Principal Cybersecurity Architect
Quick Overview
Job Description
Role : Principal Cybersecurity Architect - Identity, IAM & Zero Trust
LOCATTION : REMOTE
Duration:12+months
Interview: video
Role Summary
Looking for a Principal Cybersecurity Architect to own the enterprise security architecture across identity, access management, and Zero Trust. This is a senior individual contributor role with significant influence over how people, machines, and workloads authenticate, authorize, and access resources across our environment.
Responsibilities
· Partner with IT, infrastructure, and business stakeholders to integrate security into technology decisions
· Mentor and guide security engineers on architecture standards and design decisions
Zero Trust Architecture
· Design and mature a Zero Trust architecture (ZTNA, MFA, PAM) spanning identity, device trust, network access, and application security — grounded in NIST SP 800-207 and BeyondCorp principles.
· Define reference architectures, security patterns, and guardrails consumed across engineering and infrastructure teams
· Lead threat modeling and security architecture reviews for major platform changes and initiatives
· Evaluate and select security tooling (SASE, SSE, ZTNA, NDR, EDR) aligned to the overall architecture strategy
· Drive continuous improvement of Zero Trust posture through gap assessments and maturity modelling
Identity & Access Management (IAM)
· Own the enterprise IAM architecture — covering workforce identity, B2B federation, machine identities, and cloud entitlements
· Design and govern identity lifecycle management: provisioning, role assignment, access reviews, and deprovisioning — ensuring least privilege is enforced by default and not by exception
· Architect federation and SSO standards across the enterprise: SAML 2.0, OIDC, OAuth 2.0 — including integrations with third-party SaaS, partner tenants, and customer-facing portals
· Define authentication assurance levels by resource sensitivity, aligning MFA requirements to NIST AAL2/AAL3 — with a clear roadmap toward phishing-resistant MFA (FIDO2/WebAuthn) for privileged and high-risk access
· Lead the PAM architecture — credential vaulting, just-in-time privilege, session recording, and endpoint privilege management — in partnership with the security operations team
· Govern cloud entitlements across AWS, Azure, and Google Cloud Platform through a CIEM framework: identify over-permissioned roles, enforce least privilege for service principals and IAM roles, and manage cross-account trust relationships
· Establish and maintain a non-human identity strategy: service accounts, API keys, application credentials, and pipeline secrets — eliminating hardcoded credentials and enforcing dynamic secrets via a secrets management platform
· Drive identity governance processes: access certification campaigns, segregation of duties (SoD) controls, and role-based access control (RBAC) model design
· Partner with HR, IT, and business application owners to ensure joiner/mover/leaver processes are automated and auditable
Governance & Stakeholder Engagement
· Define security architecture standards, policies, and exception management processes
· Mentor security engineers and serve as the escalation point for complex identity and access design decisions
· Produce architecture artefacts — threat models, data flow diagrams, trust zone maps — suitable for both technical and executive audiences
· Contribute to the security roadmap and annual planning, translating risk priorities into architectural investments
Qualifications
· 8+ years in information security, with 4+ years in an architecture or senior engineering role
· Deep expertise in Zero Trust frameworks (NIST SP 800-207, BeyondCorp) and identity-centric security
· Strong understanding of threat modeling methodologies (STRIDE, PASTA, ATT&CK)
· Hands-on experience with enterprise IAM platforms — Microsoft Entra ID, Okta, Ping Identity, or equivalent
· Strong grasp of federation protocols: SAML 2.0, OIDC, OAuth 2.0, SCIM
· Experience with PAM platforms (CyberArk, BeyondTrust, Delinea) and secrets management (HashiCorp Vault, AWS Secrets Manager, Azure Key Vault)
· Familiarity with CIEM tooling and cloud IAM governance across at least two major cloud platforms
· Experience designing and governing identity lifecycle and IGA processes (SailPoint, Saviynt, or equivalent a plus)
· Strong understanding of threat modelling methodologies (STRIDE, ATT&CK) and their application to identity attack surfaces
· Excellent communication skills — able to translate complex architecture into clear guidance for engineers, business stakeholders, and executives
· Provan experience using diplomacy skills
Certifications (preferred): CISSP, SABSA, TOGAF, Microsoft SC-100, Okta Certified Architect, or equivalent
Skills
Similar jobs
Systems Engineer SME
Leidos · Alexandria, United States
17 minutes ago$131.3k - $237.3k/yrSystems Engineer SME
Leidos · Herndon, United States
17 minutes ago$131.3k - $237.3k/yrSystems Engineer SME
Leidos · Manassas, United States
17 minutes ago$131.3k - $237.3k/yrSystems Engineer SME
Leidos · Bridgeton, United States
17 minutes ago$131.3k - $237.3k/yrSystems Engineer SME
Leidos · Valley Park, United States
17 minutes ago$131.3k - $237.3k/yrSystems Engineer SME
Leidos · Wood River, United States
17 minutes ago$131.3k - $237.3k/yr