Role Summary
Looking for a Principal Cybersecurity Architect to own the enterprise security architecture across identity, access management, and Zero Trust. This is a senior individual contributor role with significant influence over how people, machines, and workloads authenticate, authorize, and access resources across our environment.
Responsibilities
- Partner with IT, infrastructure, and business stakeholders to integrate security into technology decisions
- Mentor and guide security engineers on architecture standards and design decisions
Zero Trust Architecture
- Design and mature a Zero Trust architecture (ZTNA, MFA, PAM) spanning identity, device trust, network access, and application security — grounded in NIST SP 800-207 and BeyondCorp principles.
- Define reference architectures, security patterns, and guardrails consumed across engineering and infrastructure teams
- Lead threat modeling and security architecture reviews for major platform changes and initiatives
- Evaluate and select security tooling (SASE, SSE, ZTNA, NDR, EDR) aligned to the overall architecture strategy
- Drive continuous improvement of Zero Trust posture through gap assessments and maturity modelling
Identity & Access Management (IAM)
- Own the enterprise IAM architecture — covering workforce identity, B2B federation, machine identities, and cloud entitlements
- Design and govern identity lifecycle management: provisioning, role assignment, access reviews, and deprovisioning — ensuring least privilege is enforced by default and not by exception
- Architect federation and SSO standards across the enterprise: SAML 2.0, OIDC, OAuth 2.0 — including integrations with third-party SaaS, partner tenants, and customer-facing portals
- Define authentication assurance levels by resource sensitivity, aligning MFA requirements to NIST AAL2/AAL3 — with a clear roadmap toward phishing-resistant MFA (FIDO2/WebAuthn) for privileged and high-risk access
- Lead the PAM architecture — credential vaulting, just-in-time privilege, session recording, and endpoint privilege management — in partnership with the security operations team
- Govern cloud entitlements across AWS, Azure, and Google Cloud Platform through a CIEM framework: identify over-permissioned roles, enforce least privilege for service principals and IAM roles, and manage cross-account trust relationships
- Establish and maintain a non-human identity strategy: service accounts, API keys, application credentials, and pipeline secrets — eliminating hardcoded credentials and enforcing dynamic secrets via a secrets management platform
- Drive identity governance processes: access certification campaigns, segregation of duties (SoD) controls, and role-based access control (RBAC) model design
- Partner with HR, IT, and business application owners to ensure joiner/mover/leaver processes are automated and auditable
Governance & Stakeholder Engagement
- Define security architecture standards, policies, and exception management processes
- Mentor security engineers and serve as the escalation point for complex identity and access design decisions
- Produce architecture artefacts — threat models, data flow diagrams, trust zone maps — suitable for both technical and executive audiences
- Contribute to the security roadmap and annual planning, translating risk priorities into architectural investments
Qualifications
- 8+ years in information security, with 4+ years in an architecture or senior engineering role
- Deep expertise in Zero Trust frameworks (NIST SP 800-207, BeyondCorp) and identity-centric security
- Strong understanding of threat modeling methodologies (STRIDE, PASTA, ATT&CK)
- Hands-on experience with enterprise IAM platforms — Microsoft Entra ID, Okta, Ping Identity, or equivalent
- Strong grasp of federation protocols: SAML 2.0, OIDC, OAuth 2.0, SCIM
- Experience with PAM platforms (CyberArk, BeyondTrust, Delinea) and secrets management (HashiCorp Vault, AWS Secrets Manager, Azure Key Vault)
- Familiarity with CIEM tooling and cloud IAM governance across at least two major cloud platforms
- Experience designing and governing identity lifecycle and IGA processes (SailPoint, Saviynt, or equivalent a plus)
- Strong understanding of threat modelling methodologies (STRIDE, ATT&CK) and their application to identity attack surfaces
- Excellent communication skills — able to translate complex architecture into clear guidance for engineers, business stakeholders, and executives
- Proven experience using diplomacy skills
Certifications (preferred): CISSP, SABSA, TOGAF, Microsoft SC-100, Okta Certified Architect, or equivalent