Principal Architect, Technology – Enterprise Security

Ziply Fiber

Kirkland (WA)

On-site

USD 170,000 - 250,000

Full time

8 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical
Dental
Vision
401k
FSAs
Paid sick leave
Paid time off
Parental leave
Quarterly bonus
Training
Education reimbursement

Job summary

Ziply Fiber is seeking a Principal Architect, Technology – Enterprise Security to define and advance the enterprise security architecture protecting corporate systems, employee infrastructure, and the network for 1M+ subscribers. You will own Zero Trust strategy, IAM/PAM design, and cloud security across multiple environments.

The role requires deep hands-on experience in security architecture within telecom or critical infrastructure, translating business risk into technical design and

Qualifications

  • 10+ years of progressive experience across security architecture, information security engineering, network security, cloud security, or related fields.
  • Experience defining enterprise architecture standards and influencing cross-functional decisions.
  • Familiarity with broadband/telecommunications or critical infrastructure environments.

Responsibilities

  • Define Ziply's enterprise security architecture and Zero Trust roadmap.
  • Architect firewall/perimeter strategy and IAM design across corporate and network environments.
  • Define SIEM/SOC tooling, ETL, and detection-rule governance aligned to MITRE ATT&CK.
  • Lead cloud security architecture across AWS/Azure/GCP and secure SDLC practices.
  • Collaborate with GRC to translate regulatory requirements into architecture controls.

Skills

Zero Trust Architecture
IAM & PAM
Cloud Security
SIEM/SOC Architecture
Network Security
Threat Detection
Security Operations

Education

Bachelor's degree in Cybersecurity/IT/CS

Job description

Principal Architect, Technology – Enterprise Security

Full time | Ziply Fiber | Remote Job


Posted On 08/28/2026


Job Information

Department Name Technology


Telecommunications


Job Description

This is a remote position.


Position Title: Principal Architect, Technology – Enterprise Security


Benefits: Medical, dental, vision, 401k, flexible spending account, paid sick leave and paid time off, parental leave, quarterly performance bonus, training, career growth and education reimbursement programs.


Ziply Fiber is a local internet service provider dedicated toelevating the connected livesof the communities we serve. We offer the fastest home internet in the nation, arefreshingly great customer experience,andaffordableplans that putcustomersin charge.


As ourstate-of-the-artfiber network expands, so does our need for team members who can help us grow and realize our goals.


OurCompany Values:



  • Genuinely Caring: We treat customers and colleagues like neighbors, with empathy and full attention.

  • Empowering You: We help customers choose whatisbest for them,andwesupport employeesin implementingnew ideasand solutions.

  • Innovation and Improvement: We constantly seek ways to improve how we serve customers and each other.

  • Earning Your Trust: We build trust through clear, honest,human communication.


Job Summary


The Principal Architect, Technology - Enterprise Security is a senior individual contributor responsible for defining and advancing the enterprise security architecture and technical standards that protect Ziply Fiber's corporate systems, employee infrastructure, and business applications, as well as the network we operate on behalf of 1M+ broadband subscribers.


This role provides architecture-level direction across corporate and network environments — including Zero Trust strategy, threat detection and response architecture, cloud and application security, and identity and access management design. Operation of the security tooling and Security Operations Center (SOC) sits with the Security Operations function, and control governance and approval sit with Governance, Risk & Compliance (GRC). This separation of duties is deliberate and keeps architecture and design distinct from the operation and assessment of controls.


The successful candidate brings deep, hands-on security architecture expertise in a broadband ISP, telecommunications, or critical-infrastructure environment, and the demonstrated ability to translate business risk into technical design and to communicate security architecture to both engineering teams and executive stakeholders.


Essential Duties and Responsibilities:

The Essential Duties and Responsibilities listed below are a range of duties performed by the employee and not intended to reflect all duties performed.


Security Architecture & Zero Trust


  • Define and own Ziply's enterprise security architecture: network segmentation, Zero Trust Network Access (ZTNA) strategy, micro-segmentation, and identity-based access-control design across corporate and network environments.

  • Establish the Zero Trust reference architecture and multi-year roadmap, including policy-decision and policy-enforcement point design, device-posture and conditional-access standards, and the phased migration from perimeter-based to identity-centric access.

  • Architect firewall and perimeter strategy: next-generation firewall platform selection (Palo Alto, Fortinet, or equivalent), zone and trust-boundary design, rule-governance and change standards, and policy-lifecycle design.

  • Define identity and access management (IAM) architecture: MFA enforcement standards, privileged access management (PAM) design, SSO and federation patterns (SAML/OIDC), directory and service-account governance, and joiner/mover/leaver control design.

  • Design secure remote-access architecture: ZTNA/SASE platform strategy, VPN-replacement roadmap, split-tunnel and posture-check standards, and endpoint-security integration.

  • Establish and maintain reference architectures, design patterns, and security standards that engineering and operations teams build to, evolving them as threats and technologies change.


Network Security Architecture


  • Define network security architecture for Ziply's infrastructure: out-of-band (OOB) management network design, jump-host and bastion architecture, and network-device access-control standards (TACACS+/RADIUS, role-based device access).

  • Define enterprise DDoS-protection architecture, including coordination with the Subscriber Edge DDoS/Arbor program and definition of enterprise-facing scrubbing, remotely triggered black-hole (RTBH), and mitigation capabilities.

  • Architect DNS security: RPZ (Response Policy Zones), DNSSEC, and DNS-over-HTTPS/TLS strategy for internal and subscriber-facing resolvers, and secure DNS/DHCP/IPAM design.

  • Define network monitoring and anomaly-detection architecture: NetFlow/IPFIX analysis for security use cases, IDS/IPS placement and tuning standards, TLS-inspection strategy, and integration with the SIEM.

  • Establish system-hardening baselines for network and infrastructure devices (e.g., CIS Controls, DISA STIGs, USGCB) and define secure-configuration standards for routers, switches, and firewalls.

  • Define segmentation and trust-zone architecture separating corporate, subscriber, management/OT, and lab environments.


Security Operations & Threat Detection Architecture


  • Define SIEM architecture in partnership with Security Operations: platform strategy or optimization, log-source onboarding standards, data-retention and normalization design, and correlation and detection-rule governance standards.

  • Define detection-engineering standards, including use-case development mapped to MITRE ATT&CK, alert-tuning and false-positive-reduction practices, and detection-coverage measurement.

  • Define SOC tooling architecture: SOAR platform strategy, playbook-automation standards, case-management and ticketing integration, threat-intelligence integration, and escalation-workflow design.

  • Define endpoint detection and response (EDR/XDR) architecture: platform strategy, deployment and policy standards, and integration with SIEM and SOC workflows.

  • Define vulnerability-management architecture: authenticated and unauthenticated scanning cadence, risk-based prioritization, remediation-SLA standards, and integration with change management and asset inventory.

  • Define the architecture supporting incident response, digital forensics, and log and evidence preservation, ensuring detection and telemetry coverage across corporate and network environments.


Cloud & Application Security Architecture


  • Define cloud security architecture and control standards across Ziply Fiber’s cloud environments, including AWS, Azure, Google Cloud, or equivalent platforms, with emphasis on cloud-native security tooling, CSPM, secure landing-zone design, account/subscription governance, and network-topology standards.

  • Define cloud identity and workload-protection architecture: least-privilege IAM, workload identity, key and secrets management (KMS/Key Vault), and CWPP, container, and Kubernetes security standards.

  • Define application-security architecture standards: API security and gateway design, secrets management, certificate-lifecycle and PKI management, and secure software development lifecycle (SDLC) integration (SAST/DAST/SCA and threat modeling).

  • Architect data-protection controls: data classification, encryption at rest and in transit standards, key management, tokenization and masking, and DLP architecture for sensitive subscriber and business data.

  • Define infrastructure-as-code and CI/CD security standards, including policy-as-code guardrails and pre-deployment security validation.


Governance, Risk & Compliance Partnership


  • Partner with GRC to translate regulatory and compliance requirements — CPNI, CALEA, FCC telecommunications security obligations, and applicable state-level requirements — into security-architecture control designs.

  • Ensure architecture designs are documentable, auditable, and mapped to Ziply's compliance framework and to industry frameworks such as NIST CSF, ISO 27001, and CIS benchmarks.

  • Define secure-by-design and architecture-review standards, including reference patterns and control requirements that projects must satisfy at design and review gates.

  • Contribute security-architecture review input to the deployment-governance process owned by GRC, ensuring new network and system deployments meet architecture standards before production deployment.

  • Maintain segregation of duties: design controls and standards without operating, grading, or approving them — operation sits with Security Operations and governance and approval sit with GRC.


AI & Emerging Technology Security Architecture


  • Define the security architecture supporting the secure and responsible adoption of artificial intelligence and machine learning across the organization, in partnership with the enterprise AI governance program.

  • Design controls addressing AI-specific risks — model integrity, training-data protection, and defenses against prompt injection, model evasion, and data-poisoning attacks — aligned to frameworks such as NIST AI RMF and ISO/IEC 42001.

  • Define architecture for the secure use of generative AI and AI-enabled security tooling, including data-handling, logging, and egress controls.

  • Evaluate emerging technologies — such as post-quantum cryptography readiness and IoT/OT convergence — and define forward-looking architecture standards to address them.


Other Duties


  • Must be available to work regular business hours Pacific Standard Time.

  • Must also be available to work on-call, evenings and weekends as needed.

  • Performs other duties as required to support the business and evolving organization .


Required Qualifications:


  • High school diploma or GED.

  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a closely related field. Equivalent professional experience may be considered.

  • 10+ years of progressive experience across security architecture, information security engineering, network security, cloud security, identity security, application security, or related technical fields, including substantial experience defining enterprise architecture standards and influencing complex cross-functional technical decisions.

  • Demonstrated senior independent contributor experience mentoring technical professionals, establishing architecture standards, and driving alignment across Security, Network Engineering, IT, Cloud, Application, and GRC stakeholders without direct people-management responsibility.

  • Experience in, or supporting, broadband, telecommunications, critical infrastructure, utilities, cloud, large-scale enterprise technology, or another highly regulated and network-intensive environment.

  • Deep expertise in enterprise or network security architecture, including firewall and segmentation strategy, Zero Trust design, identity-based access controls, and security controls for complex or highly available network environments.

  • Strong security-operations architecture experience, including SIEM/logging architecture, detection coverage, SOAR or workflow integration, telemetry onboarding, and SOC process integration; direct day-to-day SOC operations experience is not required.

  • Hands-on experience with IAM and PAM platforms: MFA, SSO, privileged access governance, and service-account management at enterprise scale.

  • Cloud security architecture experience in at least one major cloud platform such as AWS, Azure, or Google Cloud, with working knowledge of multi-cloud security patterns, CSPM, identity, workload protection, and secure landing-zone design.

  • Experience designing to and implementing security frameworks such as NIST CSF, ISO 27001, or CIS benchmarks.

  • Familiarity with telecommunications or critical-infrastructure security obligations, such as CPNI, CALEA, FCC requirements, or comparable regulatory and compliance frameworks; ability to translate requirements into technical architecture controls.


Preferred Qualifications:


  • CISSP, CISM, or comparable cybersecurity certifications.

  • Experience with SASE/SSE platforms: Zscaler, Palo Alto Prisma, or equivalent.

  • Background in subscriber-facing security: DNS security, RPKI/ROA, and network-level abuse management for broadband operators.

  • Familiarity with OT/ICS security in the context of critical network infrastru

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Architect
Security Architect

Digital-Global-Connectors • McLean (VA)

Hybrid
USD 130,000 - 180,000
Zscaler Integration Engineer - Mid
Zscaler Integration Engineer - Mid

Socket.dev • Washington

Hybrid
USD 110,000 - 160,000
Health insurance
401(k) with company matching
Flex spending accounts
+2
Cybersecurity Architect
Cybersecurity Architect

OneMain Financial • Washington

On-site
USD 140,000 - 200,000
Senior Architect
Senior Architect

Jobtailor • Arizona

On-site
USD 140,000 - 190,000
Principal Security Architect
Principal Security Architect

Berkley Technology Services • Irving (TX)

On-site
USD 170,000 - 230,000
Information Security Architect – Data Engineering, Security
Information Security Architect – Data Engineering, Security

Jobtailor • Alabama

On-site
USD 110,000 - 170,000
Principal Security Architect
Principal Security Architect

Berkley Technology Services • Wilmington (DE)

On-site
USD 150,000 - 210,000
SECURITY ARCHITECTURE & ENGINEERING SME
SECURITY ARCHITECTURE & ENGINEERING SME

Hiring Our Heroes • Arlington (VA)

Hybrid
USD 120,000 - 160,000
Flexible work environment
Opportunities for professional development
Senior Architect
Senior Architect

Bank of America • Chandler (AZ)

On-site
USD 150,000 - 210,000
Senior Network Security Engineer
Senior Network Security Engineer

Ignite IT, LLC • Suitland (MD)

On-site
USD 100,000 - 130,000
Health insurance
Flexible schedule
401(k) matching
+2