Principal Architect, Security Architecture

Cencora

Trenton (NJ)

On-site

USD 180,000 - 280,000

Full time

12 days ago
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Cencora is seeking a Principal Architect, Cybersecurity to lead enterprise security architecture strategy across cloud, data, AI, and applications. The role drives architecture decisions, reduces risk, and shapes technology direction in collaboration with cybersecurity and engineering teams.

You will translate business goals, regulatory obligations, and emerging threats into pragmatic security patterns, standards, and governance across the organization.

Qualifications

  • Senior-level cybersecurity architecture experience across multiple domains.
  • Ability to translate business strategy and regulatory obligations into security architectures.
  • Experience leading architecture decisions and influencing cross-domain teams.
  • Strong communication and governance capabilities across enterprise context.

Responsibilities

  • Define and evolve enterprise cybersecurity architecture aligned with strategy and risk appetite.
  • Lead security architecture reviews for platforms, cloud, data, and applications.
  • Translate Zero Trust principles into practical architectures across identity, workloads, networks, and data.
  • Partner with Enterprise Architecture to embed cybersecurity in strategy and roadmaps.
  • Collaborate with cloud, data, AI, and security teams to enable secure digital initiatives.

Skills

Security architecture
Cloud security
Identity & Access Management
Data security
Application security
Zero Trust
Threat modeling
Enterprise architecture

Tools

Kubernetes
CI/CD security
IAM tooling

Job description

Our team members are at the heart of everything we do. At Cencora, we are united in our responsibility to create healthier futures, and every person here is essential to us being able to deliver on that purpose. If you want to make a difference at the center of health, come join our innovative company and help us improve the lives of people and animals everywhere. Apply today!

Job Details
Summary
The Principal Architect, Security Architecture is a senior individual-contributor and enterprise technical leadership role responsible for defining, governing, and advancing cybersecurity architecture across the enterprise in collaboration with other Principal Architects, Cybersecurity Architects, & Cybersecurity and domain engineering teams.
The Principal Architect translates business strategy, technology direction, cyber risk, regulatory obligations, and emerging threats into practical security architectures, principles, patterns, standards, and technology decisions that enable the business while measurably reducing risk.
This role operates beyond individual cybersecurity products or domains. The Principal Architect - Cybersecurity works horizontally across the functional technology domains and the related security practices for Cloud, Infrastructure, Endpoint, Network, Storage; while also collaborating and representing core cybersecurity practices such as Identity & Access Management, Application Security, Data Security, AI Security, Cyber Defense, SaaS Security, OT/IoT, and emerging technologies, ensuring that security capabilities function as an integrated enterprise architecture rather than independent controls.
The successful candidate must combine the depth of a senior security technologist with the influence, judgment, and communication capabilities of an enterprise architect. This position is expected to challenge legacy assumptions, resolve difficult cross-domain architecture decisions, simplify security complexity, and establish clear technical direction where ownership or requirements are ambiguous.
This is not primarily a documentation, compliance, or architecture-review role. The Principal Architect - Cybersecurity is expected to shape technology and cybersecurity platform strategy and materially influence what the enterprise builds, buys, integrates, modernizes, and retires.
Key Responsibilities
Enterprise Cybersecurity Architecture
  • Define and evolve the enterprise cybersecurity architecture aligned with business strategy, enterprise architecture, technology modernization, regulatory obligations, and the organization’s risk appetite.
  • Establish cybersecurity architecture principles, reference architectures, reusable patterns, technical standards, and design requirements.
  • Maintain or support a multi-year cybersecurity architecture roadmap connecting strategic security objectives with technology investments and engineering execution.
  • Translate Zero Trust principles into practical architecture across identity, applications, workloads, networks, endpoints, data, cloud, SaaS, OT/IoT, and third-party connectivity.
  • Identify architectural fragmentation, redundant controls, security gaps, and opportunities to simplify the security technology ecosystem.
  • Establish clear target-state architectures and pragmatic transition architectures for complex legacy environments.
Architecture Governance & Decision Authority
  • Serve as a senior cybersecurity architecture authority for significant technology initiatives and high-risk architecture decisions.
  • Lead or materially influence security architecture reviews for strategic platforms, cloud environments, applications, infrastructure, acquisitions, SaaS platforms, data environments, and emerging technologies.
  • Determine when enterprise security requirements require standardization versus when risk-based exceptions or domain-specific patterns are appropriate.
  • Document significant architectural decisions, alternatives, assumptions, dependencies, and residual risks.
  • Establish escalation mechanisms for architecture decisions that cannot be resolved within individual engineering or security domains.
  • Partner with Enterprise Architecture to ensure cybersecurity architecture is embedded within enterprise technology strategy rather than operating as a downstream approval function.
Will Lead or Collaborate to Deliver Cloud & Platform Security Architecture
  • Define security architecture across public cloud, private cloud, hybrid infrastructure, SaaS, containers, Kubernetes, serverless, APIs, and platform engineering environments.
  • Establish cloud security patterns covering identity, workload protection, network segmentation, encryption, secrets, logging, configuration, exposure management, and security automation.
  • Guide adoption of cloud-native security capabilities and determine where enterprise security platforms provide greater consistency or risk reduction.
  • Drive security architecture aligned with hyperscaler well-architected principles while maintaining consistent enterprise control objectives.
  • Partner with cloud, platform engineering, and all other applicable cybersecurity engineering team to embed security into landing zones, infrastructure-as-code, CI/CD pipelines, developer platforms, and automated provisioning.
Will Lead or Collaborate to Deliver Data & AI Security
  • Establish architecture principles and patterns protecting enterprise data throughout its lifecycle.
  • Define security architectures addressing classification, encryption, tokenization, key management, secrets, DLP, data access, privacy, lineage, and data movement.
  • Provide architecture leadership for generative AI, machine learning, AI agents, RAG architectures, model integration, AI platforms, and third-party AI services.
  • Establish patterns addressing AI‑specific threats including sensitive-data disclosure, prompt injection, insecure tool use, excessive agency, model supply‑chain risk, identity, authorization, and AI application monitoring.
  • Partner with AI, Data, Privacy, Legal, Risk, and business teams to enable responsible enterprise adoption of emerging AI capabilities.
Will Lead or Collaborate to Deliver Application & API Security Architecture
  • Integrate cybersecurity architecture into application modernization and secure software development practices.
  • Establish reusable security patterns for APIs, microservices, authentication, authorization, secrets, service‑to‑service communications, software supply chains, and cloud‑native applications.
  • Partner with AppSec and development organizations to move security requirements earlier into architecture and engineering.
  • Promote security capabilities that can be consumed through standardized platforms, APIs, pipelines, and reusable engineering components rather than manual security reviews.
Will Lead or Collaborate to Deliver Identity & Zero Trust
  • Partner with IAM architecture and engineering to establish enterprise identity security patterns.
  • Ensure workforce, privileged, machine, service, workload, API, and customer identities are incorporated into enterprise security architecture.
  • Advance policy-based and identity‑aware access models that reduce dependence on network location as the primary trust mechanism.
  • Integrate identity, device posture, workload identity, data sensitivity, threat signals, and contextual risk into access‑control architecture.
Will Lead or Collaborate to Deliver Cyber Defense & Resilience
  • Ensure architecture decisions incorporate detection, telemetry, investigation, containment, recovery, and operational resilience requirements.
  • Partner with Cyber Defense, SOC, Incident Response, Threat Intelligence, Threat Hunting, Vulnerability Management, and Red Team functions.
  • Translate threat intelligence, attack patterns, incidents, vulnerabilities, and control failures into architecture improvements.
  • Ensure major platforms produce appropriate security telemetry and support enterprise detection and response capabilities.
  • Apply threat modeling and attack‑path analysis to major architecture decisions.
Will Collaborate with Key Stakeholders to Deliver M&A, Divestitures & Third-Party Integration
  • Define cybersecurity architecture patterns supporting acquisitions, divestitures, joint ventures, strategic partners, and third-party connectivity.
  • Establish secure approaches for tenant‑to‑tenant, network, identity, application, data, cloud, and SaaS integration.
  • Define transitional security architectures that reduce risk while enabling rapid business integration.
  • Identify technical‑security debt introduced through acquisitions and establish target‑state remediation strategies.
Architecture-to-Engineering Execution
  • The Principal Architect - Cybersecurity is accountable not
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Principal Architect, Security Architecture
Principal Architect, Security Architecture

Cencora • Minnesota

On-site
USD 180,000 - 240,000
Security Architect
Security Architect

CaptionCall, LLC • Salt Lake City (UT)

On-site
USD 140,000 - 210,000
Security Architect
Security Architect

Sorenson Communications, LLC • Salt Lake City (UT)

On-site
USD 170,000 - 230,000
Cybersecurity Architect
Cybersecurity Architect

Finezi Inc. • Rosemead (CA)

On-site
USD 130,000 - 160,000
Manager, Cyber Architecture
Manager, Cyber Architecture

Recru • Houston (TX)

On-site
USD 130,000 - 160,000
Cybersecurity Lead Engineer /Architect
Cybersecurity Lead Engineer /Architect

Objective Partners • Chicago (IL)

On-site
USD 180,000 - 260,000
Lead Cyber Security Architect
Lead Cyber Security Architect

PRI Technology • Seattle (WA)

On-site
USD 150,000 - 190,000
Enterprise Cybersecurity Architect
Enterprise Cybersecurity Architect

Southern-Glazer-S-Wine- • Dallas (TX)

On-site
USD 150,000 - 210,000
Medical and prescription coverage
Dental and vision plans
401(k) plan
+3
Cybersecurity Architect
Cybersecurity Architect

HealthPartners • BLOOMINGTON (MN)

Remote
USD 92,000 - 139,000
Cybersecurity Architect
Cybersecurity Architect

Talentify • BLOOMINGTON (MN)

Remote
USD 94,000 - 139,000