> Markdown version of [/jobs/ext/516956-principal-security-architecture-digital-solutions](https://www.wearedevelopers.com/jobs/ext/516956-principal-security-architecture-digital-solutions). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Principal Security Architecture - Digital Solutions - **Company:** Ally Financial Inc. - **Location:** Charlotte, NC, United States (Remote available) - **Experience:** Expert - **Salary:** $110,000.0 - $180,000.0 - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Amazon Web Services, Software Applications, Microsoft Azure, Software as a Service, Cloud Computing, Cloud Engineering, Cyber Security, Continuous Integration, Data Control, Data Governance, Information Leak Prevention, Data Sharing, Identity and Access Management, Key Management, Network Security, OAuth, OpenID, Open Web Application Security, PCI Data Security Standards, Systems Development Life Cycle, Role-Based Access Control, Secure Coding, Systems Integration, Large Language Models, Software Security, Togaf, Information Technology, Integration Frameworks, Api Gateway, Ddos, Microservices - **Published:** June 4, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=3b3e80f35889ae5d ## About the Role Do you have experience in Stakeholder relationship building?, Do you have a Master's degree?, * 7+ years of relevant experience * Bachelor's Degree in Computer Science, Information Security, or related field of study or equivalent, * Master's in Computer Science, Information Security, or related field. * 5+ years in security architecture with strong digital application security and cloud experience (AWS/Azure). * Proven ability to mentor/coach and drive cross-team adoption of secure patterns. * Demonstrated Financial Services experience supporting regulated environments, including one or more of: retail/commercial banking, investments/wealth, or digital marketing/CRM ecosystems. * Strong experience securing SaaS/third-party integrations and complex API ecosystems (partner connectivity, vendor platforms, external identity, data sharing). * Deep expertise in IAM, network security, data protection, and SaaS/third-party risk. * Experience with security reviews, threat modeling, and technology/vendor evaluations. * Knowledge of financial regulatory frameworks (FFIEC, PCI DSS, SOX) and security frameworks (NIST, CIS, CRI). * Strong communication and stakeholder management skills. * Certifications (e.g., CISSP, CCSP, AWS/Azure Security, CISM, TOGAF) desirable. * GenAI/LLM security knowledge (prompt injection defenses, sensitive data controls, RAG security, monitoring/abuse detection); regulated-environment experience preferred. ## Description * Lead end-to-end security architecture reviews for digital solutions (web, mobile, APIs, microservices, integrations) and drive risk treatment. * Maintain reference architectures, secure patterns, and standards across IAM, data, network, cloud, and third-party/SaaS. * Perform threat modeling and security risk assessments (e.g., OWASP, API abuse, supply chain threats). * Own and evolve the digital security architecture roadmap aligned to business priorities, regulation, and measurable risk reduction. * Engineering Enablement. * Embed security in CI/CD and SDLC (secure coding guidance, security testing, cloud-native guardrails). * Communicate recommendations clearly to engineers and leadership; influence design decisions and risk acceptance outcomes. Core Security Domains * IAM: authentication/authorization, federation/SSO, least privilege, service-to-service identity. * Network: segmentation, ingress/egress controls, API gateway/WAF, DDoS, secure connectivity. * Data: classification, encryption, tokenization/masking (where applicable), key/secrets management. * Cloud: AWS/Azure secure baselines and architecture patterns aligned to organizational standards. * Third-party/SaaS: security due diligence, onboarding/contractual security controls, monitoring, and ongoing assurance. * Application Security: Establish integration security standards (API schemas, mTLS/OAuth2/OIDC patterns, token storage/rotation, webhook security, idempotency/replay protections, and rate limiting/abuse detection). GenAI Security * Define secure GenAI patterns (LLM access controls, prompt/response handling, RAG security, agent/tooling boundaries). * Threat model GenAI use cases (prompt injection, data leakage, model extraction/poisoning, unsafe output handling) and define mitigations/testing. * Set GenAI data governance requirements (sensitive data use, retention, auditability) and vendor/model assurance expectations. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [WeAreDevelopers LIVE - Chrome for Sale? Comet - the upcoming perplexity browser Stealing and leaking](https://www.wearedevelopers.com/videos/1331-wearedevelopers-live-chrome-for-sale-comet-the-upcoming-perplexity-browser-stealing-and-leaking) - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [Next Level Enterprise Architecture: Modular, Flexible, Scalable, Multichannel and AI-Ready?](https://www.wearedevelopers.com/videos/1017-next-level-enterprise-architecture-modular-flexible-scalable-multichannel-and-ai-ready) - [Micro-frontends anti-patterns](https://www.wearedevelopers.com/videos/299-micro-frontends-anti-patterns) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries)