Logo for Wholesail Networks

Principal Architect, Technology – Enterprise Security

Role overview

Qualifications

  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a closely related field
  • 10+ years of progressive experience in security architecture, information security engineering, network security, cloud security, identity security, or application security
  • Deep expertise in enterprise or network security architecture including firewall and segmentation strategy
  • Hands-on experience with IAM and PAM platforms at enterprise scale

Responsibilities

  • Define and own Ziply's enterprise security architecture including Zero Trust and network segmentation
  • Establish and maintain reference architectures, design patterns, and security standards
  • Define SIEM architecture and detection-engineering standards in partnership with Security Operations
  • Design controls addressing AI-specific risks in support of secure AI adoption

About the company

Wholesail Networks logo

Wholesail Networks

Telecommunications

Company details

IndustryTelecommunications
Company size0 - 1

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

This is a remote position.

Position Title: Principal Architect, Technology – Enterprise Security

 

Base Salary: $155,000 to $230,000 annually DOE

Bonus: Target annual bonus

Benefits: Medical, dental, vision, 401k, flexible spending account, paid sick leave and paid time off, parental leave, quarterly performance bonus, training, career growth and education reimbursement programs.

 

Ziply Fiber is a local internet service provider dedicated to elevating the connected lives of the communities we serve. We offer the fastest home internet in the nation, a refreshingly great customer experience, and affordable plans that put customers in charge. 

 

As our state-of-the-art fiber network expands, so does our need for team members who can help us grow and realize our goals.  

 

Our Company Values: 

 

  • Genuinely Caring: We treat customers and colleagues like neighbors, with empathy and full attention. 
  • Empowering You: We help customers choose what is best for them, and we support employees in implementing new ideas and solutions. 
  • Innovation and Improvement: We constantly seek ways to improve how we serve customers and each other.  
  • Earning Your Trust: We build trust through clear, honest, human communication. 

 

Job Summary

The Principal Architect, Technology - Enterprise Security is a senior individual contributor responsible for defining and advancing the enterprise security architecture and technical standards that protect Ziply Fiber's corporate systems, employee infrastructure, and business applications, as well as the network we operate on behalf of 1M+ broadband subscribers.

 

This role provides architecture-level direction across corporate and network environments — including Zero Trust strategy, threat detection and response architecture, cloud and application security, and identity and access management design. Operation of the security tooling and Security Operations Center (SOC) sits with the Security Operations function, and control governance and approval sit with Governance, Risk & Compliance (GRC). This separation of duties is deliberate and keeps architecture and design distinct from the operation and assessment of controls.

 

The successful candidate brings deep, hands-on security architecture expertise in a broadband ISP, telecommunications, or critical-infrastructure environment, and the demonstrated ability to translate business risk into technical design and to communicate security architecture to both engineering teams and executive stakeholders.

 

Essential Duties and Responsibilities: 

The Essential Duties and Responsibilities listed below are a range of duties performed by the employee and not intended to reflect all duties performed.

 

Security Architecture & Zero Trust 

·        Define and own Ziply's enterprise security architecture: network segmentation, Zero Trust Network Access (ZTNA) strategy, micro-segmentation, and identity-based access-control design across corporate and network environments. 

·        Establish the Zero Trust reference architecture and multi-year roadmap, including policy-decision and policy-enforcement point design, device-posture and conditional-access standards, and the phased migration from perimeter-based to identity-centric access. 

·        Architect firewall and perimeter strategy: next-generation firewall platform selection (Palo Alto, Fortinet, or equivalent), zone and trust-boundary design, rule-governance and change standards, and policy-lifecycle design. 

·        Define identity and access management (IAM) architecture: MFA enforcement standards, privileged access management (PAM) design, SSO and federation patterns (SAML/OIDC), directory and service-account governance, and joiner/mover/leaver control design. 

·        Design secure remote-access architecture: ZTNA/SASE platform strategy, VPN-replacement roadmap, split-tunnel and posture-check standards, and endpoint-security integration. 

·        Establish and maintain reference architectures, design patterns, and security standards that engineering and operations teams build to, evolving them as threats and technologies change. 

 

Network Security Architecture 

·        Define network security architecture for Ziply's infrastructure: out-of-band (OOB) management network design, jump-host and bastion architecture, and network-device access-control standards (TACACS+/RADIUS, role-based device access). 

·        Define enterprise DDoS-protection architecture, including coordination with the Subscriber Edge DDoS/Arbor program and definition of enterprise-facing scrubbing, remotely triggered black-hole (RTBH), and mitigation capabilities. 

·        Architect DNS security: RPZ (Response Policy Zones), DNSSEC, and DNS-over-HTTPS/TLS strategy for internal and subscriber-facing resolvers, and secure DNS/DHCP/IPAM design. 

·        Define network monitoring and anomaly-detection architecture: NetFlow/IPFIX analysis for security use cases, IDS/IPS placement and tuning standards, TLS-inspection strategy, and integration with the SIEM. 

·        Establish system-hardening baselines for network and infrastructure devices (e.g., CIS Controls, DISA STIGs, USGCB) and define secure-configuration standards for routers, switches, and firewalls. 

·        Define segmentation and trust-zone architecture separating corporate, subscriber, management/OT, and lab environments. 

 

Security Operations & Threat Detection Architecture 

·        Define SIEM architecture in partnership with Security Operations: platform strategy or optimization, log-source onboarding standards, data-retention and normalization design, and correlation and detection-rule governance standards. 

·        Define detection-engineering standards, including use-case development mapped to MITRE ATT&CK, alert-tuning and false-positive-reduction practices, and detection-coverage measurement. 

·        Define SOC tooling architecture: SOAR platform strategy, playbook-automation standards, case-management and ticketing integration, threat-intelligence integration, and escalation-workflow design. 

·        Define endpoint detection and response (EDR/XDR) architecture: platform strategy, deployment and policy standards, and integration with SIEM and SOC workflows. 

·        Define vulnerability-management architecture: authenticated and unauthenticated scanning cadence, risk-based prioritization, remediation-SLA standards, and integration with change management and asset inventory. 

·        Define the architecture supporting incident response, digital forensics, and log and evidence preservation, ensuring detection and telemetry coverage across corporate and network environments. 

 

Cloud & Application Security Architecture 

·        Define cloud security architecture and control standards across Ziply Fiber’s cloud environments, including AWS, Azure, Google Cloud, or equivalent platforms, with emphasis on cloud-native security tooling, CSPM, secure landing-zone design, account/subscription governance, and network-topology standards. 

·        Define cloud identity and workload-protection architecture: least-privilege IAM, workload identity, key and secrets management (KMS/Key Vault), and CWPP, container, and Kubernetes security standards. 

·        Define application-security architecture standards: API security and gateway design, secrets management, certificate-lifecycle and PKI management, and secure software development lifecycle (SDLC) integration (SAST/DAST/SCA and threat modeling). 

·        Architect data-protection controls: data classification, encryption at rest and in transit standards, key management, tokenization and masking, and DLP architecture for sensitive subscriber and business data. 

·        Define infrastructure-as-code and CI/CD security standards, including policy-as-code guardrails and pre-deployment security validation. 

 

Governance, Risk & Compliance Partnership 

·        Partner with GRC to translate regulatory and compliance requirements — CPNI, CALEA, FCC telecommunications security obligations, and applicable state-level requirements — into security-architecture control designs. 

·        Ensure architecture designs are documentable, auditable, and mapped to Ziply's compliance framework and to industry frameworks such as NIST CSF, ISO 27001, and CIS benchmarks. 

·        Define secure-by-design and architecture-review standards, including reference patterns and control requirements that projects must satisfy at design and review gates. 

·        Contribute security-architecture review input to the deployment-governance process owned by GRC, ensuring new network and system deployments meet architecture standards before production deployment. 

·        Maintain segregation of duties: design controls and standards without operating, grading, or approving them — operation sits with Security Operations and governance and approval sit with GRC. 

 

AI & Emerging Technology Security Architecture 

·        Define the security architecture supporting the secure and responsible adoption of artificial intelligence and machine learning across the organization, in partnership with the enterprise AI governance program. 

·        Design controls addressing AI-specific risks — model integrity, training-data protection, and defenses against prompt injection, model evasion, and data-poisoning attacks — aligned to frameworks such as NIST AI RMF and ISO/IEC 42001. 

·        Define architecture for the secure use of generative AI and AI-enabled security tooling, including data-handling, logging, and egress controls. 

·        Evaluate emerging technologies — such as post-quantum cryptography readiness and IoT/OT convergence — and define forward-looking architecture standards to address them. 

 

Other Duties 

·        Must be available to work regular business hours Pacific Standard Time. 

·        Must also be available to work on-call, evenings and weekends as needed. 

·        Performs other duties as required to support the business and evolving organization.

 

Required Qualifications:

·        High school diploma or GED.

·        Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a closely related field. Equivalent professional experience may be considered. 

·        10+ years of progressive experience across security architecture, information security engineering, network security, cloud security, identity security, application security, or related technical fields, including substantial experience defining enterprise architecture standards and influencing complex cross-functional technical decisions. 

·        Demonstrated senior independent contributor experience mentoring technical professionals, establishing architecture standards, and driving alignment across Security, Network Engineering, IT, Cloud, Application, and GRC stakeholders without direct people-management responsibility.

·        Experience in, or supporting, broadband, telecommunications, critical infrastructure, utilities, cloud, large-scale enterprise technology, or another highly regulated and network-intensive environment. 

·        Deep expertise in enterprise or network security architecture, including firewall and segmentation strategy, Zero Trust design, identity-based access controls, and security controls for complex or highly available network environments. 

·        Strong security-operations architecture experience, including SIEM/logging architecture, detection coverage, SOAR or workflow integration, telemetry onboarding, and SOC process integration; direct day-to-day SOC operations experience is not required. 

·        Hands-on experience with IAM and PAM platforms: MFA, SSO, privileged access governance, and service-account management at enterprise scale. 

·        Cloud security architecture experience in at least one major cloud platform such as AWS, Azure, or Google Cloud, with working knowledge of multi-cloud security patterns, CSPM, identity, workload protection, and secure landing-zone design. 

·        Experience designing to and implementing security frameworks such as NIST CSF, ISO 27001, or CIS benchmarks. 

·        Familiarity with telecommunications or critical-infrastructure security obligations, such as CPNI, CALEA, FCC requirements, or comparable regulatory and compliance frameworks; ability to translate requirements into technical architecture controls. 

 

Preferred Qualifications:

·        CISSP, CISM, or comparable cybersecurity certifications. 

·        Experience with SASE/SSE platforms: Zscaler, Palo Alto Prisma, or equivalent. 

·        Background in subscriber-facing security: DNS security, RPKI/ROA, and network-level abuse management for broadband operators. 

·        Familiarity with OT/ICS security in the context of critical network infrastru

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

Security Architect Related jobs

Other jobs at Wholesail Networks

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.