Principal Application Security Architect
Listed on 2026-06-18
-
IT/Tech
Cybersecurity
Job Overview
LPL's Information Security team is seeking an exceptional Principal Security Architect to engage on API project efforts in Cloud, On‑prem, and Data security architectures. The role involves working side by side with Development, Operations, Business units, and Enterprise Architecture teams to ensure our environments are secured and monitored. The right person will have a broad technical cloud security background with a focus on security design, detection, prevention, and response to threats.
Responsibilities- Secure APIs by implementing robust access control mechanisms, OAuth, JWT, and configuring API gateway security to ensure authenticated and authorized access.
- Develop reusable security design patterns addressing common cybersecurity challenges, ensuring consistency and best practices across diverse technology stacks and business domains.
- Craft clear, actionable security standards and policies, aligning them with industry best practices and regulatory requirements while ensuring adaptability to emerging technologies.
- Lead the design and innovation of security architectures, integrating advanced technologies to protect against evolving threats while enabling business agility and growth.
- Collaborate with key stakeholders to align security initiatives with business objectives, ensuring broad support and integration at all levels.
- Apply cybersecurity frameworks, network security, cloud security, identity management, and encryption, including zero‑trust architectures and secure Dev Ops practices across diverse IT environments.
- Conduct threat modeling, risk assessment, and vulnerability management; implement SIEM, log analysis, and incident response in complex enterprise settings.
- Use intelligence and analytics to identify and mitigate potential security risks proactively, reducing business impact.
- Implement and oversee a risk management framework, balancing security investments with business needs to protect assets while supporting growth and innovation.
- Secure machine learning models against adversarial attacks, ensure data privacy in AI training sets, and implement ethical AI principles in security applications.
- Develop secure AI/ML pipelines, including model integrity verification, secure feature engineering, and anomaly detection in AI‑driven systems.
- 3+ years of security architecture and API security experience, designing secure API gateways and microservices architectures.
- 8+ years of experience with information security controls, guidelines, and standards (e.g., ISO
27000 series, OWASP, CSA CCM, CIS 20 Critical Security Controls, SOX, and NIST).
- Self‑driven, yet flexible and highly adept at consulting, negotiating, communicating, consensus building, and presenting.
- Ability to remain calm under pressure while managing multiple tasks.
- Demonstrated ability to learn from mistakes and apply constructive feedback to improve performance.
- Bachelor's Degree or equivalent years of experience.
- Technical knowledge/coding skills in Java, C# .Net, Ruby, and/or Python.
- In‑depth knowledge of AWS core services (EC2, S3, IAM, VPC, security groups, ACLs, AWS Security Hub, AWS WAF, Amazon Guard Duty).
- Working knowledge of Terraform, Cloud Formation, Pulumi, and/or Ansible.
- Solid experience securing scalable web architectures and distributed systems.
- Solid understanding of malware, emerging threats, attacks, and vulnerability management.
- CCSP/Other Cloud Specific Certification, CISSP and/or GIAC are a plus.
- AI/ML security expertise; proven record securing ML models and AI pipelines in financial services.
- Proficient in OAuth, OpenID Connect, JWT, API threat modeling, and automated security testing.
$ – $
BenefitsActual base salary varies based on factors including relevant skill, prior experience, education, and geographical location. In addition, LPL offers a competitive Total Rewards package that includes 401(k) matching, health benefits, employee stock options, paid time off, volunteer time off, and more.
Application ProcessLPL will only communicate with a job applicant directly from an official email address. For questions regarding the application process, contact LPL’s Human Resources Solutions Center at .
Principals only. EOE.
#J-18808-Ljbffr(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).