Principal IT Security Architect
$184.6k - $225.1kRingCentral, Inc
Say hello to opportunities. If you're looking to be part of what's next in communication, you're in the right place. At RingCentral, we believe the best customer experiences happen when humans and AI work together. Our agentic voice AI portfolio-AIR, AVA, and ACE-brings together automation, assistance, and insights across the entire conversation lifecycle. The result? More seamless, intelligent experiences for businesses everywhere. With $2.5B+ in ARR and $250M invested in R&D annually, we're building the future of AI-powered business communications. RingCentral IT is hiring a deeply technical Principal Security Architect to determine whether our enterprise, cloud, identity, network, application, and data controls will withstand a capable modern attacker-and to prove it with evidence.This is not a governance-only or advisory role. You will live inside the admin consoles of Okta, Zscaler, Google Workspace, and Microsoft 365, reconstruct how our environment and security tools are configured, challenge inherited assumptions and exceptions, identify exploitable attack paths, and personally architect, prototype, automate, and drive durable fixes into production You will combine an adversary's mindset with disciplined defensive engineering. You should think in attack paths and blast radius rather than control checklists, and be equally comfortable running a token-theft or consent-phishing simulation against our own tenants and then writing the Conditional Access policy, Okta authentication policy, or Drive sharing restriction that kills it. What You Will Own Identity as the security perimeter (Okta). End-to-end review and hardening of our Okta tenant: global session and app-level authentication policies, MFA factor strength and phishing-resistant enrollment (FastPass / WebAuthn), device trust, admin role delegation and standing-privilege reduction, API token and service-app scope hygiene, SCIM lifecycle provisioning and - critically - deprovisioning, Okta Workflows, ThreatInsight, and System Log streaming into our SIEM. You will hunt shadow admins, orphaned integrations, over-scoped OAuth grants, and legacy authentication paths. Zero trust network access (Zscaler). Architecture and configuration review across ZIA and ZPA: SSL inspection coverage and the bypass list (where real exposure usually hides), URL and cloud-app control, DNS and firewall policy, inline DLP, sandboxing, ZPA application segments and access policies scoped to least privilege, posture profiles, App Connector and Browser Access configuration, Client Connector forwarding profiles and PAC logic, and admin RBAC on the Zscaler tenant itself. SaaS data sharing and exposure (Google Workspace + Microsoft 365 / OneDrive / SharePoint). Exhaustive audit and remediation of external sharing: link-sharing defaults and expiry, target audiences, shared drives and site-level overrides, guest and unmanaged-device access, sensitivity labels and Purview / Google DLP rules, Entra ID Conditional Access, third-party OAuth app consent and API access controls, service account key sprawl and domain-wide delegation, and Alert Center / Defender for Cloud Apps signal quality. You will quantify how much company data is currently shared to "anyone with the link" - and then reduce it. Adversary-led validation. Design and run authorized, scoped tests against our own environment: adversary-in-the-middle session hijacking, MFA fatigue and downgrade paths, OAuth consent phishing, help-desk social-engineering resistance, SaaS-to-SaaS integration abuse, and identity attack-path mapping. Translate every finding into a specific configuration change with an owner and a date, then purple-team the result to confirm detection actually fired. Architecture, standards, and evidence. Set the target-state reference architecture for identity and SaaS security, define hardening baselines against CIS Benchmarks, CISA SCuBA, and NIST SP 800-207, instrument continuous configuration-drift detection, and produce the evidence auditors, customers, and executives ask for. You will brief the CIO and security leadership on residual risk in plain language. Every material finding must result in a root‑cause analysis, durable remediation, accountable owner, deadline, compensating control when necessary, and evidence that the fix worked.
REQUIRED QUALIFICATIONS
10+ years in security engineering or architecture, a substantial portion of it hands‑on‑keyboard in production. Certifications do not substitute for demonstrated configuration depth. Expert‑level, in‑console administration of Okta - you can explain policy evaluation order, the difference between a global session policy and an app authentication policy, and how you would detect a maliciously created app integration. Production experience administering Zscaler ZIA and ZPA, including the operational tradeoffs of SSL inspection, bypass exceptions, and least‑privilege application segmentation. Deep working knowledge of both Google Workspace Admin and Microsoft 365 / Entra ID administration - specifically the sharing, external-collaboration, OAuth app‑consent, and DLP surfaces. Demonstrated offensive capability against identity and SaaS environments. You have found real, exploitable misconfigurations, not just reported scanner output. Comfort with tooling such as BloodHound / AzureHound, ROADrecon, GraphRunner, and Burp Suite. Fluency in SAML, OIDC, OAuth 2.0, and SCIM - and the specific ways each is abused. Working knowledge of MITRE ATT&CK, including the cloud and SaaS matrices. Automation ability: Python or PowerShell against the Okta, Microsoft Graph, Google Admin SDK, and Zscaler APIs. This role is not survivable by clicking through consoles alone. The judgment to push a change through change control, quantify user‑experience impact, and defend the decision to a skeptical business owner. You will be told "that will break workflows." You need to be right, and you need to bring the data.PREFERRED
OSCP, GPEN, GCPN, GWAPT, or CRTO; Okta Certified Administrator or Consultant; Zscaler ZIA/ZPA certification. CISSP or CCSP is welcome but is not what we are screening for. Experience deploying an SSPM or CASB platform (Obsidian, AppOmni, Netskope, Defender for Cloud Apps) to automate posture review at scale. Experience securing AI and agentic tooling: OAuth scopes granted to AI assistants, data‑access boundaries, and enterprise copilot / agent deployments. Detection engineering against identity telemetry in a SIEM (Splunk, Sentinel, or equivalent), and prior work in a SOX or SOC 2 audited environment.HOW WE WILL EVALUATE YOU
Expect a practical loop, not a trivia quiz: a live walkthrough of how you would audit a tenant you have never seen, a written attack‑path analysis of a realistic misconfiguration scenario, and a session where you defend a hardening recommendation against business pushback. Come prepared to discuss a specific misconfiguration you personally found and closed - and what it would have cost had you not. What we offer: Comprehensive medical, dental, vision, disability, life insurance Health Savings Account (HSA), Flexible Spending Account (FSAs) and Commuter benefits 401K match and ESPP Paid time off and paid sick leave Paid parental and pregnancy leave Family-forming benefits (IVF, Preservation, Adoption etc.) Emergency backup care (Child/Adult/Pets) Employee Assistance Program (EAP) with counseling sessions available 24/7 Free legal services that provide legal advice, document creation and estate planning Employee bonus referral program Debt refinancing assistance Employee perks and discounts program RingCentral's work culture is the backbone of our success. And don't just take our word for it: we are recognized as a Best Place to Work by BuiltIn, the Top Work Culture by Comparably and hold local BPTW awards in every major location. Bottom line: We are committed to hiring and retaining great people because we know you power our success. About RingCentral RingCentral is a global leader in agentic voice AI-powered business communications, delivering an integrated platform for business phone, SMS, contact center, workforce engagement management, video collaboration, and messaging. As the communications layer connecting businesses and customers, RingCentral is the front door of business communication and is in the advantageous position to apply AI at every phase of the conversation journey - before, during, and after each interaction. Visit ringcentral.com to learn more. RingCentral is an equal opportunity employer that truly values diversity. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status. We are committed to providing reasonable accommodations for individuals with disabilities during our application and interview process. If you require such accommodations, please click on the following link to learn more about how we can assist you. If you are hired in Belmont, CA, the compensation range for this position is between $184,600 and $225,100 for full-time employees, in addition to eligibility for variable pay, equity, and benefits. Benefits may include, but are not limited to, health and wellness, 401k, ESPP, vacation, parental leave, and more! The salary may vary depending on your location, skills, and experience. #J-18808-Ljbffr RingCentral, Inc- RingCentral is seeking a Principal Security Architect in Belmont, CA to lead identity and SaaS security across Okta, Google Workspace, and Microsoft 365. You will architect, test, and harden configurations, hunt for misconfigurations, and translate findings into durable...Principal
$293.8k - $343.34k
...create safer, more civil shared experiences for everyone.As a Principal Enterprise Security Engineer, you will advance Roblox’s Enterprise Security... ...Governance, and Supply Chain Security.Collaborate closely with IT, engineering, DevOps, and business stakeholders to...PrincipalFull timeWork experience placementH1bWork at officeLocal areaVisa sponsorshipMonday to Friday$200k - $300k
Redwood CityEngineering - Software /FT /On-siteAs the Security Architect, you will be leading all aspects of Software Security for Dexterity’s... ...ComplianceExperience working with auditors and customer InfoSec/IT teams. Strong internal and external communication skills,...Suggested- RingCentral is seeking a Principal Security Architect to own identity and SaaS security across enterprise, cloud, and collaboration tools. You will work inside Okta, Zscaler, Google Workspace, and Microsoft 365, auditing configurations, identifying exploitable paths, and...Suggested
- ...Roblox Corporation in California is seeking a Principal Security Software Engineer for the Production IAM team. You will set the technical direction for identity and access across Roblox's hybrid on-prem and cloud infrastructure, covering machine, workload, human, and...Principal
- A leading IT services company in California is looking for an Info Security Analyst to operationalize security processes and work closely with IT teams. The candidate should have strong operational process expertise and experience in public cloud security solutions like...
$385.05k
..., solving unique technical challenges at scale, and helping to create safer, more civil shared experiences for everyone.As a Principal Security Software Engineer in the Enterprise Security team, you will advance Roblox's Enterprise Security strategy by building the systems...PrincipalFull timeWork experience placementH1bWork at officeLocal areaVisa sponsorshipMonday to Friday$326.06k - $385.05k
...create safer, more civil shared experiences for everyone.As a Principal Security Software Engineer on the Production IAM team, you will set... ...Advance just-in-time, least-privilege access for engineers. Architect just-in-time, least-privilege, and break-glass access to production...PrincipalFull timeWork experience placementH1bWork at officeLocal areaVisa sponsorshipMonday to Friday$326.06k - $385.05k
..., solving unique technical challenges at scale, and helping to create safer, more civil shared experiences for everyone.As a Principal Security Software Engineer, you will be reporting to the Manager of Application Security leading the Security Design and Review pod. You...PrincipalFull timeWork experience placementH1bWork at officeLocal areaVisa sponsorshipMonday to Friday- ...WashingtonLocation Type: HybridBusiness Unit: Business ProfessionalsFunction: TechnologyFull Time or Part Time: Full TimeApply: Security Architect for Network and Cloud will lead the design and development of the Firm's cloud network security solutions. The role-holder...Part timeWork experience placementWorldwide
$243.29k - $295.25k
...more civil shared experiences for everyone.As a Senior Enterprise Security Engineer, you will play a critical role in executing Roblox’s... ...Governance, and Supply Chain Security.Collaborate closely with IT, engineering, DevOps, and business stakeholders to integrate security...Full timeWork experience placementH1bWork at officeLocal areaVisa sponsorshipMonday to Friday$120k - $175k
Technology Cyber Security ArchitectCooley is seeking a Cyber Security Architect to join the technology team.Position summary: Cooley Technology embraces a culture of customer service excellence, and all members of the department are expected to move this agenda forward...Full timeTemporary workWork at officeFlexible hoursWeekend work$245k - $280k
...collaboration, manage the entire content lifecycle, secure critical content, and transform business... ...of our Enterprise Security team to help architect and scale the security systems that... ...role where you will partner closely with IT, infrastructure, and security teams to...Live inWork at officeImmediate startShift work3 days per week$200k - $300k
...organizations protect their people and places with an integrated, privacy-sensitive AI-powered platform that includes solutions for video security, access control, air quality sensors, alarms, intercoms, and visitor management. We’ve got serious momentum in the market: more...Full timeWork visaFlexible hoursShift work- ...Responsibilities Define the long-term security architecture and technical patterns for autonomous agents, MCP integrations, multi-turn reasoning, and multi-agent coordination. Architect and deploy runtime guardrails, semantic firewalls, intent verification filters...Full timeTemporary workWork at officeFlexible hours
$196.75k - $243.29k
...solving unique technical challenges at scale, and helping to create safer, more civil shared experiences for everyone.As an Offensive Security Engineer within the Detection and Response team (DART), you'll engage in the offensive security assessments that strengthen our...Full timeWork experience placementH1bWork at officeLocal areaVisa sponsorshipMonday to Friday$115k - $140k
...teamwork come together to support the most exciting missions in the world!Company Overview Qualys is a leading provider of cloud-based security and compliance solutions, processing vast amounts of data to help our global customers secure their networks, devices, and...Full timeFlexible hours$198k - $273k
...CAInformation Technology and Applications - Enterprise Security /Full-time /HybridZoox's Network Security team architects and defends the digital borders of the company —... ...), partnering closely with Network Engineering, IT, Product Security, and Software Engineering teams....Full timeTemporary workRemote workRelocation package- A recognized tech company in Redwood City is seeking a Software Engineer III to design and implement secure authentication and authorization systems. The ideal candidate has over 3 years of experience with Java or PHP, solid understanding of modern security practices,...Work at office3 days per week
- Job TitleFor roles that are based at our headquarters in San Mateo, CA: The starting base pay for this position is as shown below. The actual base pay is dependent upon a variety of job-related factors such as professional background, training, work experience, location...Full timeWork experience placement
- ...Job Title: Cloud Security Architect FedRAMP Location Palo Alto, CA (Remote Eligible) Experience Level: Mid-Senior (15+ years) Employment Type:... ...requirements with security best practices. Educate engineering and IT teams on compliance-driven architecture and federal security...Contract workRemote work
$216.68k - $269.17k
...challenges at scale, and helping to create safer, more civil shared experiences for everyone.Be a part of Roblox Corporation as a Senior Security Software Engineer in Vulnerability Management. Join our dedicated team to ensure the security of our platform. You will work on...Full timeWork experience placementH1bWork at officeLocal areaVisa sponsorshipMonday to Friday- ...including Home, Search, Matchmaking, and Notifications that guide navigation across the metaverse. What Will You Do? As a Senior / Principal Data Scientist – Discovery at Roblox, you will lead the development of ML solutions and ranking frameworks that power discovery...Principal
$233.57k - $269.17k
...solving unique technical challenges at scale, and helping to create safer, more civil shared experiences for everyone.As a Senior Security Software Engineer for Infrastructure Security you will be a part of the Information Security organization and report to the Senior...Full timeWork experience placementH1bWork at officeLocal areaVisa sponsorshipMonday to Friday- ...Hiring: Network Security EngineerLocation: Foster City, CAWork Mode: 5 Days Onsite (Local Candidates Only)Travel: Bay Area travel requiredInterview: Face-to-Face (1st Round)Visa: NO CPTKey Skills Required:6+ years of Network Security Engineering experienceNext Generation...Local areaRemote work
$192k - $260k
...Role: We are looking for a curious, smart, and "learn it all" Architect with proven experience and a passion for designing transformative... ...Engineering, Product Management, Data Ops, and Information Security teams. You will be responsible for supporting engagements...PrincipalFull timeWork at officeLocal areaRemote workWorldwideFlexible hours- ...Job Title: (IT Security Engineer) Data Protection Security Engineer - Netskope Lead Job Duration: 06+ months contract with possible extension. Location Foster City, CA 94404 Pay Range $90.00 - 105.00/hour on W2 Work Type Hybrid Job description...Contract workWork at office
$251.09k - $326.06k
...more civil shared experiences for everyone.As a Senior Cloud Security Engineer, you will define and implement the security strategy... ...deploy faster and safer.Engineer Self-Healing Infrastructure: Architect and scale systems that monitor our cloud posture and automatically...Full timeWork experience placementH1bWork at officeLocal areaVisa sponsorshipMonday to Friday$180.6k - $289.3k
...Visa and do work that matters - to you, to your community, and to the world. Progress starts with you.Job DescriptionVisa’s Cyber Security team is seeking a Cyber Security Engineer to design, build, and operate large‑scale, cloud‑native and AI‑driven security platforms...Full timePart timeWork experience placementWork at officeLocal areaRemote work$174k - $237k
...City, CAInformation Technology and Applications - Enterprise Security /Full-time /HybridWe are seeking a Senior Information Security... ...stare at a pane of glass watching alerts roll in; you will be the architect behind how those alerts are generated, triaged, and automated....Full timeTemporary workRelocation package
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Principal IT Security Architect. Be the first to apply!


