Principal Applications Security Architect
- ZoomInfo
- AI
- Machine Learning
- IAM
- Zero Trust
- Incident Response
- Risk Management
- CISSP
- CCSP
- CISM
- AWS Security Specialty
- AWS
- GCP
- Azure
- OWASP
ZoomInfo is where careers accelerate. We move fast, think boldly, and empower you to do the best work of your life. You’ll be surrounded by teammates who care deeply, challenge each other, and celebrate wins. With tools that amplify your impact and a culture that backs your ambition, you won’t just contribute. You’ll make things happen–fast.
Position Overview:
This role is responsible for defining and advancing ZoomInfo’s security architecture across cloud platforms, applications, data, identity, networks, corporate technology, and AI-enabled systems. The Security Architect partners closely with Engineering, Infrastructure, Product, IT, Privacy, Data, and other stakeholders to embed security into technical design decisions and deliver secure, scalable, and resilient solutions.
The role provides technical leadership for complex security and risk decisions, including cloud and application architecture, identity and access management, data protection, network segmentation, API security, encryption and key management, logging and detection capabilities, secure software delivery, and AI security and governance. This includes assessing AI and machine-learning solutions, model and data risks, third-party AI services, prompt and data-handling risks, access controls, and the security implications of AI-enabled products and internal use cases. Working collaboratively with delivery teams, the Security Architect translates security, privacy, compliance, and responsible AI requirements into practical architecture patterns, technical standards, and implementation guidance that support business objectives while managing risk.
Â
What you will do:
Â
Enterprise Security Architecture & Strategy
- Define and evolve the enterprise security architecture, principles, reference architectures, security patterns, and technical standards.
- Lead architecture reviews for high-impact initiatives, new products, major platform changes, acquisitions, strategic integrations, and material technology transformations.
- Establish and maintain security design standards across cloud, application, IAM, data protection, and zero-trust networks.
- Translate security, privacy, and compliance requirements into actionable technical requirements and implementation guidance.
- Influence security roadmaps and investment decisions through expert analysis of emerging threats and technology changes.
- Create and maintain threat models, architecture risk assessments, security exception processes, and security design documentation.
Â
AI Security & Governance
- Define and promote security architecture patterns for AI-enabled products, machine-learning workloads, generative AI applications, and internal AI use cases.
- Partner with Engineering, Product, Data, Privacy, Legal, and Risk teams to assess AI threats, including prompt injection, data leakage, model abuse, insecure integrations, supply-chain risks, and unauthorized access to models or training data.
- Establish practical controls and review processes for AI systems, including data classification, model and vendor risk assessments, access management, monitoring, logging, testing, incident response, and ongoing governance.
Â
Technical Leadership & Risk Management
- Independently assess complex security risks across multi-cloud environments, applications, data platforms, identity systems, networks, endpoints, and third-party integrations.
- Design pragmatic, scalable security controls that balance risk reduction, engineering velocity, customer commitments, and regulatory obligations.
- Partner with engineering and technology leaders to resolve architectural tradeoffs, address inherited technical risk, and prioritize security investments.
- Identify systemic security issues and develop long-term remediation strategies rather than isolated findings.
- Serve as a trusted technical advisor during significant security incidents, identifying architectural contributing factors and defining durable corrective actions.
- Mentor security engineers and architects, raising the technical capability and architectural maturity of the broader Security organization.
Â
Cross-Functional Collaboration & Governance
- Create formal collaboration networks across Security, Engineering, Infrastructure, Product, Data, IT, Privacy, and Legal teams.
- Develop risk-based decision frameworks and present recommendations to senior technical and business stakeholders.
- Represent Security in formal cross-functional forums, governance bodies, customer discussions, and executive-level technical reviews.
- Drive adoption of approved security architecture standards and patterns across the organization.
- Support customer security assessments, enterprise sales engagements, and audit or regulatory requirements.
Â
What you bring:
Â
Education and Experience:
- Bachelor’s degree in Computer Science, Information Security, Engineering, or a related technical discipline, plus 8+ years of relevant experience; or Master’s degree plus 5+ years of relevant experience; or PhD with 5 years of experience; or an equivalent combination of education and experience.
- Typically requires a minimum of 12 years of related professional experience in information security, security engineering, architecture, infrastructure, or software engineering.
- Demonstrated expertise designing and implementing security architecture in complex, distributed, cloud-based environments.
- Experience evaluating ambiguous situations, synthesizing complex technical and business inputs, and developing independent, risk-based recommendations.
- Experience influencing senior engineering, product, infrastructure, and business leaders without direct authority.
- Experience developing security standards, reference designs, architectural governance processes, or enterprise-wide security programs.
- Experience in a SaaS, data platform, B2B technology, or highly regulated environment preferred.
Â
Certifications (Preferred):
- CISSP, CCSP, CISM, GIAC, AWS Security Specialty, Azure Security Engineer, Google Professional Cloud Security Engineer, or equivalent.
Â
Technical Knowledge & Skills:
Â
Security Architecture & Frameworks:
- Cloud and multi-cloud security architecture, including AWS, GCP, and Azure.
- Application and API security architecture, including OWASP Top 10 and secure SDLC practices.
- Identity and Access Management (IAM) and enterprise identity ecosystems.
- Data protection, encryption, key management, and data governance.
- Network segmentation, zero-trust architecture, and secure networking.
- Logging, monitoring, detection, and incident response integration.
- Third-party and software supply-chain security.
Â
Core Competencies:
- Ability to work independently to determine methods and procedures for new or specialized assignments.
- Expertise in addressing significant and unique issues where analysis of situations or data requires evaluation of intangibles.
- Strong independent judgment in methods, techniques, and evaluation criteria for obtaining results.
- Ability to create formal networks involving coordination among groups and contribute to company objectives in creative and effective ways.
Â
#LI-SG2
#LI-Hybrid
About us:Â
ZoomInfo (NASDAQ: GTM) is the Go-To-Market Intelligence Platform that empowers businesses to grow faster with AI-ready insights, trusted data, and advanced automation. Its solutions provide more than 35,000 companies worldwide with a complete view of their customers, making every seller their best seller.
ZoomInfo is committed to protecting your privacy when you apply for jobs with us. Please review our Job ApplicantPrivacy Notice for more details on how we handle your personal information.
ZoomInfo may use a software-based assessment as part of the recruitment process. More information about this tool, including the results of the most recent bias audit, is availablehere.
ZoomInfo is proud to be an equal opportunity employer, hiring based on qualifications, merit, and business needs, and does not discriminate based on protected status. We welcome all applicants and are committed to providing equal employment opportunities regardless of sex, race, age, color, national origin, sexual orientation, gender identity, marital status, disability status, religion, protected military or veteran status, medical condition, or any other characteristic protected by applicable law. We also consider qualified candidates with criminal histories in accordance with legal requirements.
For Massachusetts Applicants: It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability. ZoomInfo does not administer lie detector tests to applicants in any location.
Principal Applications Security Architect · ZoomInfo Technologies LLC