Principal Security Architect

Posted 8hrs ago

Employment Information

Education
Salary
Experience
Job Type

Report this job

Job expired or something wrong with this job?

Job Description

Principal Security Architect owning cloud and application security for Lilly’s AWS-heavy strategic programs. Protecting trade secrets through architecture reviews, threat modeling, and risk governance.

Responsibilities:

  • Own the security architecture and risk posture for an assigned strategic program spanning cloud platforms, data flows, identity, and third-party integrations
  • Conduct architecture and design reviews, threat modeling, and risk assessments
  • Design and review controls for workloads handling trade secrets and highly sensitive intellectual property
  • Establish secure cloud architecture patterns across platforms in scope
  • Apply threat modeling frameworks and recognized industry security standards, frameworks, and best practices
  • Perform threat analysis and modeling throughout the secure development and operations lifecycle
  • Drive risk acceptance where residual risk cannot be eliminated, secure approvals, and document outcomes
  • Develop reference architectures, design patterns, and security guidance from recurring requirements
  • Partner across Security Architecture & Engineering and collaborate with program leadership, engineering, privacy, legal, audit, and other partners
  • Provide technical direction, leadership, and mentorship to architects and engineers

Requirements:

  • High School Diploma/equivalent with 4+ years of experience in Cyber Security, Information Technology, or a related field
  • 8+ years of professional experience across security, software engineering, cloud engineering, or a combination, including hands-on cloud security work
  • Qualified applicants must be authorized to work in the United States on a full-time basis
  • Deep security expertise across cloud, application security, identity, and integration patterns
  • Depth in at least one major cloud platform (AWS, Azure, or GCP), including identity and access management, network architecture, workload protection, encryption and key management, and cloud security posture management
  • Experience applying cloud security expertise across additional cloud providers
  • Demonstrated experience securing workloads handling trade secrets or highly sensitive intellectual property, including segmentation, access boundaries, and egress controls
  • Strong understanding of secure application development and the secure software development lifecycle
  • Strong experience in threat analysis and modeling
  • Solid understanding of cybersecurity engineering and operations
  • Exceptional critical thinking and analytical reasoning
  • Ability to define and influence security strategy while guiding tactical work
  • Ability to translate technical risk into clear business language and document risk decisions for audit and executive review
  • Excellent communication and presentation skills for technical and non-technical audiences
  • Experience developing and documenting architecture references, security guidelines, and standards
  • Experience mentoring more junior architects and engineers

Benefits:

  • Company bonus, depending in part on company and individual performance
  • Company-sponsored 401(k)
  • Pension
  • Vacation benefits
  • Medical, dental, vision, and prescription drug benefits
  • Flexible benefits, including healthcare and/or dependent day care flexible spending accounts
  • Life insurance and death benefits
  • Certain time off and leave of absence benefits
  • Well-being benefits, including employee assistance program, fitness benefits, and employee clubs and activities
  • Employee resource groups open to all employees