2

Remote Principal Security Architect Jobs (NOW HIRING)

Overview Overview The Information Security Architect will play a pivotal role in designing ... Remote, US Type of Employment: Full-time, permanent FLSA Classification (USA Only): Exempt Work ...

OverviewOverview The Information Security Architect will play a pivotal role in designing ... Remote, US Type of Employment: Full-time, permanent FLSA Classification (USA Only): Exempt Work ...

Lead architecture governance reviews and ensure alignment of technology solutions with enterprise objectives. * Evaluate emerging technologies and establish adoption strategies that balance ...

Description The Principal Security & IAM Architect is responsible for designing and supporting the implementation of the security and identity architecture of the MyCDW platform -- CDW Managed ...

The Principal Security & IAM Architect is responsible for designing and supporting the implementation of the security and identity architecture of the MyCDW platform - CDW Managed Services' unified ...

The Principal Security & IAM Architect is responsible for designing and supporting the implementation of the security and identity architecture of the MyCDW platform - CDW Managed Services' unified ...

This role leads the research, architecture, design, implementation, integration, and ongoing ... remote administration, and system lifecycle processes. • Evaluate, deploy, integrate, and operate ...

This role leads the research, architecture, design, implementation, integration, and ongoing ... remote administration, and system lifecycle processes. • Evaluate, deploy, integrate, and operate ...

Block is a company focused on economic empowerment, and they are seeking a Principal Security ... guiding architectural decisions and ensuring alignment with engineering best practices. • ...

Identify security market inflection points (OT/ICS cybersecurity, convergence, secure remote access ... architecture at the strategic level, maturity models, and positioning guidance. Knowledge ...

The Role The Principal Software Security Architect owns security architecture for BeyondTrust's product suite end to end, including endpoint agents, thick clients, SaaS platforms, APIs, identity ...

The Role The Principal Software Security Architect owns security architecture for BeyondTrust's product suite end to end, including endpoint agents, thick clients, SaaS platforms, APIs, identity ...

Serve as a principal-level architect, thought leader, and trusted advisor who shapes secure cloud ... Remote (USA) - with potential occasional travel to client sites. Join 3Cloud's Azure and Security ...

Serve as a principal-level architect, thought leader, and trusted advisor who shapes secure cloud ... Remote (USA) - with potential occasional travel to client sites. Join 3Cloud's Azure and Security ...

This role leads the research, architecture, design, implementation, integration, and ongoing ... remote administration, and system lifecycle processes. Evaluate, deploy, integrate, and operate ...

This role leads the research, architecture, design, implementation, integration, and ongoing ... remote administration, and system lifecycle processes. Evaluate, deploy, integrate, and operate ...

next page

Showing results 1-20

Remote Principal Security Architect information

See salary details

$92.5K

$155.9K

$211K

How much do remote principal security architect jobs pay per year?

As of Aug 25, 2026, the average yearly pay for remote principal security architect in the United States is $155,946.00, according to ZipRecruiter salary data. Most workers in this role earn between $130,000.00 and $180,000.00 per year, depending on experience, location, and employer.

What does a remote principal security architect do?

A Remote Principal Security Architect is responsible for designing, implementing, and maintaining an organization's overall security architecture, all while working remotely. They lead efforts to protect systems and data from cybersecurity threats by establishing security standards, policies, and best practices. This role often involves evaluating new technologies, assessing current security measures, and collaborating with other IT professionals to ensure comprehensive security coverage across all platforms. The 'principal' designation indicates a senior-level position with significant influence over security strategy and decision-making.

What are the key skills and qualifications needed to thrive as a remote principal security architect?

To thrive as a Remote Principal Security Architect, you need deep expertise in cybersecurity frameworks, risk assessment, and enterprise security architecture, typically backed by a degree in computer science or related fields and extensive industry experience. Familiarity with tools like SIEM platforms, cloud security solutions, and certifications such as CISSP, CISM, or AWS Certified Security Specialty are commonly required. Exceptional problem-solving, leadership, and communication skills set top candidates apart, especially when leading distributed teams and aligning security strategies with business goals. These skills ensure robust protection of digital assets, regulatory compliance, and effective collaboration in a remote work environment.

How does a remote principal security architect typically collaborate with cross-functional teams to drive security initiatives?

As a Remote Principal Security Architect, you will regularly work with engineering, product, and IT teams to embed security best practices throughout the development lifecycle. Collaboration often involves leading architecture reviews, advising on secure system design, and developing security guidelines or frameworks. Communication is primarily virtual, utilizing video conferencing, chat, and project management tools to ensure alignment across geographically dispersed teams. Building strong relationships and clearly articulating security concepts are key to influencing decisions and fostering a security-first culture.

What is the difference between Remote Principal Security Architect vs Remote Security Engineer?

AspectRemote Principal Security ArchitectRemote Security Engineer
Required CredentialsCertifications like CISSP, CISA, or CISM; extensive experience in security architectureCertifications like CompTIA Security+, CISSP; focus on technical security skills
Work EnvironmentStrategic planning, security design, policy developmentImplementation, monitoring, and technical security solutions
Employer & Industry UsageUsed in large enterprises, consulting firms, and tech companiesCommon in IT departments, security teams, and tech firms

The Remote Principal Security Architect focuses on designing and overseeing security strategies at a high level, requiring advanced certifications and experience. In contrast, the Remote Security Engineer handles technical security implementation and maintenance. Both roles are vital but differ in scope and responsibilities.

How much does a remote principal security architect get paid?

A remote principal security architect typically earns between $130,000 and $180,000 annually, depending on experience, certifications, and the industry. Senior roles often include bonuses and benefits, and strong expertise in cybersecurity frameworks and cloud security can influence compensation.

How much does a remote principal security architect make?

A remote principal security architect typically earns between $130,000 and $180,000 annually, depending on experience, certifications, and the industry. Senior roles may also include bonuses and benefits, with some earning over $200,000 in high-demand sectors.
More about Remote Principal Security Architect jobs

What cities are hiring for Remote Principal Security Architect jobs?

Cities with the most Remote Principal Security Architect job openings:

What states have the most Remote Principal Security Architect jobs?

States with the most job openings for Remote Principal Security Architect jobs include:

What job categories do people searching Remote Principal Security Architect jobs look for?

The top searched job categories for Remote Principal Security Architect jobs are:

Infographic showing various Remote Principal Security Architect job openings in the United States as of August 2026, with employment types broken down into 88% Full Time, 10% Part Time, and 2% Contract. Highlights an 93% Physical, 2% Hybrid, and 5% Remote job distribution, with an average salary of $155,946 per year, or $75 per hour.

Full-time

Posted 15 days ago


Brown University Health rating

6.7

Company rating: 6.7 out of 10

Based on 95 frontline employees who took The Breakroom Quiz

498th of 893 rated healthcare providers


Job description

SUMMARY:
The Principal Security Architect is a key member of the CISO organization responsible for establishing and governing secure technology architecture across hybrid on-premises and multi-cloud environments. This role serves as a trusted subject matter expert partnering with infrastructure, application, data, and cloud platform teams to translate security strategy, regulatory expectations, and industry best practices into practical reference architectures, security standards, and design requirements. The Principal Security Architect leads architecture review and assurance activities to ensure solutions are implemented in alignment with approved designs and enterprise standards, and drives remediation of identified security and control gaps across identity, network segmentation, data protection, monitoring, CI/CD, and third-party integrations.
Owns enterprise security reference architectures, design standards, and security patterns across the organization. Has authority to approve, require modification of, or reject proposed designs that do not meet established security requirements, and ensures deviations are formally governed through the enterprise exception management process.
RESPONSIBILITIES:
Engage in project intake and early design phases to define security requirements prior to implementation. Partner with infrastructure, application, and cloud teams to embed security-by-design into initial architecture decisions and reduce downstream rework and exception volume.
Serve as a subject matter expert for the evaluation, design, and secure adoption of infrastructure, cloud platforms, applications, and enterprise technologies, ensuring security requirements are incorporated throughout the solution lifecycle.
Lead security architecture review and assurance activities by assessing proposed and existing designs, network and application architecture diagrams, and technology implementations against enterprise standards, reference architectures, threat models, and control requirements; defining security requirements and guardrails; and validating implemented solutions align with approved designs and enterprise standards.
Identify and drive remediation of security and control gaps across identity, network segmentation, data protection, logging/monitoring, key management, CI/CD, and third-party integrations in partnership with Infrastructure, Application, Data, and Cloud Platform teams.
Design security architecture for Microsoft Fabric and lakehouse patterns (Bronze/Silver/Gold), including secure data ingestion pipelines (e.g., Data Factory), least-privilege access using service principals and managed identities, strong data governance controls such as classification, labeling, lineage, and policy enforcement via Microsoft Purview, and secure storage and access boundaries through encryption and customer-managed keys (where applicable). Define secure ingestion and connectivity patterns for on-premises systems (e.g., EMR/Epic, relational databases) and third-party platforms (e.g., Snowflake), including segmentation, traceability, and segregation of duties between data engineering and data consumers.
Define and enforce security architecture for AI platforms and agent-based solutions (e.g., Copilot Studio, Azure AI services), including identity and access controls for service principals and managed identities, least-privilege connector design, data protection and prompt handling safeguards, logging and traceability of agent actions, and integration with enterprise data governance controls (e.g., Microsoft Purview).
Assess and integrate acquired entities into the enterprise security architecture by evaluating inherited environments, identifying control gaps, and defining transition architectures that align to enterprise standards while accounting for operational constraints.
Define and maintain Microsoft Entra ID security architecture standards, including Conditional Access, phishing-resistant MFA, PIM, RBAC design, privileged access workflows, and application identity governance.
Define secure network architecture patterns including segmentation, private networking, egress controls, firewall policy, and DNS security considerations across on-premises and cloud environments.
Define enterprise logging, telemetry, and monitoring architecture requirements, including SIEM integration, retention standards, and visibility requirements across on-premises, cloud, research, and AI environments.
Own and maintain enterprise security configuration standards and baselines across endpoints, infrastructure, cloud platforms (Azure and AWS), identity services, AI/agent platforms, and controlled environments including research and AI enclaves. This includes Windows, Linux and macOS systems, network devices, cloud-native services, Microsoft Entra ID, and AI agent frameworks. Ensure alignment with CIS Benchmarks and internal policy requirements and validate adoption through architecture governance and coordination with engineering and control validation teams, with particular focus on protecting sensitive data within research and AI workloads.
Perform detailed security risk assessments across infrastructure, endpoints, identity, networks, applications, and data platforms; translate findings into actionable risk narratives, compensating controls, and prioritized roadmaps.
Evaluate new technologies and platforms for architectural fit, integration requirements, and risk implications, providing recommendations aligned to enterprise security strategy and standards.
Provide architectural guidance during major incidents and support post-incident reviews to identify control gaps and improve future-state design.
Attend and actively contribute to team, project, project management, problem management, cloud migration and major incident conference calls as required.
Participate in compliance and audit activities in support of internal and external audit requirements.
Maintains work effort status within SLA's on Brown University Health's Service Desk and Task Management Platforms.
Performs other duties as assigned.
EXPERIENCE:
A minimum of 10 years of IS/IT experience, including 5+ years in information security architecture, engineering, or related senior technical security roles.
A bachelor's degree in information systems (or equivalent experience); MBA or MS in Information Security preferred.
A minimum of 3 active security certifications are required at the time of hire or must be obtained within 6 months of employment, with emphasis on architecture, cloud, and security engineering disciplines, including certifications such as CISSP, CCSP, GIAC (e.g., GCSA, GCLD, GCAD, GCPN, GPCS, GCTD), ISSAP, CKS, CCAK, OSCP/OSCE, or equivalent.
Demonstrated ability to operate as a senior technical leader across multiple security domains, balancing enterprise architecture, cloud security, identity security, AI governance, and data protection requirements.
Demonstrated experience designing and governing security architecture for hybrid (on-premises and cloud) and multi-cloud environments, including segmentation, secure connectivity (VPN, ExpressRoute, Direct Connect equivalents), DNS/routing, egress controls, and cloud governance models (landing zones, guardrails, subscription/account strategy).
Demonstrated experience securing Azure and AWS environments across multiple subscriptions/accounts, including identity, networking, storage, monitoring, and secure landing zone architecture.
Strong technical knowledge of security methodologies, platform hardening, and enterprise security controls across Windows/Linux systems, endpoints, cloud platforms, and enterprise infrastructure.
Strong knowledge of identity and access management, including federation and authentication protocols (SAML, OAuth2, OpenID Connect), Conditional Access, RBAC, privileged access management, and application identity governance.
Experience implementing and supporting phishing-resistant MFA (e.g., FIDO2/WebAuthn, smart cards, certificate-based authentication).
Strong knowledge of encryption and key management, including PKI concepts, secrets management, and KMS/Key Vault.
Experience with automation and integration concepts, including scripting (Python, PowerShell, Bash), cloud CLIs/SDKs, and API/webhook integrations supporting security workflows, telemetry, orchestration, and validation activities.
Experience integrating security controls and governance requirements into infrastructure-as-code (e.g., Terraform, Ansible) and CI/CD workflows.
Experience with SIEM and monitoring platforms supporting enterprise logging, telemetry, alerting, and security visibility requirements; familiarity with SOAR and automated response capabilities is preferred.
Knowledge of vulnerability management processes and tools (e.g., Qualys, Nessus, Rapid7), ensuring architecture and control design support effective risk-based prioritization and remediation governance.
Experience with CSPM/CWPP solutions to identify misconfigurations, vulnerabilities, and risks across multi-cloud environments.
Strong understanding of network security architecture, including segmentation, firewalls, routing, switching, DNS, private networking, and packet analysis concepts.
Strong understanding of regulatory requirements, security frameworks, and risk methodologies (e.g., HIPAA/HITECH, NIST, ISO 27001), including the ability to translate requirements into technical controls, governance standards, and audit evidence.
Proven ability to perform risk, control, vulnerability, and business impact assessments, and translate findings into actionable remediation plans.
Excellent interpersonal, verbal, and written communication skills with the ability to develop standards, architectural diagrams, technical documentation, and executive-level reporting, and communicate security decisions to both technical and non-technical stakeholders.
Motivated self-starter with a track record of taking ownership of security challenges and driving them to resolution.
INDEPENDENT ACTION:
Employee functions independently within department policies and practices; refers specific decisions to security management where authority is outside of the defined departmental RACI Matrix or clarification of departmental policies and procedures may be required.
SUPERVISORY RESPONSIBILITIES:
None
Pay Range:
$127,691.20-$210,724.80
EEO Statement:
Brown University Health is committed to providing equal employment opportunities and maintaining a work environment free from all forms of unlawful discrimination and harassment.
Location:
Remote-Rhode Island - N/A Providence, Rhode Island 02901
Work Type:
M-F 8:30am-5:00pm ET
Work Shift:
Day
Daily Hours:
8 hours
Driving Required:
No

What Brown University Health employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom