Principal, Corporate Information Security

CotalityDallas, TX
Hybrid

About The Position

At Cotality, we are driven by a single mission—to make the property industry faster, smarter, and more people-centric. Cotality is the trusted source for property intelligence, with unmatched precision, depth, breadth, and insights across the entire ecosystem. Our talented team of 5,000 employees globally uses our network, scale, connectivity and technology to drive the largest asset class in the world. Join us as we work toward our vision of fueling a thriving global property ecosystem and a more resilient society. Cotality is committed to cultivating a diverse and inclusive work culture that inspires innovation and bold thinking; it's a place where you can collaborate, feel valued, develop skills and directly impact the real estate economy. We know our people are our greatest asset. At Cotality, you can be yourself, lift people up and make an impact. By putting clients first and continuously innovating, we're working together to set the pace for unlocking new possibilities that better serve the property industry. Role Overview We are looking for a Principal, Corporate Information Security to step in as a true Business Information Security Officer (BISO) for our internal business verticals. Think of this role as InfoSec Quality Assurance. You will sit directly between our technical security teams and business units—initially focusing on our Insurance business vertical—to evaluate security postures, assess risk maturity, and transition operations from an ad-hoc state to a defined, managed model. We want someone who can wear the CISO hat, guide executive teams to make smart risk decisions, and eventually expand coverage across additional business verticals. We are building a dynamic team and highly encourage professionals from all backgrounds to apply.

Requirements

  • Deep hands-on experience in enterprise risk management and internal security architecture.
  • Ability to threat model internal applications, design compensating controls, and ensure defense in depth principles are applied before a system goes into production.
  • Comfortable sitting in a room with a VP who is pushing to launch a project quickly.
  • Ability to hold the line on critical security requirements, but possess the business acumen to help them find a "secure yes" rather than just saying "no."
  • Ability to explain complex highly technical concepts using everyday language.
  • Strong working grasp of governance frameworks like COBIT, NIST CSF, or ISO 27001.
  • Ability to operationalize governance frameworks so they are actively used by the business.
  • Familiarity with security design models like SABSA is a huge plus.
  • Ability to trace a high-level business objective down to a specific technical control, ensuring security serves the business strategy.
  • Collaborative problem solver who brings diverse perspectives to the table.
  • Act as a bridge between the engineering teams and the business units.
  • Actively mentoring others and fostering a security first culture across the organization.
  • Hands-on expertise using Qualys to evaluate scan outputs, track vulnerabilities, and guide technical teams on remediation.
  • Proficiency in building executive risk dashboards using Google Looker / Looker Studio, Tableau, or Power BI to present actionable security metrics to leadership.
  • Direct experience working within enterprise GRC platforms (e.g., Archer GRC).
  • Direct experience leveraging third-party security rating platforms like BitSight or SecurityScorecard.
  • Ability to evaluate security controls for enterprise AI adoption, including assessing risk around prompt injection, rogue AI, AI agents/zombie agents, and AI data pipeline governance.
  • Bachelor’s degree in IT, Cybersecurity, Computer Science, or a related field (or 8+ years of equivalent senior security experience).
  • CISSP is required (rare exceptions considered only for exceptionally qualified candidates, so please still apply).

Nice To Haves

  • Experience with Black Duck is highly preferred.
  • CISM or SABSA certifications are additional pluses.

Responsibilities

  • Act as the primary security advisor for business leaders across assigned verticals.
  • Review architecture, assess vulnerability data, and evaluate risk maturity before go-live for new applications or policies.
  • Review internal security exceptions and track remediations.
  • Translate technical vulnerabilities into actual business impact so executives understand the risk.
  • Run governance reviews to ensure identity and access controls align with enterprise policies.
  • Actively participate in incident response and change control oversight.
  • Help the business move fast while staying completely secure.

Benefits

  • Generous PTO and 11 paid holidays, plus well-being and volunteer time off.
  • Up to 16 weeks of fully paid parental leave and a baby stipend.
  • Multiple medical plan options with mental health and wellness support offerings.
  • 401(k) with company match and vesting after one year.
  • $400 annual well-being stipend and tuition assistance up to $5,250.
  • Recognition Rewards, Referral bonuses, exclusive discounts and more!
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service