> Markdown version of [/jobs/ext/2004649-principal-security-architect](https://www.wearedevelopers.com/jobs/ext/2004649-principal-security-architect). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Principal Security Architect - **Company:** MetLife - **Location:** New York, NY, United States - **Experience:** Expert - **Salary:** $120,000.0 - $190,000.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Cloud Computing Security, Cloud Engineering, Cyber Security, Data Security, Software Design Patterns, Digital Architecture, Identity and Access Management, Information Security Management, Key Management, Network Security, Microsoft Software, Network Architecture, Network Segmentation, Role-Based Access Control, Cloud Services, Zero Trust Network Access, Sherwood Applied Business Security Architecture, Software Deployment, Systems Integration, Software Vulnerability Management, EndPointSecurity, Policy as Code, Data Logging, Software Security, Togaf, Containerization, Kubernetes, Infrastructure Automation Frameworks, Enterprise Integration, Devsecops, Security Orchestration, Automation & Response - **Published:** August 9, 2026 - **Apply:** https://www.juju.com/job/00000000gm9gci ## About the Role * 8- 10 years of overall experience. * Strong experience in security architecture, enterprise architecture, security engineering, or cyber risk roles with demonstrated responsibility for reviewing or designing complex technology solutions. * Demonstrated expertise in threat modeling, risk assessment, attack path analysis, trust-boundary assessment, control gap analysis, and security remediation planning. * Deep understanding of security architecture patterns, including identity-centric security, zero trust, least privilege, defense-in-depth, segmentation, secure access, data protection, secure integration, and secure-by-design principles. * Ability to evaluate security controls and technologies, determine control applicability, assess architecture fit, and provide risk-based recommendations that balance protection, usability, delivery speed, and operational feasibility. * Broad knowledge across IAM, network security, endpoint/device security, application security, data security, cloud security, SOC/security operations, governance/risk/compliance, and/or AI security. * Experience developing reference architectures, security standards, guardrails, architecture decision records, or reusable design patterns for enterprise teams. * Strong understanding of enterprise architecture practices, including current-state assessment, target-state architecture, roadmap planning, maturity modeling, capability modeling, and transformation leadership. Preferred Qualifications * Experience supporting Security Architecture Review, Architecture Review Board, technology governance, cloud governance, or risk acceptance processes in a large enterprise environment. * Hands-on or architecture experience with identity platforms, privileged access management, conditional/risk-based access, role-based access control, federation, secrets management, and workload/non-human identity patterns. * Experience with secure access service edge, zero trust network access, micro segmentation, API security, B2B connectivity, cloud connectivity, and secure hybrid network architecture. * Experience with cloud-native architectures, container platforms, Kubernetes, DevSecOps pipelines, infrastructure as code, policy-as-code, vulnerability management, posture management, logging, monitoring, detection, and response integration. * Familiarity with AI security risks and controls, including model misuse, sensitive data exposure, excessive agency, prompt injection, insecure integrations, supply chain risk, AI governance workflows, and secure AI deployment patterns. * Experience influencing cross-functional architecture decisions and leading stakeholders toward target-state designs, standard patterns, measurable maturity improvements, and practical implementation roadmaps. * Relevant certifications such as CISSP, CCSP, SABSA, TOGAF, Microsoft Cybersecurity Architect, cloud security certifications, or other security architecture credentials are a plus. Location Expectation: This is a hybrid role requiring a minimum of 3 days per week in office. ## Description As part of MetLife's Global Security team, you'll work alongside world-class experts to protect MetLife, our customers and our colleagues. The team is responsible for managing cybersecurity, IT risks and vulnerabilities, physical security, and more. In this fast-paced, mission-driven environment, you'll join outstanding teammates to expand your skills, collaborate across the organization and implement innovative approaches to safeguard MetLife when it matters most. Ready to make an impact? Join us if you want to embrace the rapidly evolving environment and use transformative technology to integrate and build security into the foundation of key initiatives across MetLife. The Opportunity The Principal Security Architect will lead risk-based security architecture reviews and provide enterprise-grade security guidance for technology and platform initiatives submitted through the Security Architecture Review process. This role will evaluate proposed architectures, identify material risks, recommend appropriate security controls, and help teams align solutions to target-state architecture, reference patterns, and roadmaps. The successful candidate will bring deep expertise in threat modeling, security control evaluation, architecture design, identity-centric security, network segmentation, secure access, risk-based access policy design, and broad security domain knowledge across IAM, network, devices, applications, data, SOC, cloud, governance/risk/compliance, and AI. This role is expected to influence architecture decisions, develop reusable reference architectures, and support enterprise transformation through current-state assessment, maturity modeling, strategic planning, and roadmap development. Key Responsibilities * Lead Security Architecture Review (SAR) assessments for enterprise technology initiatives, including applications, platforms, cloud services, infrastructure, AI solutions, integrations, and major transformation programs. * Perform threat modeling and risk assessments to identify security design gaps, control weaknesses, trust-boundary concerns, attack paths, data exposure risks, and operational impacts. * Evaluate security controls, tools, and technologies against architecture requirements, enterprise standards, risk posture, and control effectiveness objectives. * Design and recommend secure architecture patterns across identity, network, endpoint/device, application, data, cloud, SOC/security operations, governance/risk/compliance, and AI domains. * Develop and maintain reusable security reference architectures, decision patterns, implementation guardrails, and design principles to accelerate secure delivery at scale. * Provide identity-centric security architecture guidance, including authentication assurance, authorization models, privileged access, least privilege, role-based access, non-human identity considerations, and lifecycle integration. * Advise on network segmentation, micro segmentation, secure access, zero trust access patterns, ingress/egress controls, and connectivity models for internal, internet-facing, and B2B integrations. * Design risk-based access policies for users, workloads, devices, applications, data, and administrative functions, considering sensitivity, exposure, business criticality, and operational requirements. * Assess current-state security architecture and define target-state architecture, transition roadmaps, maturity models, and strategic recommendations for enterprise security transformation. * Drive integration of security architecture with the five security pillars: IAM, network, devices, applications, and data, while ensuring alignment with security automation, orchestration, monitoring, detection, and response capabilities. * Partner with enterprise architecture, application teams, cloud/platform teams, network engineering, IAM, data protection, SOC, GRC, privacy, legal, and risk stakeholders to develop pragmatic and implementable security recommendations. * Document architecture decisions, risks, assumptions, compensating controls, and required remediation actions clearly for technical teams, governance bodies, and leadership audiences. ## Related Videos - [Understanding Kubernetes in a visual way](https://www.wearedevelopers.com/videos/100085-understanding-kubernetes-in-a-visual-way) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Blueprints for Success: Steering a Global Data & AI Architecture](https://www.wearedevelopers.com/videos/1577-blueprints-for-success-steering-a-global-data-ai-architecture) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) - [Instant KAI Sandboxes with vCluster: Multi-Tenant, Multi-Scheduler GPU Sharing](https://www.wearedevelopers.com/videos/100333-instant-kai-sandboxes-with-vcluster-multi-tenant-multi-scheduler-gpu-sharing) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence](https://www.wearedevelopers.com/magazine/736-best-us-ai-conferences-for-ctos-in-2026-build-vs-buy-vendor-evaluation-and-peer-intelligence) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Everything a Developer Needs to Know About MCP with Neo4j](https://www.wearedevelopers.com/magazine/604-everything-a-developer-needs-to-know-about-mcp-with-neo4j) - [Navigating the AI Shift](https://www.wearedevelopers.com/magazine/629-navigating-the-ai-shift)