compliance status reports that highlight risk posture and trend analysis.
- Maintain a compliance calendar and tracking system to ensure timely renewals and assessments.
- Develop and execute an annual security awareness plan with monthly thematic campaigns.
- Create security awareness content such as emails, quick tips, posters, infographics, and videos.
- Develop AI security awareness content and role-specific training materials for evolving threats.
- Design and deliver role-based security training for developers, executives, new hires, and managers.
- Manage the Learning Management System for security training, completion tracking, and metrics.
- Conduct security culture surveys, analyze results, and recommend targeted improvements.
- Develop and manage a security champions program to extend security advocacy across teams.
- Partner with the Communications team to align security messaging and internal announcements.
- Create video content and scripts for training programs that engage and educate employees.
- Support executive and board-level security training with tailored briefings and insights.
Requirements
- Hold a Bachelor's degree in Information Security, Computer Science, Information Technology, or a related field.
- A Master's degree is preferred for this position.
- Possess at least one required certification such as CISSP, CISA, CISM, CRISC, ISO 27001 Lead Auditor, or Security+.
- Additional preferred certifications include ISO 27701 Lead Auditor, ISO 42001, or CEH, CCSP.
- Bring 8-10 years of experience in information security focused on technical roles, GRC, audit, or compliance.
- Demonstrate prior experience conducting security audits or detailed security assessments.
- Show familiarity with compliance frameworks such as ISO 27001, SOC2, and similar standards.
- Have hands-on experience with risk assessment methodologies and vendor security reviews.
- Proven ability to work effectively with global teams across multiple time zones.
- Prior experience in technology or SaaS companies is preferred for this role.
Nice to have
- Experience with security audit tools, reporting platforms, and compliance management systems.
- Knowledge of AI and machine learning security risks, model governance, and emerging regulations.
- Familiarity with secure software development lifecycle practices and DevSecOps integration.
- Understanding of cloud security standards such as CSA CCM and major cloud provider security offerings.
- Background in security awareness measurement, training effectiveness analytics, and behavior change programs.
- Participation in professional communities, speaking engagements, or security research contributions.
Practical notes
- This engagement may require occasional travel within India and internationally based on audit or compliance needs.
- Visa requirements for international travel will be handled per company policy and role necessity.
- The schedule is aligned with business needs and may involve limited after-hours coordination for global team coverage.
- Employment terms and start dates will be confirmed based on sourcing details and internal approval.