- Location
- RALEIGH, United States of America
- Workplace
- Remote, Hybrid, Onsite
- Type
- Full-time
- Department
- Engineering
- Seniority
- Lead
- Education
- Master
- Source
- Workday
Description
Job Description
We are seeking a Principal Security Architect to lead the design, review, and evolution of secure technology solutions across cloud, hybrid, and on-premises environments. This individual will serve as a trusted cybersecurity leader, driving architecture strategy, advancing IAM, EDR, Vulnerability Management, and Zero Trust initiatives, and partnering with cross-functional teams to strengthen the organization's security posture and reduce risk.
This role is based out of our corporate headquarters in Raleigh, NC (4 days in office, 1 day remote)
Key Responsibilities
- Develop and maintain cybersecurity architecture strategy, roadmaps, reference architectures, standards, patterns, and artifacts aligned with business drivers, technology strategy, and the evolving threat landscape (including multi-cloud and on-premises).
- Lead architecture design and formal security architecture reviews for new solutions, major changes, cloud migrations, applications, infrastructure, and third-party integrations—identifying risks and recommending practical mitigations.
- Architect and guide solutions across core verticals:
- Identity & Access Management (IAM) — Zero Trust principles, SSO/MFA, RBAC/least privilege, identity lifecycle, privileged access, and federation.
- Endpoint Detection & Response (EDR/XDR) and related endpoint protection controls.
- Vulnerability Management (VM) — scanning architecture, prioritization, remediation workflows, and integration with broader risk processes.
- Broader security controls including network segmentation, encryption, logging/detection, cloud security posture, and secure configurations.
- Provide hands-on engineering input: evaluate tools/platforms, support proofs-of-concept, guide implementation and integration, validate controls, and contribute to automation/scripting where appropriate.
- Conduct threat modeling, risk assessments, and gap analyses; translate findings into actionable architecture recommendations and control improvements.
- Serve as a trusted advisor and liaison—clearly communicating technical risks, trade-offs, and solutions to both technical and non-technical audiences; influence decision-making and continuous improvement.
- Stay current with emerging threats, technologies, and frameworks (NIST, ISO 27001, MITRE ATT&CK, Zero Trust, etc.); evaluate and recommend enhancements to security posture and processes.
Required Qualifications & Experience
- 8–12+ years in cybersecurity with substantial architecture and engineering experience (strong hands-on background preferred over pure strategy roles).
- Demonstrated depth across multiple domains: IAM, EDR/endpoint security, vulnerability management, and security architecture design + formal review processes.
- Proven ability to solve complex, ambiguous technical and organizational problems in large or complex environments and to interface effectively across security, IT/engineering, cloud, and business teams.
- Solid experience with security architecture principles, frameworks, and practices (Zero Trust, NIST CSF/800-53, ISO 27001, MITRE ATT&CK, threat modeling methodologies such as STRIDE).
- Hands-on familiarity with relevant technologies and platforms (examples: identity platforms such as Okta/Entra ID, EDR solutions.
- Experience designing and reviewing architectures for hybrid/multi-cloud and on-premises environments.
- Excellent communication, stakeholder management, and collaboration skills—ability to translate complex topics and drive alignment.
Preferred Qualifications
- Experience in retail, large distributed enterprises, or highly regulated environments.
- Leadership or principal-level individual contributor experience guiding technical direction without direct people management (or light leadership of architecture efforts).
California Residents click below for Privacy Notice: