Job Description:
At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection. We do this by driving Responsible Growth and delivering for our clients, teammates, communities and shareholders every day.
Being a Great Place to Work is core to how we drive Responsible Growth. This includes our commitment to being an inclusive workplace, attracting and developing exceptional talent, supporting our teammates’ physical, emotional, and financial wellness, recognizing and rewarding performance, and how we make an impact in the communities we serve.
Bank of America is committed to an in-office culture with specific requirements for office-based attendance and which allows for an appropriate level of flexibility for our teammates and businesses based on role-specific considerations.
At Bank of America, you can build a successful career with opportunities to learn, grow, and make an impact. Join us!
Job Description:
At Bank of America, cybersecurity is foundational to protecting the enterprise and our customers. The Principal Security Architect is a senior technical leader within the Cyber Security Technology (CST) organization and a member of the Cyber Security Product Management team. This role partners across Global Information Security (GIS) to define, design, and deliver scalable security architectures and capabilities that address evolving threats, regulatory expectations, and business priorities.
CST is a globally distributed organization responsible for cybersecurity architecture, engineering, innovation, product and technology strategy, cyber resiliency, access management, data strategy, and security control support. The Principal Security Architect plays a critical role in shaping enterprise security architecture, influencing technology strategy, and driving execution across multiple engineering initiatives.
This Principal Security Architect will provide architecture leadership and strategy across multiple domains. Prior experience working across these and related domains is preferred:
- Cloud and hybrid infrastructure.
- Zero Trust and identity.
- Application and product security.
- Data protection and cryptography.
- Security automation.
- AI security and emerging technologies.
- Cyber resilience and control modernization.
Key Responsibilities
- Define solution intent and architectural vision in partnership with senior business and technology leaders, ensuring alignment with GIS policy and enterprise standards.
- Collaborate with senior architects and product managers to develop and execute security roadmaps that deliver strategic outcomes.
- Advise senior executives on security risks, technology gaps, and architectural trade-offs; develop secure solutions through domain expertise, experimentation, and proofs of concept.
- Lead the evolution of enterprise-level security architecture, ensuring designs are secure, resilient, and adaptable to emerging requirements.
- Partner with governance and control owners to resolve policy issues and strengthen standards and best practices.
- Mentor and guide other GIS architects, driving consistency, reuse, and adoption of architectural patterns across the cybersecurity organization.
- Establish and continuously improve architectural practices, templates, and documentation.
- Work with product managers and senior technology leaders to prioritize security backlog items that enable business epics and features.
- Contribute across multiple initiatives simultaneously and adapt quickly between priorities.
- Influence resourcing, budgeting, and funding decisions through architectural input and business case development; may provide people leadership or direction for special initiatives.
How Success Is Achieved
- Promotes collaboration and builds consensus across stakeholders and senior leadership.
- Applies enterprise policy, best practices, and threat analysis to influence secure outcomes.
- Diagnoses root causes and solve complex problems in dynamic, high-pressure environments.
- Provides informed input into financial planning and investment decisions.
- Demonstrates strong ownership, accountability, and commitment to delivery.
- Maintains a clear enterprise perspective, aligning individual and team efforts to shared goals.
- Drives consistent, sustainable processes that deliver predictable, high-quality results.
- Delivers agreed business value within defined tolerances for scope, schedule, and cost.
Required Qualifications
- 10+ years of experience in security architecture, with some people management experience.
- Broad expertise across information security technologies, processes, and control frameworks and ability to work across organizational and technology boundaries.
- Strong ability to research, evaluate, and recommend emerging technologies and strategies.
- Demonstrated experience aligning security capabilities with regulatory, legal, and industry frameworks (e.g., NIST CSF).
- Familiarity with common security bodies of knowledge (e.g., NIST, ISACA, SANS, ISC2).
- Proven ability to operate effectively in a complex, globally distributed organization.
- Exceptional communication, stakeholder engagement, and executive influencing skills.
- Experience working in agile and product-based delivery models, with a track record of successful transformation.
- Experience evaluating vendors and supporting deployment and integration decisions.
Skills:
- Automation
- Influence
- Result Orientation
- Stakeholder Management
- Technical Strategy Development
- Application Development
- Architecture
- Business Acumen
- Risk Management
- Solution Design
- Agile Practices
- Analytical Thinking
- Collaboration
- Data Management
- Solution Delivery Process
Shift:
1st shift (United States of America)Hours Per Week:
40Pay Transparency details
US - CO - Denver - 1144 15th St - Denver Gis (CO9926), US - DC - Washington - 1800 K St NW - 1800 K Street NW (DC1842), US - IL - Chicago - 540 W Madison St - Bank Of America Plaza (IL4540)Pay and benefits informationPay range$156,500.00 - $230,000.00 annualized salary, offers to be determined based on experience, education and skill set.Discretionary incentive eligibleThis role is eligible to participate in the annual discretionary plan. Employees are eligible for an annual discretionary award based on their overall individual performance results and behaviors, the performance and contributions of their line of business and/or group; and the overall success of the Company.BenefitsThis role is currently benefits eligible. We provide industry-leading benefits, access to paid time off, resources and support to our employees so they can make a genuine impact and contribute to the sustainable growth of our business and the communities we serve.Skills Required
- 10+ years of experience in security architecture with some people management experience
- Broad expertise across information security technologies, processes, and control frameworks
- Experience aligning security capabilities with regulatory and industry frameworks (e.g., NIST CSF)
- Familiarity with security bodies of knowledge (NIST, ISACA, SANS, ISC2)
- Proven ability to operate effectively in a complex, globally distributed organization
- Exceptional communication, stakeholder engagement, and executive influencing skills
- Experience working in agile and product-based delivery models with transformation track record
- Experience evaluating vendors and supporting deployment and integration decisions
- Prior experience across cloud and hybrid infrastructure
- Prior experience with Zero Trust and identity
- Prior experience in application and product security
- Prior experience in data protection and cryptography
- Prior experience with security automation
- Prior experience with AI security and emerging technologies
- Prior experience in cyber resilience and control modernization
- Architectural leadership, mentoring architects, and establishing architectural practices
- Skills: automation, technical strategy development, solution design, risk management, data management, agile practices
Bank of America Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Bank of America and has not been reviewed or approved by Bank of America.
-
Healthcare Strength — Health coverage is described as comprehensive, with medical, dental, vision, virtual care via Teladoc, wellness programs, and specialized support for cancer and menopause. Wellness credits and an always‑on EAP with in‑person sessions add to the depth of care.
-
Parental & Family Support — New parents can access up to 26 weeks of leave, including 16 weeks fully paid for eligible teammates, alongside back‑up child and adult care. Family‑building resources and reimbursements (e.g., fertility, adoption, surrogacy) and a dedicated Life Event Services team extend support across life stages.
-
Equity Value & Accessibility — Broad‑based equity through the Sharing Success program, including $1B in stock to nearly all non‑executive employees in January 2026, is intended to foster an ownership mindset. Stock awards (including RSUs) are a recurring component that aligns employees’ interests with shareholders.
Bank of America Insights
What We Do
We make financial lives better for our clients and our communities through the power of every connection. Our employees are at the heart of this purpose, and are key to driving responsible growth. Every day, across the globe, our employees bring a commitment to our purpose and to driving responsible growth by living our values: deliver together, act responsibly, realize the power of our people and trust the team. A key aspect of driving responsible growth is doing so in a sustainable manner, a critical pillar of which is being a great place to work for our teammates.
Gallery








