
Principal Architect, Security Architecture
Posted 20 hours ago

Posted 20 hours ago
This is a fully remote position, open to applicants in New Jersey, +4 more states.
• Define and enhance the enterprise cybersecurity architecture to align with business strategy, enterprise architecture, technology modernization, regulatory requirements, and risk appetite.
• Establish principles of cybersecurity architecture, reference architectures, reusable patterns, technical standards, and design requirements.
• Maintain or assist in developing a multi-year cybersecurity architecture roadmap.
• Translate Zero Trust principles into actionable architecture across identity, applications, workloads, networks, endpoints, data, cloud, SaaS, OT/IoT, and third-party connectivity.
• Identify architectural fragmentation, redundant controls, security gaps, and opportunities to simplify the security technology ecosystem.
• Establish target-state and transition architectures for complex legacy systems.
• Act as the senior cybersecurity architecture authority for significant technology initiatives and high-risk architectural decisions.
• Lead or significantly influence security architecture reviews for strategic platforms, cloud environments, applications, infrastructure, acquisitions, SaaS platforms, data environments, and emerging technologies.
• Collaborate with Enterprise Architecture to integrate cybersecurity architecture within the enterprise technology strategy.
• Define security architecture for public cloud, private cloud, hybrid infrastructure, SaaS, containers, Kubernetes, serverless, APIs, and platform engineering environments.
• Establish cloud security patterns for identity, workload protection, network segmentation, encryption, secrets management, logging, configuration, exposure management, and security automation.
• Collaborate with cloud, platform engineering, and cybersecurity engineering teams to integrate security into landing zones, infrastructure-as-code, CI/CD pipelines, developer platforms, and automated provisioning.
• Establish data security architecture encompassing classification, encryption, tokenization, key management, secrets, DLP, data access, privacy, lineage, and data movement.
• Provide architectural leadership for generative AI, machine learning, AI agents, RAG architectures, model integration, AI platforms, and third-party AI services.
• Create patterns that address AI-specific threats and collaborate on responsible enterprise AI adoption.
• Integrate cybersecurity architecture into application modernization and secure software development practices.
• Develop reusable security patterns for APIs, microservices, authentication, authorization, secrets, service-to-service communications, software supply chains, and cloud-native applications.
• Partner with IAM architecture and engineering to establish enterprise identity security patterns and advance identity-aware access models.
• Incorporate detection, telemetry, investigation, containment, recovery, and operational resilience into architectural decisions.
• Collaborate with Cyber Defense, SOC, Incident Response, Threat Intelligence, Threat Hunting, Vulnerability Management, and Red Team functions.
• Translate threat intelligence, attack patterns, incidents, vulnerabilities, and control failures into architectural enhancements.
• Utilize threat modeling and attack-path analysis in major architectural decisions.
• Define cybersecurity architecture patterns for acquisitions, divestitures, joint ventures, strategic partners, and third-party connectivity.
• Work directly with cybersecurity and technology engineering teams to convert architecture into actionable capabilities.
• Ensure that reference architectures are technically feasible, scalable, maintainable, and economically viable.
• Engage in proofs of concept, technology evaluations, design workshops, and major implementation decisions.
• Assess emerging security technologies, architectural approaches, attack techniques, and industry best practices.
• Provide technical recommendations regarding cybersecurity technology investments.
• Influence decisions on build-versus-buy and strategic vendor selections.
• Identify opportunities to consolidate, modernize, automate, replace, or retire capabilities.
• Minimize unnecessary security tool proliferation and architectural complexity.
• 12+ years of progressive experience, including over 8 years in cybersecurity architecture, security engineering, infrastructure architecture, cloud security, application security, or related technology fields.
• Extensive experience in designing security solutions within large, complex enterprise environments.
• Ability to architect across multiple security domains.
• Profound understanding of cloud and modern enterprise architecture.
• Strong knowledge of Azure and practical experience with AWS and/or GCP.
• In-depth understanding of identity, network security, endpoint security, data protection, application security, APIs, cloud-native architecture, and cyber defense.
• Experience with Zero Trust architecture and identity-centric security.
• Proven experience in integrating security into cloud engineering, DevSecOps, CI/CD, infrastructure-as-code, and platform engineering.
• Experience in evaluating enterprise security technologies and translating requirements into architecture and engineering decisions.
• Strong understanding of threat modeling, attack paths, vulnerabilities, security controls, and defense-in-depth.
• Ability to communicate complex technical topics to engineers, architects, executives, risk professionals, and business leaders.
• Experience in a large global or highly regulated enterprise is preferred.
• Bachelor’s Degree in Cybersecurity, Computer Science, Information Technology, or a related field, or equivalent relevant experience is preferred.
• Familiarity with NIST Cybersecurity Framework, NIST SP 800-53, NIST Zero Trust Architecture, ISO/IEC 27001, HITRUST, CIS Controls, OWASP, Cloud Security Alliance, AWS Well-Architected Framework, Microsoft Azure Well-Architected Framework, or Google Cloud Architecture Framework is preferred.
• Experience with M&A integration, divestitures, multi-tenant environments, hybrid infrastructure, and large-scale technology modernization is strongly preferred.
• Relevant certifications may include CISSP, CCSP, SSCP, SABSA, cloud architecture/security certifications, or equivalent demonstrated expertise.
• Medical, dental, and vision care.
• Backup dependent care.
• Adoption assistance.
• Infertility coverage.
• Family building support.
• Behavioral health solutions.
• Paid parental leave.
• Paid caregiver leave.
• Training programs.
• Professional development resources.
• Mentorship programs.
• Employee resource groups.
• Volunteer activities.
• Inclusive culture and wellness resources.
Atos
Meridian Bioscience Inc.
Providence
Frontera
Get handpicked remote jobs straight to your inbox weekly.