Posted today · be early
Technical Security Controls Principal
Kemper
IndiaremotePosted today
Skill Required
Cybersecurity-AnalystSecurity-EngineerSecurity-ArchitectInformation-Security-AnalystIT-Security-SpecialistPrincipal-CybersecurityPrincipal-Security-SpecialistSecurity-Controls-EngineeringTechnical LeadsecurityCybersecurityBusiness AnalysisEngineeringautomationObservabilitydesigninganalyticsetc.)designCloudAPIsandFulltime
Key highlights
- Salary range: $93,500–$155,500
- Required experience: 10+ years of progressive cybersecurity
- Key benefit: Medical, Dental, Vision, PTO, 401K
- Notable requirement: Bachelor's degree in Cybersecurity, Computer Science, or related field
- Principal-level role requiring broad security architecture experience
- Role involves automation, scripting, and continuous control monitoring
Role overview
Kemper’s Information Security team is seeking a Technical Security Controls Principal to serve as an enterprise subject-matter authority for technical security control architecture, validation, and continuous assurance. This principal-level role connects control intent to real technical implementation across identity, endpoint, network, cloud, data, application, and logging domains, requiring strong technical depth, judgment, and influence.
Responsibilities
- Define enterprise technical security-control patterns, standards, and design expectations across identity, endpoint, network, cloud, data, application, and logging domains.
- Assess whether controls are technically designed and operating as intended using configuration review, data validation, sampling, walkthroughs, and independent challenge.
- Develop technical test procedures and evidence standards that move beyond questionnaire or document-only assurance.
- Build or sponsor automation, API integrations, telemetry-based analytics, and continuous-control-monitoring use cases.
- Translate regulatory and framework requirements into technically meaningful control objectives and identify controls that are administratively present but ineffective.
- Lead complex control-gap analysis, remediation design, exception/risk-acceptance evaluation, and closure validation.
- Act as a senior technical advisor to Cybersecurity, GRC, Internal Audit, technology teams, and executives on control effectiveness.
- Mentor analysts and engineers and establish consistent control-engineering practices.
Requirements
- Broad and deep security architecture/control experience across multiple technology domains.
- Hands-on ability to review configurations, logs, system data, architecture, technical evidence, and control logic.
- Experience designing technical control tests and validating operating effectiveness.
- Ability to use scripting, APIs, analytics, or security telemetry to automate evidence collection and continuous monitoring.
- Strong understanding of cloud, identity, endpoint, network, application, data-protection, and logging/security-monitoring control patterns.
- Typically 10+ years of progressive cybersecurity.
- Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, Information Systems, or a related discipline, or equivalent relevant professional experience.
Benefits
- Medical, Dental, Vision, PTO, 401K, etc.
Additional details
- Location(s): Not specified
- Originally posted on Himalayas
- The range for this position is 93,500-155,500. When determining candidate offers, we consider experience, skills, education, certifications, and geographic location among other factors.
- Kemper is proud to be an equal opportunity employer. All applicants will be considered for employment without attention to race, color, religion, sex, sexual orientation, gender identity, national origin, veteran, disability status or any other status protected by the laws or regulations in the locations where we operate. We are committed to supporting diversity and equality across our organization and we work diligently to maintain a workplace free from discrimination.
- Kemper does not accept unsolicited resumes through or from search firms or staffing agencies. All unsolicited resumes will be considered the property of Kemper and Kemper will not be obligated to pay a placement fee.
- Kemper will never request personal information, such as your social security number or banking information, via text or email.
- Additionally, Kemper does not use external messaging applications like WireApp or Skype to communicate with candidates. If you receive such a message, delete it.