Prinicipal Architect
Indexed description
In This Role, You Will
- Define and own the security strategy, governance framework, risk tolerance, and control standards across the AI Platforms portfolio.
- Establish and oversee security governance processes, including Authority to Operate (ATO), risk acceptance, compliance monitoring, and executive risk reporting.
- Drive secure-by-design principles across cloud-native and AI-native platforms, including Zero Trust, threat modelling, identity security, encryption, and policy-driven controls.
- Lead regulatory compliance, audit readiness, vulnerability management, incident response governance, and threat intelligence programs across healthcare and financial services platforms.
- Build and lead a high-performing security organization while partnering with engineering and business leaders to balance risk management, innovation, and delivery outcomes.
The working arrangements for this role are accurate as of the date of posting. This may change based on the project you’re engaged in, as well as business and client requirements. Rest assured; we will always be clear about role expectations.
What You Need To Have To Be Considered
- 20+ years of experience in information security and cybersecurity, including leadership experience in a CISO or CISO-1 role within a software product organization.
- Experience operating in highly regulated industries such as Healthcare and/or Financial Services, with accountability for security governance and risk management.
- Deep expertise in cloud and application security, including Secure by Design, Zero Trust, Defense in Depth, threat modeling, and software security practices.
- Proven experience managing regulatory and compliance frameworks such as HIPAA, HITRUST, SOC 2, PCI-DSS, and related governance requirements.
- Strong experience securing cloud-native, AI-enabled, and modern software platforms across AWS, Azure, and GCP environments.
- Experience building or transforming security organizations supporting large-scale platform modernization and cloud transformation initiatives.
- Expertise in AI security, agentic AI governance, model access controls, AI risk management, and AI-specific threat vectors.
- Strong understanding of encryption architectures, key management, workload identity separation, and cloud-native security controls.
- Experience overseeing penetration testing, adversary simulations, and threat intelligence programs utilizing frameworks such as MITRE ATT&CK, MITRE ATLAS, and OWASP guidance.
- Professional certifications such as CISSP, CCSP, CISM, CRISC, CCISO, or HITRUST CCSFP.
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search