ForgeApply
Try it free

ForgeApply · Job listing

Principal Information Security Engineer - Governance, Risk & Security Awareness

Ferguson

Remote · US

See all 147 open roles at Ferguson

Tailor your resume for this Ferguson job in about a minute.

ForgeApply tailors your resume and cover letter to this exact posting, then hands you a ready-to-submit application for Ferguson's site. Free trial, no card required.

About this role

Job Posting: Since 1953, Ferguson has been a source of quality supplies for a variety of industries. Together We Build Better infrastructure, better homes and better businesses. We exist to make our customers’ complex projects simple, successful, and sustainable. We proactively solve problems, adapt and grow to continuously serve our customers, communities and each other. Ferguson, a Fortune 500 company, is proud to provide best-in-class products, service and capabilities across the following industries: Commercial/Mechanical, Facilities Supply, Fire and Fabrication, HVAC, Industrial, Residential Trade, Residential Building and Remodel, Waterworks and Residential Digital Commerce. Ferguson has approximately 36,000 associates across 1,700 locations. Ferguson is a community of proud associates who operate with the shared purpose of building something meaningful. You will build a career that you are proud of, at a company you can believe in.

Principal Information Security Engineer - Governance, Risk & Security Awareness

The Principal Information Security Engineer - Governance, Risk & Security Awareness is an experienced cybersecurity leader responsible for strengthening Ferguson's security posture through enterprise risk management, security governance, third-party risk oversight, and security awareness initiatives. This role serves as a trusted advisor across the organization, helping identify, assess, communicate, and reduce cybersecurity risks while advancing security maturity and risk management practices.

A primary focus of this role is leading Ferguson's phishing simulation and security awareness program, driving a proactive approach to human risk management. This includes developing and executing risk-informed phishing campaigns, measuring program effectiveness, analyzing user behavior trends, and implementing targeted awareness strategies that strengthen cybersecurity knowledge and behavior across the enterprise. The role also leads enterprise risk assessments, third-party security reviews, governance initiatives, and executive reporting that support informed decision-making and risk-based prioritization.

Partnering closely with peers across Information Security, Technology, Internal Audit, Procurement, Legal, HR, Communications, and business leadership, the Principal Information Security Engineer translates complex cybersecurity risks into actionable business insights and recommendations. The ideal candidate brings deep expertise in cybersecurity governance, enterprise risk management, security awareness, and threat mitigation, combined with strong communication, stakeholder influence, and program leadership skills.

Location: This role is approved to be fully remote and can be based anywhere in the continental United States.

Duties & Responsibilities: • Lead cybersecurity risk assessments and security maturity evaluations using industry frameworks, including NIST CSF, identifying control gaps, emerging risks, and opportunities to strengthen Ferguson's security posture. • Develop risk mitigation strategies, remediation plans, and governance recommendations, partnering with business and technology teams to drive sustainable risk reduction. • Support the development and continuous improvement of cybersecurity governance processes, security roadmaps, risk registers, and program performance metrics. • Coordinate and support internal and external audits, independent security assessments, regulatory reviews, and risk management initiatives. • Lead Ferguson's enterprise simulated phishing exercises and cybersecurity education program, developing risk-based campaigns and targeted training initiatives that improve employee awareness and cyber resilience. • Analyze phishing simulation results, reporting trends, and awareness metrics to identify risks, measure efficiency, and drive ongoing improvement of security culture. • Partner with business leaders, Human Resources, Corporate Communications, and Information Security teams to reduce phishing susceptibility and increase employee engagement in security procedures. • Conduct security assessments of vendors, suppliers, and technology partners as part of Ferguson's third-party risk management program. • Review security questionnaires, SOC reports, penetration test results, compliance certifications, and other security documentation to evaluate vendor risk. • Identify, assess, and communicate third-party security risks, providing recommendations to support informed business decisions and remediation efforts. • Collaborate with Procurement, Legal, and business customers to help ensure appropriate security requirements are incorporated into third-party engagements. • Develop and maintain cybersecurity dashboards, scorecards, important metrics, KRIs, and executive reporting that provide access to risk, compliance, and program performance. • Apply reporting and automation tools to improve the efficiency, effectiveness, and scalability of Governance, Risk, and Compliance (GRC) activities. • Translate technical risks into business-focused insights, helping leaders understand risk exposure, prioritize remediation efforts, and make informed decisions. • Serve as a trusted advisor on cybersecurity governance, risk management, and compliance matters, building strong partnerships across business and technology teams. • Communicate security risks, recommendations, and program outcomes effectively to both technical and non-technical audiences, including senior leadership.

Qualifications & Requirements: • Bachelor's degree in Information Security, Cybersecurity, Information Systems, Computer Science, Business Administration, or a related field; equivalent combination of education and experience will be considered. • 5+ years of experience in Information Security, Cybersecurity, IT Risk Management, IT Audit, Governance, Risk & Compliance (GRC), or related disciplines. • Experience conducting security risk assessments and evaluating security controls acr

Tailor your resume for this Ferguson role before you apply.

Tailor my resume for this job

Similar jobs

More like this: Security & Cybersecurity Jobs · Remote Security & Cybersecurity Jobs · Browse all jobs

Free ATS checker · How to Tailor Your Resume to a Job Description (Step by Step)