> Markdown version of [/jobs/ext/173416-principal-architect-product-security](https://www.wearedevelopers.com/jobs/ext/173416-principal-architect-product-security). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Principal Architect, Product Security - **Company:** Infoblox - **Location:** Tacoma, WA, United States - **Salary:** $195,000.0 - $300,300.0 - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Amazon Web Services, Microsoft Azure, Bash Shell, C++ (Programming Language), Software as a Service, Control Objectives for Information and Related Technology (COBIT), Cyber Security, Continuous Integration, Dynamic Host Configuration Protocol, Software Design Patterns, Domain Name System (DNS), Firmware, Information Systems Security Architecture Professional, Python (Programming Language), Lua (Scripting Language), OAuth, OpenID, Role-Based Access Control, Zero Trust Network Access, Secure Coding, Security Information and Event Management, Systems Integration, Rust (Programming Language), Policy as Code, Pulumi, Google Cloud, Cloud Platform System, Istio, System Availability, Software Security, Multi-Cloud, Amazon Virtual Private Cloud (VPC), Cloudformation, Kustomize Configuration Management, Kubernetes, Multiaccess Edge Computing, U-Boot, Api Gateway, Terraform, Ddos, Oracle Cloud Infrastructure, Serverless Computing, Security Orchestration, Automation & Response, Microservices - **Published:** May 19, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=24d8e405dc0b6bbd ## About the Role * 15 plus years of Security Engineering and Architecture experience, including principal- or architect-level leadership designing secure SaaS, appliance-based, or cloud-native platforms at global scale. * Proven ability to architect secure multi-cloud (AWS, GCP, Azure, OCI) platforms, including identity federation, VPC/network isolation, workload identity, secrets lifecycle, and secure control-plane design. * Deep expertise in securing: + Container and Kubernetes ecosystems (EKS, GKE, AKS, Istio, Envoy, Pod Security, eBPF, runtime protection) + Infrastructure-as-Code and platform engineering workflows (Terraform, Helm, CloudFormation, Kustomize, Pulumi) + Protocol-heavy systems (DNS, DHCP, IPAM / DDI architecture, control-plane security, service segmentation, and abuse prevention) * Advanced knowledge of secure architecture patterns, including Zero Trust, secure edge computing, secure boot, TPM, firmware integrity, remote attestation, confidential computing, and supply chain integrity (SBOM, SLSA, SCVS). * Strong track record of architecting and implementing security automation, using language fluency in Python, Go, Rust, or Shell to build scalable tools, runtime validation frameworks, and detection/response integrations. * Demonstrated experience translating compliance frameworks (FedRAMP High, SOC2, NIST 800-53, ISO 27001, SOX, CSA CCM) into engineering-enforceable technical control architectures. * Hands-on experience conducting and leading: + Threat modeling (STRIDE, PASTA, attack trees, misuse cases) + Secure code reviews (Python, Go, Rust, C/C++, Lua, Shell) + API and microservice security reviews (OAuth2/OIDC, mTLS, JWT, ABAC/RBAC) * Experience defining and leading security capability roadmaps, influencing long-term strategy for platform hardening, secure edge architecture, supply chain resilience, and incident-driven control improvements. * Strong communication and influence skills-capable of evangelizing secure architecture to VP-level business leaders, product strategists, and engineering leaders. * Relevant certifications desirable (AWS Security Specialty, CISSP-ISSAP, GIAC-GDSA/GCSA, CCSP, OSCP), but hands-on architectural experience outweighs certifications. ## Description We have an opportunity for a Principal Architect to join our Architecture team in Tacoma, WA, Austin, TX or Atlanta, GA, reporting to the Vice President of Architecture. In this role, you will play a vital part in shaping and governing product security architecture across our products and platforms. You will work as part of an extended architecture team alongside product engineering, cloud platform, and security stakeholders to identify security gaps, define security architecture standards, and drive adoption of industry-leading practices. You are the ideal candidate if you are a security thought leader who enjoys identifying gaps and designing corrective measures in collaboration with key stakeholders. Be a Contributor - What You'll Do * Serve as the security architecture authority within the architecture organization, partnering with product architects, principal engineers, cloud partners (AWS, Azure, GCP, OCI), and business leaders to embed secure-by-design principles into hardware appliances, multi-tenant SaaS platforms, and globally distributed cloud infrastructure. * Architect end-to-end security controls and trust boundaries across hybrid infrastructure-firmware and appliance platforms (TPM, secure boot, supply chain), Kubernetes-based microservices, APIs, control-plane services, and multi-cloud SaaS environments with high availability and resilience. * Lead the creation and enforcement of security reference architectures and reusable design patterns, covering Zero Trust, confidential computing, data protection, SBOM/SLSA-based supply chain integrity, workload identity, runtime security (eBPF), and API authn/authz protections. * Drive and institutionalize architectural threat modeling (STRIDE, PASTA, attack trees, misuse cases) at the feature, platform, and system levels-directly shaping secure designs before code is written. * Architect secure implementations of DNS, DHCP, IPAM (DDI) and high-scale network-centric services, ensuring resilience to poisoning, tunneling, spoofing, DDoS, query amplification, misconfiguration, and protocol misuse. * Define and integrate security control points throughout CI/CD and platform engineering workflows, using Policy-as-Code, IaC scanning, security validation hooks, attestation requirements, and automated enforcement at deployment gates. * Design, build, and scale security automation and orchestration capabilities using Python/Go, serverless, event-driven frameworks, OPA/Kyverno, and CI/CD integrations to reduce manual toil and accelerate secure delivery. * Lead and influence architecture reviews and governance forums, shaping long-term technical roadmaps and product direction to meet security and reliability objectives. * Drive adoption of CNAPP, CWPP, WAF, service mesh security, API gateways, SIEM/SOAR, and cloud-native telemetry for protective monitoring, runtime defense, and incident-ready detection. * Translate regulatory and compliance requirements (FedRAMP, SOC2, ISO 27001, NIST SP 800-53, CSA CCM, SOX) into actionable, measurable, and auditable security architecture control objectives-shifting from audit-driven to architecture-driven alignment. * Act as a security culture amplifier, mentoring architects and senior engineers, building a broader security-minded engineering community, and elevating the technical bar across the organization., First 90 Days: Immerse in our culture, connect with mentors (Blox Buddies), and map the systems and meet with key stakeholders that rely on your work. Discuss and create short/long term goals. Six Months: Gain a comprehensive understanding of our product ecosystem and its security needs, establish strong relationships with key stakeholders across teams, and identify and propose enhancements for security automation in our infrastructure. One Year: Become a trusted advisor within the organization, recognized for leading secure product design initiatives, assist in the design of a comprehensive security architecture roadmap and ensure IT SOC processes are in alignment with product security objectives. Belong- Your Community Our culture thrives on inclusion, rewarding the bold ideas, curiosity, and creativity that move us forward. In a community where every voice counts, continuous learning is the norm. So, whether you code, create, sell, or care for customers, you'll grow and belong here. ## Related Videos - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [WeAreDevelopers LIVE - Chrome for Sale? Comet - the upcoming perplexity browser Stealing and leaking](https://www.wearedevelopers.com/videos/1331-wearedevelopers-live-chrome-for-sale-comet-the-upcoming-perplexity-browser-stealing-and-leaking) - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Rate-limiting using eBPF and Istio: How to protect your SaaS customers from themselves](https://www.wearedevelopers.com/videos/100220-rate-limiting-using-ebpf-and-istio-how-to-protect-your-saas-customers-from-themselves) - [Get started with securing your cloud-native Java microservices applications](https://www.wearedevelopers.com/videos/123-get-started-with-securing-your-cloud-native-java-microservices-applications) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [The Best X (Twitter) Accounts for Developers](https://www.wearedevelopers.com/magazine/294-the-best-x-twitter-accounts-for-developers) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)