Principal, Cloud Security Architect

LIO Insurance

Conshohocken (Montgomery County)

Hybrid

USD 180,000 - 240,000

Full time

3 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Health insurance
401(k) plan
Paid time off
Flexible work options

Job summary

The Principal Cloud Security Architect at LIO Insurance leads the design and implementation of secure AWS infrastructure, data protection, and AI workload security. This hands-on, IC role sets standards, guides engineering teams, and partners with the CISO and GRC teams to support regulatory examinations.

You will shape multi-year cloud security strategy, drive automation, and ensure resilient, cost-aware solutions across accounts and services, while mentoring engineers and documenting decisions.

Qualifications

  • Deep AWS architecture and engineering experience across networking, IAM, resilience, logging, and security.
  • Hands-on experience with infrastructure as code and automation (Terraform/CloudFormation/CDK) and scripting (Python/PowerShell/Bash).
  • Security engineering across identity, access control, monitoring, incident response, and vulnerability remediation.
  • Experience operating production services with defined service expectations and incident follow-through.

Responsibilities

  • Own AWS infrastructure architecture, including account structure, networking, identity, compute, storage, connectivity, and environment separation.
  • Establish reusable infrastructure patterns and guardrails with infrastructure as code, version control, and automated deployment checks.
  • Design for availability, recovery, performance, and cost; make practical tradeoffs based on workload and business needs.
  • Partner with Enterprise Architecture on standards and design reviews, translating requirements into secure cloud infrastructure.

Skills

AWS architecture
Infrastructure as code
Security engineering
Identity and access
Cloud security governance

Education

Bachelor's degree in CS/IT or related field

Tools

Terraform
CloudFormation
CDK
Python

Job description

Summary / Objective

The Principal Cloud Security Architect owns the architecture and technical safeguards behind LIO's AWS environment as our applications, integrations, and AI capabilities grow. This is a hands‑on individual contributor role, not a people‑management role: the incumbent designs, builds, and secures cloud infrastructure directly, sets standards adopted across teams, and partners with the fractional CISO and GRC team to support security governance and regulatory examinations.

Summary / Objective

The Principal Cloud Security Architect owns the architecture and technical safeguards behind LIO's AWS environment as our applications, integrations, and AI capabilities grow. This is a hands‑on individual contributor role, not a people‑management role: the incumbent designs, builds, and secures cloud infrastructure directly, sets standards adopted across teams, and partners with the fractional CISO and GRC team to support security governance and regulatory examinations.

Essential Duties & Functions
  • Own AWS infrastructure architecture, including account structure, networking, identity, compute, storage, connectivity, and environment separation.
  • Establish reusable infrastructure patterns and guardrails with infrastructure as code, version control, and automated deployment checks.
  • Design for availability, recovery, performance, and cost; make practical tradeoffs based on workload and business needs.
  • Partner with Enterprise Architecture on standards and design reviews, translating application and integration requirements into secure, supportable cloud infrastructure.
  • Set technical requirements for cloud engineering providers, review their designs and implementation, and contribute hands‑on to critical changes and complex troubleshooting.
  • Define architecture and control standards for cloud services, endpoints, identity, and connectivity, partnering with IT Operations on implementation and supportability.
  • Design observability, escalation patterns, and technical runbooks; agree operational handoffs and coverage with the accountable service owners.
  • Design infrastructure backup and recovery capabilities; work with business and application owners to define recovery objectives and validate restoration with IT Operations and providers.
  • Improve operational performance through automation, capacity planning, root-cause analysis, and disciplined change management.
  • Evaluate infrastructure and security tooling, identify cloud cost improvements, and recommend lifecycle investments to the accountable budget owner.
  • Implement the technical controls supporting LIO's security program across AWS, identity platforms, Microsoft 365, endpoints, networks, and shared infrastructure.
  • Strengthen privileged access, authentication, segmentation, encryption, secrets management, logging, and data protection.
  • Define infrastructure vulnerability remediation patterns, implement complex fixes, and coordinate technical remediation with application and service owners using agreed priorities and deadlines.
  • Establish effective detection and response capabilities with internal teams and providers; lead technical containment and recovery during incidents.
  • Partner with engineering on secure deployment practices and with AI/data owners on workload identity, access boundaries, sensitive-data protection, and monitoring.
  • Produce operating evidence, support control assessments, and resolve findings in partnership with the CISO and GRC lead.
  • Mentor engineers and operational staff, document design decisions, and build reusable patterns that reduce dependence on individual experts.
  • Shape the multi-year cloud security architecture and technical roadmap; agree delivery priorities and capacity with the CTO/CIO, CISO, and functional leaders.
  • Translate technical issues into clear choices about risk, cost, service impact, and delivery timing.
  • Set technical acceptance criteria for providers, review implementation quality, and retain architecture knowledge and documentation within LIO.
  • Escalate unresolved risks, resource constraints, and control exceptions promptly through the agreed governance process.
  • Participate in special projects and other duties as assigned.
LIO LIFE — What We Value
  • The Customer Lens -- Prioritizing our relationships, service, and needs of our customers.
  • Innovative Thinking -- Fostering an environment that empowers and sustains bold thinking and actions.
  • Balance -- Creating an inclusive, diverse, and holistic balance to meet our personal and professional needs.
  • Simplicity -- Striving for simplicity in our service, products, and processes.
  • Accountability -- Owning our results and learning from them.
Qualifications
  • Deep, current AWS architecture and engineering experience, particularly networking, IAM, resilience, logging, and infrastructure security.
  • Demonstrated hands‑on ability with infrastructure as code and automation, using tools such as Terraform, CloudFormation, or CDK and a scripting language such as Python, PowerShell, or Bash.
  • Practical security engineering experience across identity, access control, vulnerability remediation, monitoring, and incident response.
  • Experience operating production services with defined service expectations, tested recovery procedures, and accountable incident follow-through.
  • Track record of setting architecture standards across teams, mentoring senior engineers, reviewing provider implementations, and influencing investment decisions without direct reporting authority.
  • Clear communication with engineers, business leaders, and risk/compliance partners, supported by useful technical documentation.
  • Ability to thrive in a virtual, global organization and effectively manage competing priorities.
Required Education And Experience
  • Bachelor's Degree in Computer Science, Information Technology, or a related field (or equivalent practical experience).
  • Typically 12 or more years of relevant cloud infrastructure, platform engineering, or security engineering experience, with sustained organization-wide architectural impact; level is based on demonstrated capability, not tenure alone.
  • Demonstrated track record of setting technical direction and influencing outcomes across teams without direct reporting authority.
Preferred Education And Experience
  • Experience in insurance, financial services, or another regulated environment.
  • Familiarity with Microsoft 365, Intune, Okta or Entra ID, and endpoint security platforms.
  • Experience with Datadog or comparable observability and security monitoring tools.
  • Experience integrating security checks into software delivery and securing AI or LLM workloads.
  • Familiarity with NIST CSF, control assessments, and evidence supporting regulatory examinations.
Additional Eligibility Requirements (Certificates, Licenses, Required/Preferred)
  • Relevant AWS, cloud security, or information security certifications preferred; demonstrated delivery experience is equally valued.
LIO Life — Our Benefits

LIO offers a comprehensive benefits package designed to support your health, financial security, and work-life balance. Benefits are effective on your date of hire.

Health & Wellness
  • Medical coverage with a choice of plan options, including preventive care and prescription drug coverage.
  • Dental, Vision, and Prescription coverage.
  • Health Savings Account (HSA) with employer contributions.
  • Flexible Spending Accounts (FSA) for healthcare and dependent care expenses.
Financial Protection
  • Employer-paid Basic Life & AD&D coverage.
  • Employer-paid Short-Term Disability coverage.
  • Employer-paid Long-Term Disability coverage.
  • Voluntary Life & AD&D coverage available for employees and their families.
  • 401(k) Retirement Savings plan.
Additional Perks
  • Flexible Time Off.
  • Employee Assistance Program (EAP) — confidential support for personal and work‑related challenges.
  • Voluntary Pet Insurance.
  • Career development with clear performance goals, coaching, and opportunities to lead initiatives.
  • Community involvement and volunteer opportunities supported by leadership.
Work Environment

This role operates in a remote/hybrid work environment with regular virtual collaboration across IT, security, and business teams. This role routinely uses standard office and computing equipment.

Position Type / Expected Hours of Work

This is a full‑time position. Expected days and hours of work are Monday through Friday, 8:30 a.m. to 5:00 p.m. This position may require extended hours, occasional weekend work, and off‑hours availability to support incident response based on business need.

Travel

Minimal travel required; occasional travel for team, vendor, or leadership meetings as needed.

EEO Statement

LIO Insurance provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, creed, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state, or local laws. This policy applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation, and training.

Other Duties

Please note this job description is not designed to cover or contain a comprehensive listing of activities, duties, or responsibilities that are required of the employee for this job. Duties, responsibilities, and activities may change at any time with or without notice.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

LIO Specialty, Underwriter - Construction
LIO Specialty, Underwriter - Construction

LIO Insurance • Conshohocken

On-site
USD 85,000 - 110,000
Medical coverage
Dental coverage
Vision coverage
+13
DevSecOps Cloud Automation Engineer - Clearance Required
DevSecOps Cloud Automation Engineer - Clearance Required

LMI Consulting, LLC • United States

On-site
USD 140,000 - 165,000
Remote DevSecOps Engineer: CI/CD & Cloud Security
Remote DevSecOps Engineer: CI/CD & Cloud Security

LMI Consulting, LLC • United States

On-site
USD 100,000 - 166,000
Remote Federal Security Lead - Cloud & DevSecOps
Remote Federal Security Lead - Cloud & DevSecOps

LMI Consulting, LLC • United States

On-site
USD 134,367 - 232,404
Principal Engineer, Solutions Architecture
Principal Engineer, Solutions Architecture

LMI Consulting, LLC • United States

On-site
USD 150,000 - 190,000
AWS Cloud Architect
AWS Cloud Architect

LTM • Houston (TX)

On-site
USD 130,000 - 210,000
Medical plan
Disability coverage
401(k) match
+3
Full Stack Developer
Full Stack Developer

LMI Government Consulting • Northern (KY)

Hybrid
USD 122,000 - 211,000
Senior Systems Administrator & CI/CD Lead
Senior Systems Administrator & CI/CD Lead

LufCo • Aberdeen (MD)

Hybrid
USD 120,000 - 180,000
Blue Award referral bonus
Health/dental/vision insurance
401K matching
+2
Remote Platform Engineer — AWS/Kubernetes, Secret Clearance
Remote Platform Engineer — AWS/Kubernetes, Secret Clearance

LMI Consulting, LLC • United States

On-site
USD 135,000 - 230,000
Security Risk Architect
Security Risk Architect

L.E.K. Consulting • Boston (MA)

Hybrid
USD 130,000 - 150,000