Principal Security Architect

Posted 2 Days Ago
Be an Early Applicant
Hyderabad, Telangana, IND
In-Office
Expert/Leader
HR Tech
The Role
Defines and embeds application security architecture, standards, controls, and secure design practices across the product lifecycle. Advises engineering and product leaders on web, API, microservices, cloud, and distributed-system security. Leads architecture reviews, security tooling implementation, CI/CD integration, risk remediation, policy development, and developer enablement. Requires strong knowledge of application security frameworks, cloud-native security, identity, API design, and risk management, plus executive communication skills.
Summary Generated by Built In

TriNet is a leading provider of comprehensive human resources solutions for small to midsize businesses (SMBs). We enhance business productivity by enabling our clients to outsource their HR function to one strategic partner and allowing them to focus on operating and growing their core businesses. Our full-service HR solutions include features such as payroll processing, human capital consulting, employment law compliance and employee benefits, including health insurance, retirement plans and workers’ compensation insurance. 
TriNet has a nationwide presence and an experienced executive team. Our stock is publicly traded on the NYSE under the ticker symbol TNET. If you’re passionate about innovation and making an impact on the large SMB market, come join us as we power our clients’ business success with extraordinary HR. 
Don't meet every single requirement? Studies have shown that many potential applicants discourage themselves from applying to jobs unless they meet every single requirement. TriNet always strives to hire the most qualified candidate for a particular role, ensuring we deliver outstanding results for our small and medium-size customers. So, if you're excited about this role but your past experience doesn't align perfectly with every single qualification in the job description, nobody’s perfect – and we encourage you to apply. You may just be the right candidate for this or other roles. 
A Brief Overview
As a Principal Security Architect focused on the Product and Application Security domain, this role serves in two complementary capacities. First, it is responsible for defining and embedding security architecture, standards, and practices into TriNet’s Value Creation Process, ensuring that security is integrated by design across the product and application lifecycle. Second, the role acts as a consultative reviewer and advisor for individual solutions, providing architectural guidance, risk insight, and design feedback as they progress through the Value Creation Process. Together, these responsibilities ensure that security is both scalable as a process and applied thoughtfully to individual products.

Although you will collaborate with other security architects who have deep expertise in adjacent domains, a strong understanding of all security architecture domains is important to effectively embed security into the Value Creation Process and provide informed guidance on individual product and application designs. These domains include Identity and Access Management, Cloud Security, Endpoint Security, Security Operations, and Governance, Risk, and Compliance.

The successful candidate will be a trusted advisor to engineering and product leaders, combining deep technical expertise with strong communication skills. This role is both strategic and hands‑on, shaping how security is embedded into the Value Creation Process while also guiding architecture decisions and risk tradeoffs for individual products and applications as they are designed and delivered at scale. 
 
What you will do

  • Maintain awareness of TriNet’s product and application architectures and their alignment to the threat landscape, regulatory requirements, and business risk tolerance.
  • Act as a subject-matter expert in application security architecture, including web applications, APIs, microservices, and distributed systems.
  • Define, create, and drive adoption of secure design patterns, reference architectures, policies and standards for product and application development, and secure coding guidelines and practices.
  • Drive the integration of application security controls into the SDLC and CI/CD pipelines, including SAST, DAST, SCA, secret scanning, and IaC/PaC/SaC where applicable.
  • Partner with product and engineering teams early in the exploration and design phases to perform architecture and design reviews.
  • Coordinate integration of security services into internally and externally-facing solutions.
  • Maintain awareness of the architecture of TriNet cloud environments and their relationships to the threat landscape and compliance requirements; be able to communicate same.
  • Raise and manage the remediation of issues related to gaps in product and application security.
  • Maintain awareness of how TriNet cloud environments influence product and application security risk.
  • Contribute to TriNet security policies, standards, and guidelines related to product and application security.
  • Communicate to security and technology leadership the status of projects and issues related to product and application security.
  • Research the latest product and application tools, techniques, and leading practices.
  • Find opportunities to enhance control or process efficiency and effectiveness and provide recommendations for same. This includes enhancement through automation and developer/engineer enablement.

Education Qualifications

  • Bachelor’s degree in computer engineering, cyber security, or related field
  • Master’s degree preferred

Experience Qualifications

  • Typically 12+ years of related experience, including at least 6 years of experience in a security role, 3 years experience in a defensive application security role and working directly with software engineering teams, and 3 years of work experience as a security architect.
  • Experience designing and reviewing secure application and API architectures
  • Experience driving the implementation of application security tooling (SAST, DAST, SCA, API security, secrets management)
  • Experience integrating security into CI/CD pipelines and developer workflows
  • Experience with cloud-native application architectures (e.g., microservices, Kubernetes) as they relate to application security
  • Experience presenting and influencing at the engineering leadership and executive level
  • Experience working effectively within a globally distributed organization, collaborating across time zones, cultures, and functional teams to drive consistent security outcomes

Skills and Abilities

  • Practical knowledge of control frameworks such as the NIST CSF, Center for Internet Security’s Critical Security Controls (v8), OWASP SAMM, ASVS, and Top 10
  • Practical knowledge of the MITRE Adversarial Tactics, Techniques, and Common Knowledge (ATT&CK) framework
  • Knowledge of identity, authentication, authorization, and secure API design
  • Strong risk management mindset with the ability to balance security and business outcomes
  • Ability to communicate complex technical concepts to non-technical audiences
  • Excellent problem-solving, analytical, and collaboration skills
  • Demonstrated commitment to ethical standards and a diverse, inclusive workplace

Licenses and Certifications

  • At least one certification related to application security or secure development (e.g., CSSLP, GWEB, CASE)
  • General cloud or Kubernetes security certification preferred (e.g., CKS, CCSK, CCSP, GCSA)
  • General security certification preferred (e.g., CISSP, GIAC)
  • General security architecture certification preferred (e.g., SABSA SCF, ISSAP)
  • Cloud and container certifications are preferred but are not the primary focus

Work Environment

  • Work in a clean, pleasant, and comfortable office work setting. The work environment characteristics described here are representative of those an employee encounters while performing the essential functions of this job. Reasonable accommodations may be made to enable persons with disabilities to perform the essential functions. 
  • This position is 100% in office. 

Please Note: TriNet reserves the right to change or modify job duties and assignments at any time. The above job description is not all encompassing. Position functions and qualifications may vary depending on business necessity.

TriNet is an Equal Opportunity Employer and does not discriminate against applicants based on race, religion, color, disability, medical condition, legally protected genetic information, national origin, gender, sexual orientation, marital status, gender identity or expression, sex (including pregnancy, childbirth or related medical conditions), age, veteran status or other legally protected characteristics. Any applicant with a mental or physical disability who requires an accommodation during the application process should contact [email protected] to request such an accommodation. 

Skills Required

  • Bachelor's degree in computer engineering, cybersecurity, or a related field
  • Typically 12 or more years of related experience
  • At least 6 years of experience in a security role
  • At least 3 years of experience in defensive application security while working directly with software engineering teams
  • At least 3 years of experience as a security architect
  • Experience designing and reviewing secure application and API architectures
  • Experience implementing application security tooling, including SAST, DAST, SCA, API security, and secrets management
  • Experience integrating security into CI/CD pipelines and developer workflows
  • Experience with cloud-native application architectures, including microservices and Kubernetes, as they relate to application security
  • Experience presenting to and influencing engineering leadership and executives
  • Experience collaborating effectively within globally distributed organizations
  • At least one application security or secure development certification, such as CSSLP, GWEB, or CASE
  • Master's degree
  • Cloud or Kubernetes security certification, such as CKS, CCSK, CCSP, or GCSA
  • General security certification, such as CISSP or GIAC
  • Security architecture certification, such as SABSA SCF or ISSAP
  • Cloud and container certifications

TriNet Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about TriNet and has not been reviewed or approved by TriNet.

  • Healthcare Strength Access to major national and regional carriers (e.g., Aetna, Kaiser, select Blue plans, and UnitedHealthcare in many states) and multiple plan designs underpin strong health coverage. Consolidated enrollment tools and recognizable networks help many teams view total rewards favorably.
  • Retirement Support A TriNet-sponsored multiple-employer 401(k) administered with Empower simplifies setup and payroll integration. Fiduciary and administrative responsibilities handled by the provider add tangible value to retirement offerings.
  • Flexible Benefits A broad menu spans medical, dental, vision, life/disability, FSA/HSA, EAP, commuter, and other voluntary options with side-by-side plan comparisons and open-enrollment support. Access to add-ons like telemedicine and wellness perks in one platform expands choice for varied workforce needs.

TriNet Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Dublin, California
4,405 Employees

What We Do

TriNet (NYSE: TNET) provides small and medium-size businesses (SMBs) with full-service HR solutions tailored by industry. To free SMBs from HR complexities, TriNet offers access to human capital expertise, benefits, risk mitigation and compliance, payroll and real-time technology. From Main Street to Wall Street, TriNet empowers SMBs to focus on what matters most—growing their business.

Similar Jobs

Remote or Hybrid
2 Locations
289097 Employees
Hybrid
Hyderabad, Telangana, IND
289097 Employees

Capco Logo Capco

Liquidity reporting Compliance

Fintech • Professional Services • Consulting • Energy • Financial Services • Cybersecurity • Generative AI
Remote or Hybrid
India
6000 Employees

Micron Technology Logo Micron Technology

Staff Engineer

Artificial Intelligence • Hardware • Information Technology • Machine Learning
In-Office
Hyderabad, Telangana, IND
45000 Employees
7-7 Annually

Similar Companies Hiring

RethinkFirst Thumbnail
Telehealth • Software • Professional Services • Information Technology • HR Tech • Healthtech • Edtech
New York, NY
300 Employees
Empathy Thumbnail
Fintech • Healthtech • HR Tech • Information Technology • Financial Services • Telehealth
IL
200 Employees
Compa Thumbnail
Artificial Intelligence • HR Tech • Software • Business Intelligence
Irvine, California
75 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account