Principal, Corporate Information Security

Cotality
  • Dallas, Texas
    2 days ago

    Job Description

    At Cotality, we are driven by a single mission-to make the property industry faster, smarter, and more people-centric. Cotality is the trusted source for property intelligence, with unmatched precision, depth, breadth, and insights across the entire ecosystem. Our talented team of 5,000 employees globally uses our network, scale, connectivity and technology to drive the largest asset class in the world. Join us as we work toward our vision of fueling a thriving global property ecosystem and a more resilient society.

    Cotality is committed to cultivating a diverse and inclusive work culture that inspires innovation and bold thinking; it's a place where you can collaborate, feel valued, develop skills and directly impact the real estate economy. We know our people are our greatest asset. At Cotality, you can be yourself, lift people up and make an impact. By putting clients first and continuously innovating, we're working together to set the pace for unlocking new possibilities that better serve the property industry.

    Job Description:

    Role Overview
    We are looking for a Principal, Corporate Information Security to step in as a true Business Information Security Officer (BISO) for our internal business verticals. Think of this role as InfoSec Quality Assurance. You will sit directly between our technical security teams and business units-initially focusing on our Insurance business vertical-to evaluate security postures, assess risk maturity, and transition operations from an ad-hoc state to a defined, managed model. We want someone who can wear the CISO hat, guide executive teams to make smart risk decisions, and eventually expand coverage across additional business verticals. We are building a dynamic team and highly encourage professionals from all backgrounds to apply.

    What You Will Do
    You will act as the primary security advisor for business leaders across assigned verticals. For example, if a team wants to launch a new application or policy, you are the one reviewing architecture, assessing vulnerability data, and evaluating risk maturity before go-live. You will review internal security exceptions, track remediations, and translate technical vulnerabilities into actual business impact so executives understand the risk. You will also run governance reviews to ensure identity and access controls align with enterprise policies, while actively participating in incident response and change control oversight. It is all about finding ways to help the business move fast while staying completely secure.

    Core Competencies and Skills
    • Enterprise Risk & Architecture
      Deep hands on experience in enterprise risk management and internal security architecture. You know how to threat model internal applications, design compensating controls, and ensure defense in depth principles are applied before a system goes into production.
    • Executive Presence & Negotiation
      You are comfortable sitting in a room with a VP who is pushing to launch a project quickly. You have the backbone to hold the line on critical security requirements, but the business acumen to help them find a "secure yes" rather than just saying "no."
    • Translation & Risk Articulation
      You know how to explain complex highly technical concepts using everyday language. Instead of telling a non technical leader about a "CVSS 9.8 vulnerability," you can translate that into operational or financial risk so they actually understand the business impact.
    • Governance Frameworks
      A strong working grasp of governance frameworks like COBIT, NIST CSF, or ISO 27001. More importantly, you know how to operationalize these frameworks so they are actively used by the business, not just sitting in a binder.
    • Security Design
      Familiarity with security design models like SABSA is a huge plus. You know how to trace a high-level business objective down to a specific technical control, ensuring security serves the business strategy.
    • Collaborative Mindset & Culture Building
      You are a collaborative problem solver who brings diverse perspectives to the table. You act as a bridge between the engineering teams and the business units, actively mentoring others and fostering a security first culture across the organization.
    Job Qualifications:

    Tools & Technologies
    • Vulnerability & Scan Management (Required): Hands-on expertise using Qualys (must-have) and Veracode to evaluate scan outputs, track vulnerabilities, and guide technical teams on remediation. Experience with Black Duck is highly preferred.
    • Data & Report

    Numbers & Facts

    LocationDallas, Texas

    More jobs like this

    See more jobs

    Be found by employers

    5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.