> Markdown version of [/jobs/ext/3395934-principal-cloud-security-architect](https://www.wearedevelopers.com/jobs/ext/3395934-principal-cloud-security-architect). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Principal, Cloud Security Architect - **Company:** LIO Insurance Company - **Location:** Conshohocken, PA, United States - **Salary:** $189,000.0 - $299,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Artificial Intelligence, Amazon Web Services, Bash Shell, Cloud Computing, Cloud Computing Security, Cloud Engineering, Cyber Security, Identity and Access Management, Information Technology Operations, Python (Programming Language), Key Management, Windows PowerShell, Cloud Services, Security Information and Event Management, Software Vulnerability Management, Datadog, Data Logging, Scripting, Okta, Large Language Models, Cloudformation, Microsoft InTune, Infrastructure Automation Frameworks, Information Technology, Deployment Automation, Terraform, Software Version Control - **Published:** September 22, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=e9bbc932039a774a ## About the Role To perform this job successfully, an individual must be able to perform each essential duty satisfactorily. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions. * Deep, current AWS architecture and engineering experience, particularly networking, IAM, resilience, logging, and infrastructure security. * Demonstrated hands-on ability with infrastructure as code and automation, using tools such as Terraform, CloudFormation, or CDK and a scripting language such as Python, PowerShell, or Bash. * Practical security engineering experience across identity, access control, vulnerability remediation, monitoring, and incident response. * Experience operating production services with defined service expectations, tested recovery procedures, and accountable incident follow-through. * Track record of setting architecture standards across teams, mentoring senior engineers, reviewing provider implementations, and influencing investment decisions without direct reporting authority. * Clear communication with engineers, business leaders, and risk/compliance partners, supported by useful technical documentation. * Ability to thrive in a virtual, global organization and effectively manage competing priorities., * Bachelor's Degree in Computer Science, Information Technology, or a related field (or equivalent practical experience). * Typically 12 or more years of relevant cloud infrastructure, platform engineering, or security engineering experience, with sustained organization-wide architectural impact; level is based on demonstrated capability, not tenure alone. * Demonstrated track record of setting technical direction and influencing outcomes across teams without direct reporting authority. Preferred Education and Experience * Experience in insurance, financial services, or another regulated environment. * Familiarity with Microsoft 365, Intune, Okta or Entra ID, and endpoint security platforms. * Experience with Datadog or comparable observability and security monitoring tools. * Experience integrating security checks into software delivery and securing AI or LLM workloads. * Familiarity with NIST CSF, control assessments, and evidence supporting regulatory examinations. Additional Eligibility Requirements (Certificates, Licenses, Required/Preferred) * Relevant AWS, cloud security, or information security certifications preferred; demonstrated delivery experience is equally valued. ## Description * Own AWS infrastructure architecture, including account structure, networking, identity, compute, storage, connectivity, and environment separation. * Establish reusable infrastructure patterns and guardrails with infrastructure as code, version control, and automated deployment checks. * Design for availability, recovery, performance, and cost; make practical tradeoffs based on workload and business needs. * Partner with Enterprise Architecture on standards and design reviews, translating application and integration requirements into secure, supportable cloud infrastructure. * Set technical requirements for cloud engineering providers, review their designs and implementation, and contribute hands-on to critical changes and complex troubleshooting. * Define architecture and control standards for cloud services, endpoints, identity, and connectivity, partnering with IT Operations on implementation and supportability. * Design observability, escalation patterns, and technical runbooks; agree operational handoffs and coverage with the accountable service owners. * Design infrastructure backup and recovery capabilities; work with business and application owners to define recovery objectives and validate restoration with IT Operations and providers. * Improve operational performance through automation, capacity planning, root-cause analysis, and disciplined change management. * Evaluate infrastructure and security tooling, identify cloud cost improvements, and recommend lifecycle investments to the accountable budget owner. * Implement the technical controls supporting LIO's security program across AWS, identity platforms, Microsoft 365, endpoints, networks, and shared infrastructure. * Strengthen privileged access, authentication, segmentation, encryption, secrets management, logging, and data protection. * Define infrastructure vulnerability remediation patterns, implement complex fixes, and coordinate technical remediation with application and service owners using agreed priorities and deadlines. * Establish effective detection and response capabilities with internal teams and providers; lead technical containment and recovery during incidents. * Partner with engineering on secure deployment practices and with AI/data owners on workload identity, access boundaries, sensitive-data protection, and monitoring. * Produce operating evidence, support control assessments, and resolve findings in partnership with the CISO and GRC lead. * Mentor engineers and operational staff, document design decisions, and build reusable patterns that reduce dependence on individual experts. * Shape the multi-year cloud security architecture and technical roadmap; agree delivery priorities and capacity with the CTO/CIO, CISO, and functional leaders. * Translate technical issues into clear choices about risk, cost, service impact, and delivery timing. * Set technical acceptance criteria for providers, review implementation quality, and retain architecture knowledge and documentation within LIO. * Escalate unresolved risks, resource constraints, and control exceptions promptly through the agreed governance process. * Participate in special projects and other duties as assigned. LIO LIFE - What We Value The Customer Lens * - Prioritizing our relationships, service, and needs of our customers. Innovative Thinking * - Fostering an environment that empowers and sustains bold thinking and actions. Balance * - Creating an inclusive, diverse, and holistic balance to meet our personal and professional needs. Simplicity * - Striving for simplicity in our service, products, and processes. Accountability * - Owning our results and learning from them.