Principal Architect, Enterprise Security

Ziply Fiber

Everett (WA)

On-site

USD 180,000 - 240,000

Full time

3 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Ziply Fiber is seeking a Principal Architect, Technology - Enterprise Security to define and advance the security architecture protecting corporate systems, employee infrastructure, and the network serving 1M+ broadband subscribers. This senior role shapes Zero Trust, threat detection, cloud/app security, and IAM design.

Partner with Security Operations and GRC to translate risk into controls, lead standards, reference architectures, and governance.

Qualifications

  • Bachelor's degree in Cybersecurity, IT, CS or closely related field; equivalent experience accepted.
  • 10+ years in security architecture, engineering, cloud/security, IAM, and related fields.
  • Experience defining enterprise architecture standards and influencing cross-functional decisions.
  • Deep expertise in firewall, segmentation, Zero Trust, identity controls, and secure network environments.
  • Strong SOC/telemetry, SIEM, SOAR, and architecture integration capabilities.
  • Ability to translate regulatory requirements into security architecture controls.

Responsibilities

  • Lead enterprise security architecture, including Zero Trust, network segmentation, IAM, MFA, PAM, SSO, and secure remote access.
  • Develop security standards, roadmaps, reference architectures, and design patterns.
  • Define firewall, perimeter security, and access-control strategies.
  • Design secure network architectures and management networks; define DDoS, DNS, IDS/IPS standards.
  • Collaborate with Security Operations to define SIEM/SOAR/EDR/XDR architectures and governance.
  • Translate regulatory requirements (NIST ISO 27001 CIS) into architecture controls.
  • Define security architecture for cloud platforms, containers (Kubernetes), and cloud-native services.
  • Establish application security, secrets management, encryption, and CI/CD security practices.
  • Ensure alignment with governance, risk, and compliance and communicate with executives.

Skills

Security architecture
Zero Trust
IAM
MFA
PAM
SSO
Threat detection
Cloud security
NIST/ISO 27001/CIS
SOC operations
Executive communication

Education

Bachelor's degree in Cybersecurity/IT/CS
Equivalent professional experience

Tools

SIEM
SOAR
EDR/XDR
Cloud platforms (AWS/Azure/GCP)
Kubernetes

Job description

Ziply Fiber is a local internet service provider dedicated to elevating the connected lives of the communities we serve. We offer the fastest home internet in the nation, a refreshingly great customer experience, and affordable plans that put customers in charge.

As our state-of-the-art fiber network expands, so does our need for team members who can help us grow and realize our goals.

Our Company Values:

  • Genuinely Caring: We treat customers and colleagues like neighbors, with empathy and full attention.
  • Empowering You: We help customers choose what is best for them, and we support employees in implementing new ideas and solutions.
  • Innovation and Improvement: We constantly seek ways to improve how we serve customers and each other.
  • Earning Your Trust: We build trust through clear, honest, human communication.

Job Summary

The Principal Architect, Technology - Enterprise Security is a senior individual contributor responsible for defining and advancing the enterprise security architecture and technical standards that protect Ziply Fiber's corporate systems, employee infrastructure, and business applications, as well as the network we operate on behalf of 1M+ broadband subscribers.

This role provides architecture-level direction across corporate and network environments — including Zero Trust strategy, threat detection and response architecture, cloud and application security, and identity and access management design. Operation of the security tooling and Security Operations Center (SOC) sits with the Security Operations function, and control governance and approval sit with Governance, Risk & Compliance (GRC). This separation of duties is deliberate and keeps architecture and design distinct from the operation and assessment of controls.

The successful candidate brings deep, hands-on security architecture expertise in a broadband ISP, telecommunications, or critical-infrastructure environment, and the demonstrated ability to translate business risk into technical design and to communicate security architecture to both engineering teams and executive stakeholders.

Essential Duties and Responsibilities:

The Essential Duties and Responsibilities listed below are a range of duties performed by the employee and not intended to reflect all duties performed.

Security Architecture & Zero Trust

  • Lead enterprise security architecture, including Zero Trust, network segmentation, IAM, MFA, PAM, SSO, and secure remote access.
  • Develop security standards, roadmaps, reference architectures, and design patterns.
  • Define firewall, perimeter security, and access-control strategies.

Network Security Architecture

  • Design secure network architectures, segmentation, access controls, and management networks.
  • Define DDoS protection, DNS security, IDS/IPS, monitoring, and SIEM integration standards.
  • Establish network hardening and secure configuration baselines.

Security Operations & Threat Detection

  • Partner with Security Operations to define SIEM, SOAR, EDR/XDR, and threat detection architectures.
  • Establish detection engineering, vulnerability management, and incident response standards.
  • Ensure enterprise-wide visibility, telemetry, and security monitoring capabilities.
  • Define security architecture for cloud platforms, containers, Kubernetes, and cloud-native services.
  • Establish application security, API security, secrets management, encryption, and data protection standards.
  • Develop secure CI/CD, infrastructure-as-code, and software development practices.
  • Translate regulatory and compliance requirements into security architecture standards and controls.
  • Ensure alignment with NIST, ISO 27001, CIS, telecommunications security requirements, and other applicable regulations.
  • Support architecture reviews and secure-by-design governance processes.

AI & Emerging Technologies

  • Define security standards for AI/ML platforms, generative AI, and emerging technologies.
  • Address AI-specific risks, data protection, and responsible AI adoption.
  • Evaluate future technologies and develop forward-looking security architecture strategies.

Other Duties

  • Must be available to work regular business hours Pacific Standard Time.
  • Must also be available to work on-call, evenings and weekends as needed.

Required Qualifications:

  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a closely related field. Equivalent professional experience may be considered.
  • 10+ years of progressive experience across security architecture, information security engineering, network security, cloud security, identity security, application security, or related technical fields, including substantial experience defining enterprise architecture standards and influencing complex cross-functional technical decisions.
  • Demonstrated senior independent contributor experience mentoring technical professionals, establishing architecture standards, and driving alignment across Security, Network Engineering, IT, Cloud, Application, and GRC stakeholders without direct people-management responsibility.
  • Experience in, or supporting, broadband, telecommunications, critical infrastructure, utilities, cloud, large-scale enterprise technology, or another highly regulated and network-intensive environment.
  • Deep expertise in enterprise or network security architecture, including firewall and segmentation strategy, Zero Trust design, identity-based access controls, and security controls for complex or highly available network environments.
  • Strong security-operations architecture experience, including SIEM/logging architecture, detection coverage, SOAR or workflow integration, telemetry onboarding, and SOC process integration; direct day-to-day SOC operations experience is not required.
  • Hands-on experience with IAM and PAM platforms: MFA, SSO, privileged access governance, and service-account management at enterprise scale.
  • Cloud security architecture experience in at least one major cloud platform such as AWS, Azure, or Google Cloud, with working knowledge of multi-cloud security patterns, CSPM, identity, workload protection, and secure landing-zone design.
  • Experience designing to and implementing security frameworks such as NIST CSF, ISO 27001, or CIS benchmarks.
  • Familiarity with telecommunications or critical-infrastructure security obligations, such as CPNI, CALEA, FCC requirements, or comparable regulatory and compliance frameworks; ability to translate requirements into technical architecture controls.

Preferred Qualifications:

  • CISSP, CISM, or comparable cybersecurity certifications.
  • Experience with SASE/SSE platforms: Zscaler, Palo Alto Prisma, or equivalent.
  • Background in subscriber-facing security: DNS security, RPKI/ROA, and network-level abuse management for broadband operators.
  • Familiarity with OT/ICS security in the context of critical network infrastructure.
  • Experience with DevSecOps practices and secure software development lifecycle (SDLC).
  • Experience presenting security architecture or risk posture to executive leadership.

Knowledge, Skills, and Abilities:

  • Proven ability to design and govern enterprise security architecture, frameworks, and standards.
  • Ability to align security architecture with business objectives and risk management priorities.
  • Strong analytical, strategic planning, and problem-solving skills.
  • Ability to lead technical initiatives and drive alignment across cross-functional teams.
  • Excellent communication skills, including translating technical risk into business impact.
  • Strong leadership and influencing skills, with the ability to mentor teams and establish standards
  • Ability to balance security, operational resilience, regulatory requirements, and business needs.
  • Ability to collaborate effectively across Security, Network Engineering, IT, and GRC organizations while maintaining appropriate governance boundaries.

Applicants must be currently authorized to work in the US for any employer. Sponsorship is not available for this position.

Ziply Fiber must be your primary employer. Outside employment or self-employment requires prior written approval and must not create a conflict of interest with Ziply Fiber's business interests.

Ziply Fiber is an equal opportunity employer and considers all qualified applicants without regard to any legally protected status.

Employment is contingent upon successful completion of a background check and, where applicable, a pre-employment drug screen. Ziply Fiber is a drug-free workplace.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Principal Architect, Technology – Enterprise Security
Principal Architect, Technology – Enterprise Security

Ziply Fiber • Kirkland (WA)

On-site
USD 170,000 - 250,000
Medical
Dental
Vision
+8
Director of Cyber Security
Director of Cyber Security

Ziply Fiber • Everett (WA)

On-site
USD 180,000 - 260,000
Principal Architect, Technology - Infrastructure
Principal Architect, Technology - Infrastructure

Ziply Fiber • Northern (KY)

Hybrid
USD 150,000 - 230,000
Medical
Dental
Vision
+8
Principal Architect, Technology Infrastructure
Principal Architect, Technology Infrastructure

Ziply Fiber • Everett (WA)

On-site
USD 180,000 - 240,000
Principal Architect, Technology - Transport
Principal Architect, Technology - Transport

Doist • United States

On-site
USD 155,000 - 230,000
Medical
Dental
Vision
+7
Remote Principal Architect, Enterprise Security
Remote Principal Architect, Enterprise Security

Ziply Fiber • Kirkland (WA)

On-site
USD 170,000 - 250,000
Medical
Dental
Vision
+8
Senior Enterprise Security Architect - Zero Trust & Cloud
Senior Enterprise Security Architect - Zero Trust & Cloud

Ziply Fiber • Everett (WA)

On-site
USD 180,000 - 240,000
Senior Manager, Corporate Development & Strategy
Senior Manager, Corporate Development & Strategy

Ziply Fiber • Seattle (WA)

On-site
USD 117,000 - 165,000
Medical, dental, vision benefits
401k and flexible spending accounts
Paid sick leave and time off
+3
Local Government Relations Manager
Local Government Relations Manager

Ziply Fiber • Kirkland (WA)

On-site
USD 85,000 - 120,000
Medical
Dental
Vision
+9
Manager, OSP Engineering
Manager, OSP Engineering

Ziplyfiber • United States

On-site
USD 90,000 - 140,000
Medical, dental, vision
401k
Paid time off