Principal Security Architect, Cloud & Infrastructure
On-siteCambridge, Massachusetts, United States
Job Summary
Own the end-to-end security architecture for CMT's mobile SDKs, APIs, data pipelines, and partner integrations, including sensitive driver and location data. Define security standards, reference architectures, and engineering guardrails for AI/ML features and tools, driving adoption across teams through threat modeling, secure design reviews, and actionable engineering requirements. Lead the AppSec and Product Security roadmap, translating risk findings into prioritized work while serving as the senior security authority for architecture reviews and technical guidance. Support customer and partner security reviews and mentor engineers on secure design.
Required Qualifications
- Bachelor's degree or equivalent years of experience and/or certification in a related field
- 7+ years of experience in security, with deep, hands-on expertise in application and product security architecture
- Proven ability to provide technical leadership and drive security initiatives through influence
- Strong software engineering foundation with experience reviewing code and system architecture
- Deep knowledge of threat modeling, secure SDLC, OWASP, authentication, cryptography, API security, and mobile security
- Experience securing products that process sensitive personal data and support regulatory requirements
- Working knowledge of AI/ML and LLM security, including secure AI adoption
- Excellent written and verbal communication skills
Desired Qualifications
- Experience with mobile SDK security, reverse engineering, and anti-tampering
- Familiarity with data-intensive architectures and ML-driven products
- Experience developing AI governance or secure AI adoption programs
- Experience in telematics, IoT, connected vehicles, fintech, or other high-trust industries
- Relevant certifications such as CSSLP, OSCP, or GWEB
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.