
Principal Architect, Technology – Enterprise Security
Posted Aug 28

Posted Aug 28
This is a fully remote position, open to applicants in United States.
• Define and oversee the enterprise security architecture for Ziply Fiber within corporate and network environments.
• Establish the Zero Trust reference architecture along with a multi-year strategic roadmap.
• Design firewall, perimeter, IAM, PAM, SSO, federation, and secure remote-access strategies.
• Create and maintain security reference architectures, design patterns, and engineering standards.
• Define the network security architecture, including OOB management, jump hosts, bastions, device access controls, DDoS protection, DNS security, monitoring, anomaly detection, and segmentation.
• Outline SIEM, detection engineering, SOC tooling, SOAR, EDR/XDR, vulnerability management, and incident response architecture.
• Develop cloud security architecture across AWS, Azure, Google Cloud, or equivalent platforms.
• Establish standards for cloud identity, workload protection, containers, Kubernetes, application security, data protection, infrastructure as code, and CI/CD security.
• Collaborate with GRC to translate CPNI, CALEA, FCC telecommunications obligations, and state requirements into architectural controls.
• Ensure that designs are documentable, auditable, and aligned with compliance and industry frameworks.
• Define secure-by-design principles and architecture review standards while contributing architectural input to deployment governance.
• Maintain a clear segregation of duties between architecture, Security Operations, and GRC.
• Establish security architecture for the responsible adoption of AI and machine learning.
• Design controls for model integrity, training data protection, prompt injection, model evasion, and data poisoning risks.
• Define secure architecture for generative AI and AI-enabled security tooling.
• Assess emerging technologies, including post-quantum cryptography and IoT/OT convergence.
• Mentor technical professionals and ensure alignment among cross-functional stakeholders.
• Perform additional duties as required.
• High school diploma or GED.
• Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a closely related field; equivalent professional experience may be considered.
• Over 10 years of progressive experience in security architecture, information security engineering, network security, cloud security, identity security, application security, or related technical fields.
• Significant experience in defining enterprise architecture standards and influencing complex cross-functional technical decisions.
• Experience as a senior independent contributor mentoring technical professionals, establishing architecture standards, and driving alignment across Security, Network Engineering, IT, Cloud, Application, and GRC stakeholders without direct people-management responsibility.
• Background in or supporting broadband, telecommunications, critical infrastructure, utilities, cloud, large-scale enterprise technology, or another highly regulated and network-intensive environment.
• Extensive expertise in enterprise or network security architecture, including firewall and segmentation strategies, Zero Trust designs, identity-based access controls, and security controls for complex or highly available network environments.
• Strong experience in security operations architecture, including SIEM/logging architecture, detection coverage, SOAR or workflow integration, telemetry onboarding, and SOC process integration.
• Hands-on experience with IAM and PAM platforms, including MFA, SSO, privileged access governance, and service-account management at enterprise scale.
• Cloud security architecture experience in at least one major cloud platform such as AWS, Azure, or Google Cloud.
• Familiarity with multi-cloud security patterns, CSPM, identity, workload protection, and secure landing-zone design.
• Experience in designing and implementing security frameworks such as NIST CSF, ISO 27001, or CIS benchmarks.
• Knowledge of telecommunications or critical infrastructure security obligations, such as CPNI, CALEA, and FCC requirements, or other relevant regulatory and compliance frameworks.
• Ability to convert regulatory requirements into technical architecture controls.
• Must be available during regular business hours Pacific Standard Time.
• Must be available for on-call evenings and weekends as required.
• Medical, dental, and vision insurance.
• 401(k) plan.
• Flexible spending account.
• Paid sick leave and paid time off.
• Parental leave.
• Quarterly performance bonus.
• Training opportunities.
• Career growth and education reimbursement programs.
• Target annual bonus.
Leidos
Cisco
RELX
TASQ Staffing Solutions
Get handpicked remote jobs straight to your inbox weekly.