We are seeking a Principal Security Architect to lead the design, review, and evolution of secure technology solutions across cloud, hybrid, and on-premises environments. This individual will serve as a trusted cybersecurity leader, driving architecture strategy, advancing IAM, EDR, Vulnerability Management, and Zero Trust initiatives, and partnering with cross-functional teams to strengthen the organization's security posture and reduce risk.
This role is based out of our corporate headquarters in Raleigh, NC (4 days in office, 1 day remote)
Key Responsibilities
- Develop and maintain cybersecurity architecture strategy, roadmaps, reference architectures, standards, patterns, and artifacts aligned with business drivers, technology strategy, and the evolving threat landscape (including multi-cloud and on-premises).
- Lead architecture design and formal security architecture reviews for new solutions, major changes, cloud migrations, applications, infrastructure, and third-party integrations—identifying risks and recommending practical mitigations.
- Architect and guide solutions across core verticals:
- Identity & Access Management (IAM) — Zero Trust principles, SSO/MFA, RBAC/least privilege, identity lifecycle, privileged access, and federation.
- Endpoint Detection & Response (EDR/XDR) and related endpoint protection controls.
- Vulnerability Management (VM) — scanning architecture, prioritization, remediation workflows, and integration with broader risk processes.
- Broader security controls including network segmentation, encryption, logging/detection, cloud security posture, and secure configurations.
- Provide hands-on engineering input: evaluate tools/platforms, support proofs-of-concept, guide implementation and integration, validate controls, and contribute to automation/scripting where appropriate.
- Conduct threat modeling, risk assessments, and gap analyses; translate findings into actionable architecture recommendations and control improvements.
- Serve as a trusted advisor and liaison—clearly communicating technical risks, trade-offs, and solutions to both technical and non-technical audiences; influence decision-making and continuous improvement.
- Stay current with emerging threats, technologies, and frameworks (NIST, ISO 27001, MITRE ATT&CK, Zero Trust, etc.); evaluate and recommend enhancements to security posture and processes.
Required Qualifications & Experience
- 8–12+ years in cybersecurity with substantial architecture and engineering experience (strong hands-on background preferred over pure strategy roles).
- Demonstrated depth across multiple domains: IAM, EDR/endpoint security, vulnerability management, and security architecture design + formal review processes.
- Proven ability to solve complex, ambiguous technical and organizational problems in large or complex environments and to interface effectively across security, IT/engineering, cloud, and business teams.
- Solid experience with security architecture principles, frameworks, and practices (Zero Trust, NIST CSF/800-53, ISO 27001, MITRE ATT&CK, threat modeling methodologies such as STRIDE).
- Hands-on familiarity with relevant technologies and platforms (examples: identity platforms such as Okta/Entra ID, EDR solutions.
- Experience designing and reviewing architectures for hybrid/multi-cloud and on-premises environments.
- Excellent communication, stakeholder management, and collaboration skills—ability to translate complex topics and drive alignment.
Preferred Qualifications
- Experience in retail, large distributed enterprises, or highly regulated environments.
- Leadership or principal-level individual contributor experience guiding technical direction without direct people management (or light leadership of architecture efforts).
California Residents click below for Privacy Notice:
Skills Required
- 8-12+ years in cybersecurity with substantial architecture and engineering experience (hands-on background preferred)
- Depth across IAM, EDR/endpoint security, and vulnerability management
- Experience with security architecture design and formal security architecture review processes
- Experience designing and reviewing architectures for hybrid/multi-cloud and on-premises environments
- Familiarity with security frameworks and methodologies (Zero Trust, NIST CSF/800-53, ISO 27001, MITRE ATT&CK, STRIDE)
- Hands-on familiarity with identity platforms and endpoint security technologies (examples: Okta, Entra ID, EDR solutions)
- Ability to solve complex technical and organizational problems and interface across security, IT/engineering, cloud, and business teams
- Excellent communication, stakeholder management, and collaboration skills
- Based out of corporate headquarters in Raleigh, NC (4 days in office, 1 day remote)
- Experience in retail, large distributed enterprises, or highly regulated environments
- Leadership or principal-level individual contributor experience guiding technical direction without direct people management
Advance Auto Parts Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Advance Auto Parts and has not been reviewed or approved by Advance Auto Parts.
-
Retirement Support — Benefits are described as including a 401(k) plan with company matching, which is repeatedly positioned as a notable strength. Retirement tools like HSAs/FSAs and related financial protections (life and disability coverage) further reinforce the sense of baseline financial support.
-
Healthcare Strength — Health coverage is presented as broad, including medical, prescription, dental, and vision options, with additional supplemental medical plans. Eligibility beginning shortly after hire for full-time roles is framed as a practical advantage for accessing coverage earlier in tenure.
-
Leave & Time Off Breadth — Paid time off is described as accruing and increasing with tenure, and parental leave is included among the offerings. Flexible PTO for longer-tenured employees is positioned as an added offset for a subset of roles.
Advance Auto Parts Insights
What We Do
Advance Auto Parts, Inc. is a leading automotive aftermarket parts provider that serves both professional installer and do-it-yourself customers. As of January 3, 2026, Advance operated 4,305 stores primarily within the United States, with additional locations in Canada, Puerto Rico and the U.S. Virgin Islands. The Company also served 809 independently owned Carquest branded stores across these locations in addition to Mexico and various Caribbean islands. Additional information about Advance, including employment opportunities, customer services, and online shopping for parts, accessories and other offerings can be found at www.AdvanceAutoParts.com.









