×
Register Here to Apply for Jobs or Post Jobs. X
More jobs:

Principal IT Security Architect

Job in Frankfort, Franklin County, Kentucky, 40601, USA
Listing for: RingCentral
Full Time position
Listed on 2026-09-08
Job specializations:
  • IT/Tech
    Cybersecurity
Salary/Wage Range or Industry Benchmark: 185000 - 225000 USD Yearly USD 185000.00 225000.00 YEAR
Job Description & How to Apply Below

Say hello to opportunities.

If you’re looking to be part of what’s next in communication, you’re in the right place.

At Ring Central, we believe the best customer experiences happen when humans and AI work together. Our agentic voice AI portfolio—AIR, AVA, and ACE—brings together automation, assistance, and insights across the entire conversation lifecycle. The result? More seamless, intelligent experiences for businesses everywhere.

With $2.5B+ in ARR and $250M invested in R&D annually, we’re building the future of AI-powered business communications.

Ring Central IT is hiring a deeply technical Principal Security Architect to determine whether our enterprise, cloud, identity, network, application, and data controls will withstand a capable modern attacker—and to prove it with evidence.

This is not a governance-only or advisory role. You will live inside the admin consoles of Okta, Zscaler, Google Workspace, and Microsoft 365, reconstruct how our environment and security tools are configured, challenge inherited assumptions and exceptions, identify exploitable attack paths, and personally architect, prototype, automate, and drive durable fixes into production

You will combine an adversary’s mindset with disciplined defensive engineering. You should think in attack paths and blast radius rather than control checklists, and be equally comfortable running a token-theft or consent-phishing simulation against our own tenants and then writing the Conditional Access policy, Okta authentication policy, or Drive sharing restriction that kills it.

What You Will Own
  • Identity as the security perimeter (Okta). End-to-end review and hardening of our Okta tenant: global session and app-level authentication policies, MFA factor strength and phishing-resistant enrollment (Fast Pass / Web Authn), device trust, admin role delegation and standing-privilege reduction, API token and service-app scope hygiene, SCIM lifecycle provisioning and — critically — deprovisioning, Okta Workflows, Threat Insight, and System Log streaming into our SIEM.

    You will hunt shadow admins, orphaned integrations, over-scoped OAuth grants, and legacy authentication paths.

  • Zero trust network access (Zscaler). Architecture and configuration review across ZIA and ZPA: SSL inspection coverage and the bypass list (where real exposure usually hides), URL and cloud-app control, DNS and firewall policy, inline DLP, sandboxing, ZPA application segments and access policies scoped to least privilege, posture profiles, App Connector and Browser Access configuration, Client Connector forwarding profiles and PAC logic, and admin RBAC on the Zscaler tenant itself.

  • SaaS data sharing and exposure (Google Workspace + Microsoft 365 / One Drive / SharePoint). Exhaustive audit and remediation of external sharing: link-sharing defaults and expiry, target audiences, shared drives and site-level overrides, guest and unmanaged-device access, sensitivity labels and Purview / Google DLP rules, Entra l Access, third-party OAuth app-consent, and API access controls, service account key sprawl and domain-wide delegation, and Alert Center / Defender for Cloud Apps signal quality.

    You will quantify how much company data is currently shared to “anyone with the link” — and then reduce it.

  • Adversary-led validation. Design and run authorized, scoped tests against our own environment: adversary-in-the-middle session hijacking, MFA fatigue and downgrade paths, OAuth consent phishing, help-desk social-engineering resistance, SaaS-to-SaaS integration abuse, and identity attack-path mapping. Translate every finding into a specific configuration change with an owner and a date, then purple-team the result to confirm detection actually fired.

  • Architecture, standards, and evidence. Set the target-state reference architecture for identity and SaaS security, define hardening baselines against CIS Benchmarks, CISA SCuBA, and NIST SP 800-207, instrument continuous configuration-drift detection, and produce the evidence auditors, customers, and executives ask for. You will brief the CIO and security leadership on residual risk in plain language.

  • Every material finding must result in a…

To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary