Principal Security Architect
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+2 more
Job description
Experteer Overview In this role you will lead risk-based security architecture reviews and provide enterprise-grade guidance for technology initiatives within MetLife’s Global Security team. You’ll shape secure patterns across IAM, network, data, cloud, and AI domains, aligning solutions with target architectures and roadmaps. You’ll drive threat modeling, risk assessments, and reusable reference architectures to enable secure delivery at scale. This is a hybrid, impact-oriented role that partners across the organization to transform security practices and support enterprise transformation. Compensation / Benefits * Lead Security Architecture Review (SAR) assessments for enterprise initiatives including cloud services, AI, and major transformation programs * Conduct threat modeling and risk assessments to identify design gaps, trust-boundary issues, and data exposure risks * Evaluate security controls and technologies against architecture requirements and risk objectives * Design secure architecture patterns across identity, network, data, cloud, SOC, governance, and AI domains * Develop reusable security reference architectures, guardrails, and design principles to accelerate secure delivery * Provide identity-centric security guidance (authentication, authorization, privileged access, least privilege) * Advise on network segmentation, secure access patterns, zero trust, and B2B/internet connectivity * Define risk-based access policies for users, workloads, devices, apps, and data * Assess current-state vs target-state architecture with roadmap and maturity modeling * Collaborate with enterprise architecture, security, cloud, IAM, data protection, and governance teams to produce pragmatic recommendations * Document decisions, risks, and remediation actions for technical and leadership audiences Tasks * 8-10 years of overall experience * Strong experience in security architecture, enterprise architecture, security engineering, or cyber risk roles * Expertise in threat modeling, risk assessment, attack path analysis, trust-boundary assessment, control gap analysis * Deep understanding of identity-centric security, zero trust, least privilege, defense-in-depth, segmentation, secure-by-design principles * Ability to evaluate security controls and provide risk-based recommendations balancing protection, usability, and delivery speed * Broad knowledge across IAM, network security, endpoint security, application security, data security, cloud security, SOC/GRC/AI security * Experience developing reference architectures, security standards, guardrails, and reusable design patterns * Familiarity with enterprise architecture practices including current/target-state architecture and roadmaps Key requirements * comprehensive health plan * life insurance * 401(k) with employer matching * parantal leave * paid time off and holidays * EAP and digital mental health programs
Requirements
_ architecture patterns across identity, network, data, cloud, SOC, governance, and AI domains * Develop reusable security reference architectures, guardrails, and design principles to accelerate secure delivery * Provide identity-centric security guidance (authentication, authorization, privileged access, least privilege) * Advise on network segmentation, secure access patterns, zero trust, and B2B/internet connectivity * Define risk-based access policies for users, workloads, devices, apps, and data * Assess current-state vs target-state architecture with roadmap and maturity modeling * Collaborate with enterprise architecture, security, cloud, IAM, data protection, and governance teams to produce pragmatic recommendations * Document decisions, risks, and remediation actions for technical and leadership audiences Tasks * 8-10 years of overall experience * Strong experience in security architecture, enterprise architecture, security engineering, or cyber risk roles * Expertise in threat a reusable risk assessment, attack path analysis, trust-boundary assessment, control gap analysis * Deep understanding of identity-centric security, zero trust, least privilege, defense-in-depth, segmentation, secure-by-design principles * Ability to evaluate security controls and provide risk-based recommendations balancing protection, usability, and delivery speed * Broad knowledge across IAM, network security, endpoint security, application security, data security, cloud security, SOC/GRC/AI security * Experience developing reference architectures, security standards, guardrails, and reusable design patterns * Familiarity with enterprise architecture practices including current/target-state architecture and roadmaps Key requirements * comprehensive health plan * life insurance * 401(k) with employer matching * parantal leave * paid time off and holidays * EAP and digital mental health programs
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on us.experteer.comGood distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Understanding and Mitigating Common Web Vulnerabilities
Everything a Developer Needs to Know About MCP with Neo4j
What Are The Top Skills Required For Azure Developers?
Dev Digest 120 - Apple and peers