Principal Security Architect

Francisco Partners

United States

On-site

USD 130,000 - 165,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Francisco Partners is seeking a hands-on Security Architect to shape and execute our modern security vision across on-prem and cloud environments. You'll design, implement, and mature core security controls in AWS, Terraform, and CI/CD pipelines, while guiding remediation and threat-hunting efforts.

You’ll mentor engineers, collaborate with Platform Engineering and DevOps, and translate senior leadership goals into actionable plans, all while balancing security with engineering velocity.

Qualifications

  • 7+ years hands-on cybersecurity in senior roles (Senior/Lead Engineer or Architect).
  • Experience as Security Architect in growing engineering orgs.
  • Proven ability to operate in hybrid environments and deploy Terraform.
  • Strong knowledge of AWS native security services (GuardDuty, Security Hub, IAM, KMS).
  • Understanding enterprise networking, firewall management, and cloud migrations.
  • Ability to balance gold-standard security with operational constraints and risk.
  • Excellent communication and coaching skills.

Responsibilities

  • Designs, implements, and maintains security guardrails and architectures within AWS.
  • Writes, reviews, and enforces security controls directly within Terraform and CI/CD pipelines.
  • Assesses, refactors, and stabilizes baseline security operations across datacenter and cloud assets.
  • Matures core controls: Vulnerability Management, SIEM/Telemetry, Detection & Response.
  • Partners with Platform Engineering/DevOps to establish identity, access, and logging standards.
  • Serves as senior technical point for security incident escalation, threat hunting, and emergency response.
  • Establishes risk-based prioritization for vulnerabilities and remediation.
  • Translates CISO goals into practical execution plans.
  • Mentors engineers on secure design patterns and cloud best practices.

Skills

Security architecture
Cloud security
SIEM
Threat hunting
Incident response
DevOps collaboration
Security governance

Education

Bachelor's degree in Cybersecurity/CS/IT

Tools

Terraform
GuardDuty
Security Hub
IAM
KMS

Job description

Job Summary/Objective

Serves as a hands-on Security Architect to help shape and execute the company’s modern security vision. Designs, builds, and matures core security controls across both infrastructures. Solves complex technical challenges, brings order to distributed controls, and delivers steady, incremental security improvements without stalling engineering velocity.

Key Responsibilities & Duties (essential to the job)
  • Designs, implements, and maintains security guardrails and architectures within AWS.
  • Writes, reviews, and enforces security controls directly within Terraform and CI/CD pipelines to ensure "security-as-code" across modern deployments.
  • Assesses, refactors, and stabilizes baseline security operations across legacy datacenter assets and modern cloud workloads.
  • Matures core foundational controls, including Vulnerability Management, SIEM/Telemetry aggregation, and Detection & Response capabilities.
  • Partners with Platform Engineering and DevOps teams to establish consistent, scalable identity, access, and logging standards.
  • Serves as the senior technical point of contact for security incident escalation, threat hunting, and emergency response.
  • Establishes realistic risk-based prioritization for vulnerabilities and remediation across heterogeneous environments.
  • Translates high-level strategic goals from the CISO into practical, achievable technical execution plans.
  • Mentors software engineers and systems administrators on modern secure design patterns and cloud best practices.
Education

A bachelor’s degree from an accredited college or university is required, with a focus in Cybersecurity, Computer Science, Information Technology, or related discipline. In the absence of a degree, equivalent work experience directly related to the key responsibilities of the role will be considered as a substitute for the degree.

Experience, Skills and Key Competencies
  • At least 7 years of experience in hand-on cybersecurity, with significant experience operating as a Senior/Lead Security Engineer or Security Architect in growing engineering organizations, demonstrated experience navigating hybrid environments, and deep practical experience writing and deploying Terraform.
  • Must also be able to demonstrate the following knowledge, skills and abilities: Strong working knowledge of native AWS security services (GuardDuty, Security Hub, IAM, KMS, Org-level controls).
  • Understanding of traditional enterprise networking, firewall management, server administration, and the practical realities of cloud migrations.
  • Versatile, generalist knowledge across Security Operations (SecOps), SIEM architecture, Detection & Response, and Vulnerability Management life cycles.
  • Excellent judgment in balancing "gold-standard" security architecture against real-world operational constraints and incremental business risk.
  • Ability to build strong relationships with DevOps, IT, and software development teams through collaborative problem-solving rather than rigid auditing.
  • Flexible and adaptable approach to work, and can easily adjust to shifts in priorities as the needs of the business change.
  • Able to effectively work and thrive in a remote work environment that has limited opportunities for in-person interactions.
  • Excellent communication skills and can tailor messaging to a specific audience/situation.
  • Comfortable providing coaching, guidance and feedback to peers.
Special Position Requirements
  • Willing and able to attend virtual meetings with the laptop camera on.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity Engineer
Cybersecurity Engineer

OneImaging • Bellevue (WA)

On-site
USD 100,000 - 130,000
Health Care Plan
Retirement Plan
Paid Time Off
+2
Systems Architect
Systems Architect

Compunnel, Inc. • Irving (TX)

On-site
USD 140,000 - 190,000
AWS Solution architect
AWS Solution architect

Russell Tobin • Alpharetta (GA)

On-site
USD 120,000 - 150,000
Comprehensive healthcare coverage
401(k)-retirement savings
Life & disability insurance
Senior Technical Lead/ Security Architect
Senior Technical Lead/ Security Architect

TechDigital Group • Frisco (TX)

On-site
USD 120,000 - 180,000
AWS Cloud Security Engineer
AWS Cloud Security Engineer

Insight Global • Reston (VA)

On-site
USD 140,000 - 200,000
Technical Analyst
Technical Analyst

Synergy Business Consulting, Inc. • Town of Florida (NY)

On-site
USD 120,000 - 190,000
Sr. Security Engineer
Sr. Security Engineer

California Water Service • San Jose (CA)

On-site
USD 180,000 - 240,000
Information Security Architect
Information Security Architect

Compunnel, Inc. • San Francisco (CA)

On-site
USD 140,000 - 180,000
Cloud Security Architect
Cloud Security Architect

TechDigital Group • Philadelphia

On-site
USD 130,000 - 160,000
Security Architect (Cloud)
Security Architect (Cloud)

SS&C Technologies • Windsor (CT)

Hybrid
GBP 90,000 - 130,000
Hybrid Work Model
Professional Development Reimbursement
Competitive holiday scheme
+1