> Markdown version of [/jobs/ext/913210-principal-security-architect](https://www.wearedevelopers.com/jobs/ext/913210-principal-security-architect). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Principal Security Architect - **Company:** First Horizon Bank - **Location:** Memphis, TN, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Active Directory, Agile Methodology, Microsoft Azure, Software as a Service, Continuous Integration, DevOps, Network Topologies, Identity and Access Management, Key Management, Network Segmentation, OAuth, OpenID, Open Web Application Security, PCI Data Security Standards, Ping (Networking Utility), Systems Development Life Cycle, Phishing, Zero Trust Network Access, Salesforce.Com, Data Logging, Data Processing, Okta, Cyberark, Mitre Att&ck, Customer Identity Access Management, Kubernetes, Information Technology, Api Gateway, Splunk, Servicenow - **Published:** June 2, 2026 - **Apply:** https://dejobs.org/x/x/4E3A27BD250B41F78A8BA51A5D62E1BF/job/ ## About the Role * Bachelor's degree in Computer Science, Management Information Systems, or related field * (12+) years of InformationSecurityexperience * (7+) years ofSecurityArchitecture * Experience in regulated financial services * Experience with Azuresecurityarchitecture across multi-tenant/region and hybrid environments; strong Zero Trust and network segmentation expertise * Regulatory fluency: FFIEC, GLBA, PCI DSS; practical NIST CSF/800-53 mapping; MITRE ATT&CK-aligned detection design. * Experience with technical documentation like interaction diagrams, process diagrams, network topologies and otherarchitectural content * Experience with Agile/SAFe methodologies * Experience with EnterpriseArchitecture Governance: ARB/design councils, exception handling, and audit narratives; ability to set and harmonize enterprise standards. Certifications/Licensures * Strongly preferred: CISSP or CompTIASecurity+ Microsoft AzureSecurityEngineer or Azure SolutionsArchitectExpert * Preferred: CCSP; CISM or CRISC; SANS GCSA or GCLD; PCI Professional (PCIP) or equivalent GIAC enterprise defense/IR certifications Skills And Competencies * Ability to adapt to new technologies and learn quickly * Enterprisearchitectural leadership across identity, cloud, application, data, and networksecurity. * IAM for associates (Entra ID, Active Directory) and clients (TransmitSecurity, ForgeRock/Ping, or Okta); OAuth/OIDC; phishing-resistant MFA/passkeys; PAM integration and privileged pathway design. * IntegrationSecurity: FAPI, OAuth2.0, FDX, mTLS, rate limiting, schema validation, abuse/bot mitigation, CIAM integration, OWASP, and high-quality telemetry to Splunk. * Secure SDLC and supply chain: threat modeling, pipelinesecurity, artifact signing/SBOM, dependency hygiene, and secrets management. * Communication, influence, and enablement: ability to translate risk to business impact, drive adoption, and coach peers and engineers. * Ownership and execution: measurable risk reduction, pattern adoption, and cross-team collaboration. ## Description * Manages solution design from conception, through ARB, to delivery * Primarily responsible for producingarchitecture documentation forsecurityapplications as assigned and as projects and programs of work dictate * Maintains First Horizon'sSecurityArchitecture Pattern Inventory (across identity, data, application, network, and cloud) as a member of the Core EnterpriseArchitecture Team * Leadssecuritydesign workshops and POC efforts for new (security) capabilities * Validates 3rd Party/Vendor Solutions forsecurityconcerns * Aligns InformationSecurityTechnology strategy and planning with First Horizon's business goals and objectives * Promotes the use of a shared infrastructure and application roadmap to reduce costs and improve how assets are secured * Builds and maintains technical trusted advisor relationships with influential technical decision makers within Technology * Works with engineers to ensure that technical solutions as delivered align with InformationSecurityStandards and Policies * Works with Portfolio technology leaders to include IT Risk andSecurityException initiatives in portfolio roadmap * Manage Encryption Standards: key management, tokenization for payments, DLP/classification/handling;architectPCI DSS segmentation boundaries and compensating controls. * Manage Network/Zero Trust Standards: microsegmentation across Azure and colocation; secure branch/office connectivity; define workload identity and continuous verification patterns; enforce least privilege. * Detection/telemetry: Publish Splunk logging schema, retention, and correlation strategies; onboard logs from Azure, Colo, API Gateways, IAM, CyberArk, MFaaS, and core platforms; drive ATT&CK-aligned detections and forensic readiness. * Secure SDLC and supply chain: Operationalize threat modeling; collaboratively define CI/CD control overlays with DevOps; establish artifact signing/SBOM standards; ensure secrets handling and container/Kubernetes baselines where applicable. * Governance and risk: Maintain control overlays mapped to FFIEC/GLBA/PCI/NIST; lead design reviews; manage exceptions with remediation timelines; produce audit-ready decision records in partnership with the CISO team. * Payments and third-party/SaaS: Define intake andsecurityrequirements for MFaaS, Salesforce, ServiceNow, FIS/Fiserv/Bottomline integrations-identity, logging, data handling, and PCI scoping. * Physicalsecurityintegration: Align building access, video, and visitor systems with identity and logging patterns; coordinate incident playbooks with Corporate/PhysicalSecurity. * Enablement and influence: Mentor seniorarchitects and engineering associates; lead communities of practice; communicate strategy, benefits, and trade-offs to executives and delivery teams. ## Related Videos - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) - [Enterprise-Cloud-Native - Fast-Paced Development & Deployment in a Highly Secure Banking Environment](https://www.wearedevelopers.com/videos/671-enterprise-cloud-native-fast-paced-development-deployment-in-a-highly-secure-banking-environment) - [Advanced Cypress: custom assertions and tasks](https://www.wearedevelopers.com/videos/790-advanced-cypress-custom-assertions-and-tasks) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Everything a Developer Needs to Know About MCP with Neo4j](https://www.wearedevelopers.com/magazine/604-everything-a-developer-needs-to-know-about-mcp-with-neo4j) - [Building Security Champions](https://www.wearedevelopers.com/magazine/87-building-security-champions) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking)