This is a remote position.
Position Title: Principal Architect, Technology – Enterprise Security
Base Salary: $155,000 to $230,000 annually DOE
Bonus: Target annual bonus
Benefits: Medical, dental, vision, 401k, flexible spending account, paid sick leave and paid time off, parental leave, quarterly performance bonus, training, career growth and education reimbursement programs.
Ziply Fiber is a local internet service provider dedicated to elevating the connected lives of the communities we serve. We offer the fastest home internet in the nation, a refreshingly great customer experience, and affordable plans that put customers in charge.
As our state-of-the-art fiber network expands, so does our need for team members who can help us grow and realize our goals.
Our Company Values:
Job Summary
The Principal Architect, Technology - Enterprise Security is a senior individual contributor responsible for defining and advancing the enterprise security architecture and technical standards that protect Ziply Fiber's corporate systems, employee infrastructure, and business applications, as well as the network we operate on behalf of 1M+ broadband subscribers.
This role provides architecture-level direction across corporate and network environments — including Zero Trust strategy, threat detection and response architecture, cloud and application security, and identity and access management design. Operation of the security tooling and Security Operations Center (SOC) sits with the Security Operations function, and control governance and approval sit with Governance, Risk & Compliance (GRC). This separation of duties is deliberate and keeps architecture and design distinct from the operation and assessment of controls.
The successful candidate brings deep, hands-on security architecture expertise in a broadband ISP, telecommunications, or critical-infrastructure environment, and the demonstrated ability to translate business risk into technical design and to communicate security architecture to both engineering teams and executive stakeholders.
Essential Duties and Responsibilities:
The Essential Duties and Responsibilities listed below are a range of duties performed by the employee and not intended to reflect all duties performed.
Security Architecture & Zero Trust
· Define and own Ziply's enterprise security architecture: network segmentation, Zero Trust Network Access (ZTNA) strategy, micro-segmentation, and identity-based access-control design across corporate and network environments.
· Establish the Zero Trust reference architecture and multi-year roadmap, including policy-decision and policy-enforcement point design, device-posture and conditional-access standards, and the phased migration from perimeter-based to identity-centric access.
· Architect firewall and perimeter strategy: next-generation firewall platform selection (Palo Alto, Fortinet, or equivalent), zone and trust-boundary design, rule-governance and change standards, and policy-lifecycle design.
· Define identity and access management (IAM) architecture: MFA enforcement standards, privileged access management (PAM) design, SSO and federation patterns (SAML/OIDC), directory and service-account governance, and joiner/mover/leaver control design.
· Design secure remote-access architecture: ZTNA/SASE platform strategy, VPN-replacement roadmap, split-tunnel and posture-check standards, and endpoint-security integration.
· Establish and maintain reference architectures, design patterns, and security standards that engineering and operations teams build to, evolving them as threats and technologies change.
Network Security Architecture
· Define network security architecture for Ziply's infrastructure: out-of-band (OOB) management network design, jump-host and bastion architecture, and network-device access-control standards (TACACS+/RADIUS, role-based device access).
· Define enterprise DDoS-protection architecture, including coordination with the Subscriber Edge DDoS/Arbor program and definition of enterprise-facing scrubbing, remotely triggered black-hole (RTBH), and mitigation capabilities.
· Architect DNS security: RPZ (Response Policy Zones), DNSSEC, and DNS-over-HTTPS/TLS strategy for internal and subscriber-facing resolvers, and secure DNS/DHCP/IPAM design.
· Define network monitoring and anomaly-detection architecture: NetFlow/IPFIX analysis for security use cases, IDS/IPS placement and tuning standards, TLS-inspection strategy, and integration with the SIEM.
· Establish system-hardening baselines for network and infrastructure devices (e.g., CIS Controls, DISA STIGs, USGCB) and define secure-configuration standards for routers, switches, and firewalls.
· Define segmentation and trust-zone architecture separating corporate, subscriber, management/OT, and lab environments.
Security Operations & Threat Detection Architecture
· Define SIEM architecture in partnership with Security Operations: platform strategy or optimization, log-source onboarding standards, data-retention and normalization design, and correlation and detection-rule governance standards.
· Define detection-engineering standards, including use-case development mapped to MITRE ATT&CK, alert-tuning and false-positive-reduction practices, and detection-coverage measurement.
· Define SOC tooling architecture: SOAR platform strategy, playbook-automation standards, case-management and ticketing integration, threat-intelligence integration, and escalation-workflow design.
· Define endpoint detection and re
| Location | Kirkland, WA (Remote) |
| Salary | $155,000–$230,000 Per Year |
Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.
Free resume templatesImprove your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.
Free resume builder