Principal Security Architect

Posted 8 Hours Ago
Be an Early Applicant
Cary, NC, USA
Hybrid
120K-190K Annually
Expert/Leader
Fintech • Information Technology • Insurance • Financial Services • Big Data Analytics
At MetLife, we’re a purpose-driven company that helps our customers build a more confident future.
The Role
Leads enterprise security architecture reviews for applications, platforms, cloud services, AI solutions, infrastructure, and transformation programs. Performs threat modeling, risk assessments, control evaluations, and security gap analysis. Designs reference architectures and security patterns spanning IAM, networks, devices, applications, data, cloud, SOC, GRC, and AI. Defines target-state architectures, maturity models, roadmaps, access policies, segmentation strategies, and remediation plans while influencing cross-functional stakeholders.
Summary Generated by Built In
Description and Requirements
The Team You Will Join
As part of MetLife's Global Security team, you'll work alongside world-class experts to protect MetLife, our customers and our colleagues. The team is responsible for managing cybersecurity, IT risks and vulnerabilities, physical security, and more. In this fast-paced, mission-driven environment, you'll join outstanding teammates to expand your skills, collaborate across the organization and implement innovative approaches to safeguard MetLife when it matters most. Ready to make an impact? Join us if you want to embrace the rapidly evolving environment and use transformative technology to integrate and build security into the foundation of key initiatives across MetLife.
The Opportunity
The Principal Security Architect will lead risk-based security architecture reviews and provide enterprise-grade security guidance for technology and platform initiatives submitted through the Security Architecture Review process. This role will evaluate proposed architectures, identify material risks, recommend appropriate security controls, and help teams align solutions to target-state architecture, reference patterns, and roadmaps. The successful candidate will bring deep expertise in threat modeling, security control evaluation, architecture design, identity-centric security, network segmentation, secure access, risk-based access policy design, and broad security domain knowledge across IAM, network, devices, applications, data, SOC, cloud, governance/risk/compliance, and AI. This role is expected to influence architecture decisions, develop reusable reference architectures, and support enterprise transformation through current-state assessment, maturity modeling, strategic planning, and roadmap development.
Key Responsibilities
• Lead Security Architecture Review (SAR) assessments for enterprise technology initiatives, including applications, platforms, cloud services, infrastructure, AI solutions, integrations, and major transformation programs.
• Perform threat modeling and risk assessments to identify security design gaps, control weaknesses, trust-boundary concerns, attack paths, data exposure risks, and operational impacts.
• Evaluate security controls, tools, and technologies against architecture requirements, enterprise standards, risk posture, and control effectiveness objectives.
• Design and recommend secure architecture patterns across identity, network, endpoint/device, application, data, cloud, SOC/security operations, governance/risk/compliance, and AI domains.
• Develop and maintain reusable security reference architectures, decision patterns, implementation guardrails, and design principles to accelerate secure delivery at scale.
• Provide identity-centric security architecture guidance, including authentication assurance, authorization models, privileged access, least privilege, role-based access, non-human identity considerations, and lifecycle integration.
• Advise on network segmentation, micro segmentation, secure access, zero trust access patterns, ingress/egress controls, and connectivity models for internal, internet-facing, and B2B integrations.
• Design risk-based access policies for users, workloads, devices, applications, data, and administrative functions, considering sensitivity, exposure, business criticality, and operational requirements.
• Assess current-state security architecture and define target-state architecture, transition roadmaps, maturity models, and strategic recommendations for enterprise security transformation.
• Drive integration of security architecture with the five security pillars: IAM, network, devices, applications, and data, while ensuring alignment with security automation, orchestration, monitoring, detection, and response capabilities.
• Partner with enterprise architecture, application teams, cloud/platform teams, network engineering, IAM, data protection, SOC, GRC, privacy, legal, and risk stakeholders to develop pragmatic and implementable security recommendations.
• Document architecture decisions, risks, assumptions, compensating controls, and required remediation actions clearly for technical teams, governance bodies, and leadership audiences.
Required Qualifications
  • 8- 10 years of overall experience.
  • Strong experience in security architecture, enterprise architecture, security engineering, or cyber risk roles with demonstrated responsibility for reviewing or designing complex technology solutions.
  • Demonstrated expertise in threat modeling, risk assessment, attack path analysis, trust-boundary assessment, control gap analysis, and security remediation planning.
  • Deep understanding of security architecture patterns, including identity-centric security, zero trust, least privilege, defense-in-depth, segmentation, secure access, data protection, secure integration, and secure-by-design principles.
  • Ability to evaluate security controls and technologies, determine control applicability, assess architecture fit, and provide risk-based recommendations that balance protection, usability, delivery speed, and operational feasibility.
  • Broad knowledge across IAM, network security, endpoint/device security, application security, data security, cloud security, SOC/security operations, governance/risk/compliance, and/or AI security.
  • Experience developing reference architectures, security standards, guardrails, architecture decision records, or reusable design patterns for enterprise teams.
  • Strong understanding of enterprise architecture practices, including current-state assessment, target-state architecture, roadmap planning, maturity modeling, capability modeling, and transformation leadership.

Preferred Qualifications
• Experience supporting Security Architecture Review, Architecture Review Board, technology governance, cloud governance, or risk acceptance processes in a large enterprise environment.
• Hands-on or architecture experience with identity platforms, privileged access management, conditional/risk-based access, role-based access control, federation, secrets management, and workload/non-human identity patterns.
• Experience with secure access service edge, zero trust network access, micro segmentation, API security, B2B connectivity, cloud connectivity, and secure hybrid network architecture.
• Experience with cloud-native architectures, container platforms, Kubernetes, DevSecOps pipelines, infrastructure as code, policy-as-code, vulnerability management, posture management, logging, monitoring, detection, and response integration.
• Familiarity with AI security risks and controls, including model misuse, sensitive data exposure, excessive agency, prompt injection, insecure integrations, supply chain risk, AI governance workflows, and secure AI deployment patterns.
• Experience influencing cross-functional architecture decisions and leading stakeholders toward target-state designs, standard patterns, measurable maturity improvements, and practical implementation roadmaps.
• Relevant certifications such as CISSP, CCSP, SABSA, TOGAF, Microsoft Cybersecurity Architect, cloud security certifications, or other security architecture credentials are a plus.
Location Expectation: This is a hybrid role requiring a minimum of 3 days per week in office.
The expected salary range for this position is $120 ,000 - $190,000 . This role may also be eligible for annual short-term incentive compensation and stock-based long-term incentives. All incentives and benefits are subject to the applicable plan terms.
Benefits We Offer
Our U.S. benefits address holistic well-being with programs for physical and mental health, financial wellness, and support for families. We offer a comprehensive health plan that includes medical/prescription drug and vision, dental insurance, and no-cost short- and long-term disability. We also provide company-paid life insurance and legal services, a retirement pension funded entirely by MetLife and 401(k) with employer matching, group discounts on voluntary insurance products including auto and home, pet, critical illness, hospital indemnity, and accident insurance, as well as Employee Assistance Program (EAP) and digital mental health programs, parental leave, paid time off, paid holidays, volunteer time off, tuition assistance and much more! For more information regarding MetLife's U.S. benefits, please click here .
About MetLife
Recognized on Fortune magazine's list of the "World's Most Admired Companies", Fortune World's 25 Best Workplaces™, as well as the Fortune 100 Best Companies to Work For®, MetLife, through its subsidiaries and affiliates, is one of the world's leading financial services companies; providing insurance, annuities, employee benefits and asset management to individual and institutional customers. With operations in more than 40 markets, we hold leading positions in the United States, Latin America, Asia, Europe, and the Middle East.
As part of our New Frontier strategy, MetLife is building an AI-enabled, people-centered future. We're looking for people who bring curiosity, adaptability, and a growth mindset as we use AI to enhance how we serve customers, support communities, and evolve the way work gets done. At MetLife, AI is a responsible partner that supports human judgment, creativity, and continuous improvement while helping us build trust, inclusion, and long-term value.
Our purpose is simple - to help our colleagues, customers, communities, and the world at large create a more confident future. United by purpose and guided by our core values - Win Together, Do the Right Thing, Deliver Impact Over Activity, and Think Ahead - we're inspired to transform the next century in financial services. At MetLife, it's #AllTogetherPossible . Join us!
MetLife is an Equal Opportunity Employer. All employment decisions are made without regards to race, color, national origin, religion, creed, sex (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity or expression, age, disability, marital or domestic/civil partnership status, genetic information, citizenship status (although applicants and employees must be legally authorized to work in the United States), uniformed service member or veteran status, or any other characteristic protected by applicable federal, state, or local law ("protected characteristics").
If you need an accommodation due to a disability, please email us at [email protected]. This information will be held in confidence and used only to determine an appropriate accommodation for the application process.
MetLife maintains a drug-free workplace.
This posting is for a current vacancy and is anticipated to remain open for at least 90 days from the listed posting date.
#BI-Hybrid

Skills Required

  • 8-10 years of overall experience
  • Experience in security architecture, enterprise architecture, security engineering, or cyber risk roles involving complex technology solutions
  • Expertise in threat modeling, risk assessment, attack path analysis, trust-boundary assessment, control gap analysis, and security remediation planning
  • Understanding of identity-centric security, zero trust, least privilege, defense-in-depth, segmentation, secure access, data protection, secure integration, and secure-by-design principles
  • Ability to evaluate security controls and technologies and provide risk-based recommendations
  • Broad knowledge of IAM, network security, endpoint/device security, application security, data security, cloud security, SOC/security operations, GRC, and/or AI security
  • Experience developing reference architectures, security standards, guardrails, architecture decision records, or reusable design patterns
  • Understanding of current-state assessment, target-state architecture, roadmap planning, maturity modeling, capability modeling, and transformation leadership
  • Experience supporting Security Architecture Review, Architecture Review Board, technology governance, cloud governance, or risk acceptance processes
  • Experience with identity platforms, privileged access management, conditional/risk-based access, RBAC, federation, secrets management, and workload/non-human identity
  • Experience with SASE, ZTNA, microsegmentation, API security, B2B connectivity, cloud connectivity, and secure hybrid network architecture
  • Experience with cloud-native architectures, containers, Kubernetes, DevSecOps, infrastructure as code, policy as code, vulnerability management, posture management, logging, monitoring, detection, and response integration
  • Familiarity with AI security risks, controls, governance workflows, and secure AI deployment patterns
  • Experience influencing cross-functional architecture decisions and leading stakeholders toward target-state designs and implementation roadmaps
  • Relevant certifications such as CISSP, CCSP, SABSA, TOGAF, Microsoft Cybersecurity Architect, or cloud security certifications

What the Team is Saying

Chelsea
Nick
Naren
Laura
Bill
Jing Huang
Sara Strauch
Dan Xiao
Cara Mootz
Cara Mootz
Naren Peri
Patricia Hixson
Jing Huang
Samantha Heron
Pete Clarke
Erica Provido
Rene Rivera

MetLife Compensation & Benefits Highlights

  • Retirement Support Retirement support is strengthened by a company‑funded cash‑balance pension alongside a 401(k) with company match—an uncommon combination among large U.S. employers. Pension eligibility begins after one year, reinforcing long‑term savings.
  • Healthcare Strength Health coverage spans medical, dental, vision, and prescription drugs with access to HSAs/FSAs, wellness resources, and expert second‑opinion services. Targeted programs for cancer care, family‑building, menopause, musculoskeletal issues, and diabetes/hypertension broaden the support.
  • Leave & Time Off Breadth Time away is bolstered by a minimum of 22 days of PTO for U.S. employees plus a paid Volunteer Day, and many hybrid roles receive 10 additional virtual flex days. Flexible work arrangements are also highlighted for applicable roles.

MetLife Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: New York, NY
43,000 Employees
Year Founded: 1868

What We Do

We're honored to be No. 10 on Great Place to Work's World's Best Workplaces and recognized in the Fortune 100 Best Companies to Work For® list in 2025. At MetLife, we're leading the global transformation of an industry we’ve defined for over 157 years. At MetLife, every innovation and line of code is a lifeline for our customers and their families—from victims of natural disasters to people living with disabilities and beyond. With operations in more than 40 markets and leading positions across the globe, MetLife fosters an inclusive culture where our people are energized and inspired to deliver for our customers and communities. Join our remarkable journey—one in which you help write the next century of innovation in financial services—because with MetLife, making the world a better place is All Together Possible.

Why Work With Us

At MetLife, you’ll be working for a company whose purpose is to help customers throughout their life’s journey, and often in their most critical time of need. You’ll be a part of developing leading-edge platforms that will have a lasting impact on the lives and well-being of tens of millions of customers.

Gallery

Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery

MetLife Teams

Team
Product + Tech
About our Teams

MetLife Offices

Hybrid Workspace

Employees engage in a combination of remote and on-site work.

MetLife's current workplace policies classify roles as Office, Hybrid or Virtual based on the nature of work, encouraging new ways of working together

Typical time on-site: Flexible
Company Office Image
HQNew York City, NY
Company Office Image
Pune, IN
Company Office Image
Mexico City, MX
Company Office Image
Bridgewater, NJ
Company Office Image
Cary, NC
Company Office Image
Clark Summit, PA
Company Office Image
Greenville, SC
Company Office Image
Hyderabad, IN
Company Office Image
Tampa, FL
Company Office Image
Whippany, NJ
Learn more

Similar Jobs

MetLife Logo MetLife

Architect

Fintech • Information Technology • Insurance • Financial Services • Big Data Analytics
Hybrid
Cary, NC, USA
43000 Employees
100K-165K Annually

MetLife Logo MetLife

Senior Consultant

Fintech • Information Technology • Insurance • Financial Services • Big Data Analytics
Hybrid
Cary, NC, USA
43000 Employees
105K-135K Annually

MetLife Logo MetLife

Data Engineer

Fintech • Information Technology • Insurance • Financial Services • Big Data Analytics
Hybrid
Cary, NC, USA
43000 Employees
70K-90K Annually

MetLife Logo MetLife

Customer Service Associate - 19328

Fintech • Information Technology • Insurance • Financial Services • Big Data Analytics
Remote or Hybrid
United States
43000 Employees
42K-49K Annually

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account