Principal Architect, Security Architecture

Posted 20 hours ago

This is a fully remote position, open to applicants in New Jersey, +4 more states.

📋 Description

• Define and enhance the enterprise cybersecurity architecture to align with business strategy, enterprise architecture, technology modernization, regulatory requirements, and risk appetite.

• Establish principles of cybersecurity architecture, reference architectures, reusable patterns, technical standards, and design requirements.

• Maintain or assist in developing a multi-year cybersecurity architecture roadmap.

• Translate Zero Trust principles into actionable architecture across identity, applications, workloads, networks, endpoints, data, cloud, SaaS, OT/IoT, and third-party connectivity.

• Identify architectural fragmentation, redundant controls, security gaps, and opportunities to simplify the security technology ecosystem.

• Establish target-state and transition architectures for complex legacy systems.

• Act as the senior cybersecurity architecture authority for significant technology initiatives and high-risk architectural decisions.

• Lead or significantly influence security architecture reviews for strategic platforms, cloud environments, applications, infrastructure, acquisitions, SaaS platforms, data environments, and emerging technologies.

• Collaborate with Enterprise Architecture to integrate cybersecurity architecture within the enterprise technology strategy.

• Define security architecture for public cloud, private cloud, hybrid infrastructure, SaaS, containers, Kubernetes, serverless, APIs, and platform engineering environments.

• Establish cloud security patterns for identity, workload protection, network segmentation, encryption, secrets management, logging, configuration, exposure management, and security automation.

• Collaborate with cloud, platform engineering, and cybersecurity engineering teams to integrate security into landing zones, infrastructure-as-code, CI/CD pipelines, developer platforms, and automated provisioning.

• Establish data security architecture encompassing classification, encryption, tokenization, key management, secrets, DLP, data access, privacy, lineage, and data movement.

• Provide architectural leadership for generative AI, machine learning, AI agents, RAG architectures, model integration, AI platforms, and third-party AI services.

• Create patterns that address AI-specific threats and collaborate on responsible enterprise AI adoption.

• Integrate cybersecurity architecture into application modernization and secure software development practices.

• Develop reusable security patterns for APIs, microservices, authentication, authorization, secrets, service-to-service communications, software supply chains, and cloud-native applications.

• Partner with IAM architecture and engineering to establish enterprise identity security patterns and advance identity-aware access models.

• Incorporate detection, telemetry, investigation, containment, recovery, and operational resilience into architectural decisions.

• Collaborate with Cyber Defense, SOC, Incident Response, Threat Intelligence, Threat Hunting, Vulnerability Management, and Red Team functions.

• Translate threat intelligence, attack patterns, incidents, vulnerabilities, and control failures into architectural enhancements.

• Utilize threat modeling and attack-path analysis in major architectural decisions.

• Define cybersecurity architecture patterns for acquisitions, divestitures, joint ventures, strategic partners, and third-party connectivity.

• Work directly with cybersecurity and technology engineering teams to convert architecture into actionable capabilities.

• Ensure that reference architectures are technically feasible, scalable, maintainable, and economically viable.

• Engage in proofs of concept, technology evaluations, design workshops, and major implementation decisions.

• Assess emerging security technologies, architectural approaches, attack techniques, and industry best practices.

• Provide technical recommendations regarding cybersecurity technology investments.

• Influence decisions on build-versus-buy and strategic vendor selections.

• Identify opportunities to consolidate, modernize, automate, replace, or retire capabilities.

• Minimize unnecessary security tool proliferation and architectural complexity.


⛳️ Requirements

• 12+ years of progressive experience, including over 8 years in cybersecurity architecture, security engineering, infrastructure architecture, cloud security, application security, or related technology fields.

• Extensive experience in designing security solutions within large, complex enterprise environments.

• Ability to architect across multiple security domains.

• Profound understanding of cloud and modern enterprise architecture.

• Strong knowledge of Azure and practical experience with AWS and/or GCP.

• In-depth understanding of identity, network security, endpoint security, data protection, application security, APIs, cloud-native architecture, and cyber defense.

• Experience with Zero Trust architecture and identity-centric security.

• Proven experience in integrating security into cloud engineering, DevSecOps, CI/CD, infrastructure-as-code, and platform engineering.

• Experience in evaluating enterprise security technologies and translating requirements into architecture and engineering decisions.

• Strong understanding of threat modeling, attack paths, vulnerabilities, security controls, and defense-in-depth.

• Ability to communicate complex technical topics to engineers, architects, executives, risk professionals, and business leaders.

• Experience in a large global or highly regulated enterprise is preferred.

• Bachelor’s Degree in Cybersecurity, Computer Science, Information Technology, or a related field, or equivalent relevant experience is preferred.

• Familiarity with NIST Cybersecurity Framework, NIST SP 800-53, NIST Zero Trust Architecture, ISO/IEC 27001, HITRUST, CIS Controls, OWASP, Cloud Security Alliance, AWS Well-Architected Framework, Microsoft Azure Well-Architected Framework, or Google Cloud Architecture Framework is preferred.

• Experience with M&A integration, divestitures, multi-tenant environments, hybrid infrastructure, and large-scale technology modernization is strongly preferred.

• Relevant certifications may include CISSP, CCSP, SSCP, SABSA, cloud architecture/security certifications, or equivalent demonstrated expertise.


🏝️ Benefits

• Medical, dental, and vision care.

• Backup dependent care.

• Adoption assistance.

• Infertility coverage.

• Family building support.

• Behavioral health solutions.

• Paid parental leave.

• Paid caregiver leave.

• Training programs.

• Professional development resources.

• Mentorship programs.

• Employee resource groups.

• Volunteer activities.

• Inclusive culture and wellness resources.

People also viewed

Atos14 hours ago

Security Engineer

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
Meridian Bioscience Inc.14 hours ago

Medical Device Cybersecurity Engineer

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
Providence15 hours ago

Senior Security Engineer – Identity and Access Management

US flagCalifornia, +2 more statesFull-timeCybersecurity / Security Engineer$54 – $122/hour
ApplyView job
Frontera15 hours ago

Head of Information Security – Compliance

US flagColorado OnlyFull-timeCybersecurity / Security Engineer$175k – $220k/year
ApplyView job
Accela15 hours ago

Cybersecurity Engineer

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$90k – $110k/year
ApplyView job
Climb Channel Solutions NA18 hours ago

Senior Director, Enterprise Security

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$225k – $260k/year
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers