Posted 2 weeks ago
Principal, Corporate Information Security
Job description
At Cotality, we are driven by a single mission—to make the property industry faster, smarter, and more people-centric. Cotality is the trusted source for property intelligence, with unmatched precision, depth, breadth, and insights across the entire ecosystem. Our talented team of 5,000 employees globally uses our network, scale, connectivity and technology to drive the largest asset class in the world. Join us as we work toward our vision of fueling a thriving global property ecosystem and a more resilient society. Cotality is committed to cultivating a diverse and inclusive work culture that inspires innovation and bold thinking; it's a place where you can collaborate, feel valued, develop skills and directly impact the real estate economy. We know our people are our greatest asset. At Cotality, you can be yourself, lift people up and make an impact. By putting clients first and continuously innovating, we're working together to set the pace for unlocking new possibilities that better serve the property industry. Job Description: Role Overview We are looking for a Principal, Corporate Information Security to step in as a true Business Information Security Officer (BISO) for our internal business verticals. Think of this role as InfoSec Quality Assurance. You will sit directly between our technical security teams and business units—initially focusing on our Insurance business vertical—to evaluate security postures, assess risk maturity, and transition operations from an ad-hoc state to a defined, managed model. We want someone who can wear the CISO hat, guide executive teams to make smart risk decisions, and eventually expand coverage across additional business verticals. We are building a dynamic team and highly encourage professionals from all backgrounds to apply. What You Will Do You will act as the primary security advisor for business leaders across assigned verticals. For example, if a team wants to launch a new application or policy, you are the one reviewing architecture, assessing vulnerability data, and evaluating risk maturity before go-live. You will review internal security exceptions, track remediations, and translate technical vulnerabilities into actual business impact so executives understand the risk. You will also run governance reviews to ensure identity and access controls align with enterprise policies, while actively participating in incident response and change control oversight. It is all about finding ways to help the business move fast while staying completely secure. Core Competencies and Skills Enterprise Risk & Architecture Deep hands on experience in enterprise risk management and internal security architecture. You know how to threat model internal applications, design compensating controls, and ensure defense in depth principles are applied before a system goes into production. Executive Presence & Negotiation You are comfortable sitting in a room with a VP who is pushing to launch a project quickly. You have the backbone to hold the line on critical security requirements, but the business acumen to help them find a "secure yes" rather than just saying "no." Translation & Risk Articulation You know how to explain complex highly technical concepts using everyday language. Instead of telling a non technical leader about a "CVSS 9.8 vulnerability," you can translate that into operational or financial risk so they actually understand the business impact. Governance Frameworks A strong working grasp of governance frameworks like COBIT, NIST CSF, or ISO 27001. More importantly, you know how to operationalize these frameworks so they are actively used by the business, not just sitting in a binder. Security Design Familiarity with security design models like SABSA is a huge plus. You know how to trace a high-level business objective down to a specific technical control, ensuring security serves the business strategy. Collaborative Mindset & Culture Building You are a collaborative problem solver who brings diverse perspectives to the table. You act as a bridge between the engineering teams and the business units, actively mentoring others and fostering a security first culture across the organization.
Job Qualifications
Tools & Technologies Vulnerability & Scan Management (Required): Hands-on expertise using Qualys (must-have) and Veracode to evaluate scan outputs, track vulnerabilities, and guide technical teams on remediation.
Experience
with Black Duck is highly preferred. Data & Reporting Visualization (Required): Proficiency in building executive risk dashboards using Google Looker / Looker Studio. Tableau, or Power BI to present actionable security metrics to leadership. GRC & Security Ratings (Required): Direct experience working within enterprise GRC platforms (e.g., Archer GRC) and leveraging third-party security rating platforms like BitSight or SecurityScorecard. AI Security & Emerging Threats (Strong Differentiator): Ability to evaluate security controls for enterprise AI adoption, including assessing risk around prompt injection, rogue AI, AI agents/zombie agents, and AI data pipeline governance.
Education
and Certifications
Education
Bachelor’s degree in IT, Cybersecurity, Computer Science, or a related field (or 8+ years of equivalent senior security experience). Certifications: CISSP is required (rare exceptions considered only for exceptionally qualified candidates, so please still apply). CISM or SABSA certifications are additional pluses. Annual
Pay Range
134,400 - 165,000 USD Application Window: This opportunity is expected to remain posted through the date identified below, subject to business needs. Thrive with Cotality At Cotality, we offer more than just a job, we provide a benefits experience designed to support your whole self. From a flexible working model to competitive time off and standout health coverage with meaningful perks and growth opportunities, our package is built to help you thrive at work and in life. Highlights, depending on role classification, include: Time off: Generous PTO and 11 paid holidays, plus well-being and volunteer time off. Family Support: Up to 16 weeks of fully paid parental leave and a baby stipend. Health: Multiple medical plan options with mental health and wellness support offerings. Retirement: 401(k) with company match and vesting after one year. Financial Perks: $400 annual well-being stipend and tuition assistance up to $5,250. Extras: Recognition Rewards, Referral bonuses, exclusive discounts and more! Cotality is an Equal Opportunity employer committed to attracting and retaining the best-qualified people available, without regard to race, color, religion, national origin, gender, sexual orientation, gender identity, age, disability or status as a veteran of the Armed Forces, or any other basis protected by federal, state or local law. Cotality maintains a Drug-Free Workplace. Cotality is fully committed to a work environment that embraces everyone’s unique contributions, experiences and values. We offer an empowered work environment that encourages creativity, initiative and professional growth and provides a competitive salary and benefits package. We are better together when we support and recognize our differences. Privacy Policy Global Applicant Privacy Policy By providing your telephone number, you agree to receive automated (SMS) text messages at that number from Cotality regarding all matters related to your application and, if you are hired, your employment and company business. Message & data rates may apply. You can opt out at any time by responding STOP or UNSUBSCRIBING and will automatically be opted out company-wide. Connect with us on social media! Click on the quicklinks below to find out more about our company and associates Looking for a Remote role? Please navigate to "location" and filter on desired country under the "locations". ex: United States, Canada, United Kingdom, India Are you ready for a career with Cotality? We have some exciting news to share with you, CoreLogic will now be called Cotality! Our new brand reflects our commitment to delivering innovative solutions and building deep relationships. Speaking of fresh starts—if you’re thinking about making a change, and you’re someone who wants to work for a growing company with a people-first culture which has earned us Great Place to Work recognitions in six countries, apply today! Cotality is an Equal Opportunity employer committed to attracting and retaining the best-qualified people available, without regard to race, color, religion, national origin, gender, sexual orientation, gender identity, age, disability or status as a veteran of the Armed Forces, or any other basis protected by federal, state or local law. Cotality will not discriminate or retaliate against applicants who inquire about, disclose, or discuss their compensation or that of other applicants. If you need reasonable accommodation to complete the on-line application, please contact Talent Acquisition at careers@cotality.com or 1-866-224-2086. Please include the following information in your email: The specific accommodation you’re requesting to complete an employment application the position you are applying for (job title and/or job number) Do you represent a third-party organization supporting individuals with disabilities? You can contact us at careers@cotality.com. Please allow up to three business days to receive a response. Please include the following information in your email: Your organization’s name Organization’s location(s) Brief description of your need Cotality is aware of schemes involving fraudulent job postings on third-party employment search sites and/or individual(s) or entities claiming to be employees of Cotality. Those involved are offering fraudulent employment opportunities to applicants, often asking for sensitive personal and financial information. If you believe you have been contacted by anyone misrepresenting themselves as an employee of Cotality or a Cotality recruiter, please contact Cotality at careers@cotality.com. Please be advised that all legitimate correspondence from a Cotality employee will come from "@Cotality.com" or "@CoreLogic.com" email accounts. Cotality will not interview candidates via text or email. Our interviews will be conducted by recruiters and leaders via the phone, zoom/teams or in an in-person format. Cotality will never ask candidates to make any type of personal financial investment related to gaining employment with the Company. Please click here to view the Cotality Applicant Privacy Statement. By providing your telephone number, you agree to receive automated (SMS) text messages at that number from Cotality regarding all matters related to your application and, if you are hired, your employment and company business. Message & data rates may apply. You can opt out at any time by responding STOP or UNSUBSCRIBING and will automatically be opted out company-wide.
Skills and functions
- Human Resources