Eli Lilly

Principal Security Architect

Eli Lilly$163K — $297K *
US-AnywhereRemote in United States
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • Deep expertise in cloud security, application security, identity, and integration patterns.
  • Experience designing security controls for sensitive intellectual property and trade secrets.
  • Background in building and operating secure systems, security engineering, incident response, or security architecture.
  • Hands-on knowledge of one major cloud platform (AWS, Azure, or GCP), particularly around identity and access management and workload protection.
  • Ability to communicate technical risks in business terms for diverse audiences.

Responsibilities

  • Own the security architecture and risk posture for the program across multiple cloud platforms.
  • Conduct architecture reviews, threat modeling, and risk assessments.
  • Design security controls for workloads with sensitive intellectual property.
  • Develop secure cloud architecture patterns for consistent application across platforms.
  • Apply industry security standards and frameworks in threat modeling.
  • Drive risk acceptance processes and document outcomes clearly.
  • Mentor architects and engineers involved in security design and implementation.

Benefits

  • Participation in a company-sponsored 401(k) and pension plan.
  • Comprehensive medical, dental, vision, and prescription drug benefits.
  • Flexible spending accounts for healthcare and dependent care.
  • Access to life insurance and well-being programs.
  • Opportunities for company bonuses based on performance.
Full Job Description
Principal Security Architect

Main Attributes

Role summary: Security Architecture & Engineering needs a senior architect to serve as the dedicated security architect for a major strategic program. The program is cloud-heavy, built primarily on AWS with additional cloud platforms in scope, and its workloads handle trade secrets and highly sensitive intellectual property. This person owns the security architecture end to end and is the definitive technical voice on cloud and application security for the program.

Qualifications: Deep security expertise across cloud, application security, identity, and integration patterns. Experience designing controls for workloads handling trade secrets or sensitive intellectual property. Background is open-building and operating secure systems, security engineering, incident response, and security architecture are all relevant paths, provided the depth supports sound judgment on real designs.

Key responsibilities: Own the security architecture and risk posture for the assigned program; lead architecture reviews, threat modeling, and risk assessments; drive risk acceptance where residual risk remains; and develop reference architectures, design patterns, and security guidance from recurring requirements.

Collaboration: This role works directly with program leadership, engineering teams, and partners across Security Architecture & Engineering, Tech[redacted], privacy, legal, and audit.

What You'll Be Doing

As Principal Security Architect on the Security Architecture & Engineering team, you will be the dedicated security architect for a major strategic program built primarily on AWS, with workloads handling trade secrets and highly sensitive intellectual property. You will own its security architecture across cloud platforms, data flows, identity, and third-party integrations, and lead architecture reviews, threat modeling, and risk assessments. You will develop reference architectures and design patterns that scale across the program, provide technical direction to engineers supporting the work, and ensure technology is deployed securely and in alignment with enterprise security standards.

How You'll Succeed

Technical authority: You will be senior enough to be taken seriously by experienced engineering leaders and technical enough to demonstrate why a proposed design does not hold up-and to show teams a viable secure alternative.

Cloud security depth: You will bring hands-on cloud security architecture expertise-identity and access management, network architecture, workload protection, encryption and key management, and posture management-with enough breadth to design consistently across a multi-cloud environment.

Protecting sensitive intellectual property: You will design and review controls for workloads handling trade secrets, reasoning about segmentation, access boundaries, egress paths, encryption and key management, monitoring, and third-party exposure, and holding designs to a standard appropriate to what they protect.

Security built in early: You will engage at design time rather than at the end, grounded in a strong understanding of secure application development and the secure software development lifecycle, so security is built in rather than bolted on.

Risk evaluation and mitigation: You will evaluate technical security risk, design mitigations appropriate to the exposure, and communicate both the risk and the recommended approach clearly to technical and non-technical audiences.

Key Responsibilities
  • Own the security architecture and risk posture for an assigned strategic program spanning cloud platforms, data flows, identity, and third-party integrations.
  • Conduct architecture and design reviews, threat modeling, and risk assessments across cloud platforms, application components, identity, and integrations.
  • Design and review controls for workloads handling trade secrets and highly sensitive intellectual property, covering segmentation, access boundaries, egress controls, encryption and key management, and monitoring.
  • Establish secure cloud architecture patterns and extend them consistently across the cloud platforms in scope.
  • Apply threat modeling frameworks alongside recognized industry security standards, frameworks, and best practices when evaluating designs and documenting technical guidance.
  • Perform threat analysis and modeling to enable business and technical partners to deliver secure solutions integrated with the secure development and operations lifecycle.
  • Drive risk acceptance where residual risk cannot be eliminated, framing the decision accurately, securing approvals, and documenting the outcome.
  • Develop reference architectures, design patterns, and security guidance from recurring requirements, and partner across Security Architecture & Engineering to bring the right expertise into engagements.
  • Provide technical leadership and mentorship to architects and engineers supporting the program.


What You Should Bring
  • Security depth sufficient to make sound judgment calls on real designs. Backgrounds vary and all of the following are relevant paths: building and operating secure systems, security engineering, incident response, penetration testing, or security architecture.
  • Depth in at least one major cloud platform (AWS, Azure, or GCP), covering identity and access management, network architecture, workload protection, encryption and key management, and cloud security posture management, with the ability to apply that depth across additional providers.
  • Demonstrated experience securing workloads handling trade secrets or highly sensitive intellectual property, including segmentation, access boundaries, and egress controls.
  • Strong understanding of secure application development and the secure software development lifecycle, including threat mitigation techniques.
  • Strong experience in threat analysis and modeling, and a solid understanding of cybersecurity engineering and operations.
  • Exceptional critical thinking and analytical reasoning, with proven ability to define and influence security strategy while also guiding tactical work.
  • Ability to translate technical risk into clear business language and to document risk decisions in a form that holds up to audit and executive review.
  • Excellent communication and presentation skills, with the ability to adapt messaging for technical and non-technical audiences.
  • Experience developing and documenting architecture references, security guidelines, and standards, and mentoring more junior architects and engineers.


Your Basic Qualifications
  • High School Diploma/equivalent with 4+ years of experience in Cyber Security, Information Technology, or a related field.
  • 8+ years of professional experience across security, software engineering,
  • Qualified applicants must be authorized to work in the United States on a full-time basis. Lilly will not provide support for or sponsor work authorization or visas for this role, including but not limited to F-1 CPT, F-1 OPT, F-1 STEM OPT, J-1, H-1B, TN, O-1, E-3, H-1B1, or L-1.
    cloud engineering, or a combination, including hands-on cloud security work.

Actual compensation will depend on a candidate's education, experience, skills, and geographic location. The anticipated wage for this position is
$163,500 - $297,000

Full-time equivalent employees also will be eligible for a company bonus (depending, in part, on company and individual performance). In addition, Lilly offers a comprehensive benefit program to eligible employees, including eligibility to participate in a company-sponsored 401(k); pension; vacation benefits; eligibility for medical, dental, vision and prescription drug benefits; flexible benefits (e.g., healthcare and/or dependent day care flexible spending accounts); life insurance and death benefits; certain time off and leave of absence benefits; and well-being benefits (e.g., employee assistance program, fitness benefits, and employee clubs and activities).Lilly reserves the right to amend, modify, or terminate its compensation and benefit programs in its sole discretion and Lilly's compensation practices and guidelines will apply regarding the details of any promotion or transfer of Lilly employees.

#WeAreLilly

About Eli Lilly

ICOS Corporation is a biotechnology company that engages in the discovery, development, and commercialization of therapeutic products. It is engaged in the commercialization of treatments for unmet medical conditions, such as benign prostatic hyperplasia, hypertension, pulmonary arterial hypertension, cancer, and inflammatory diseases. It is the developer of a treatment known as Cialis (tadalafil), a product for the treatment of erectile dysfunction through its joint venture with Eli Lilly and Company in North America and Europe. It is also engaged in contract manufacturing services for third parties. It is in a strategic alliance with Solvay Pharmaceuticals, Inc. ICOS Corporation was established in 1989, based in Bothell, Washington. It is currently operated by Eli Lilly and Company.

Eli Lilly Careers

Joining Eli Lilly offers an unparalleled opportunity to become part of a leading global team dedicated to creating a healthier future. As a company revered for its commitment to innovation and leadership in the pharmaceutical industry, Eli Lilly is where your professional journey can flourish. Work You’ll Do At Eli Lilly, we are passionate about transforming patient care and advancing medical innovation. Our team at Eli Lilly is at the forefront of developing groundbreaking solutions in healthcare. By joining us, you will collaborate with some of the brightest minds in the industry, using cutting-edge technology to make real-world impacts. Lead with Innovation and Leadership Eli Lilly stands out in the marketplace by integrating deep industry expertise with robust research and development efforts. We are looking for professionals who are eager to drive change and lead the way in developing therapeutic breakthroughs. Explore Job Opportunities and Growth Eli Lilly offers a variety of career paths, including full-time positions and internships, across multiple functions such as research, marketing, IT, and sales. Whether you are a seasoned professional or a recent graduate, Eli Lilly provides an environment that promotes career growth and learning opportunities. Our commitment to diversity and leadership training ensures that every employee can achieve their potential. Be Part of Our Team Our team at Eli Lilly is committed to excellence and driven by a mission to improve lives. Employees enjoy a supportive culture that values collaboration, creativity, and diversity. We believe that a diverse workforce fosters innovation and helps us better connect with the communities we serve. Benefits and Culture Eli Lilly is dedicated to supporting our employees, offering competitive benefits, wellness programs, and comprehensive health care. Our culture is built on a foundation of respect, integrity, and quality, making Eli Lilly not just a great place to work, but a community to grow with. Networking and Professional Development Eli Lilly encourages continuous professional development and networking. With access to various training programs and mentorship opportunities, employees can enhance their skills and advance their careers. Our leadership is committed to nurturing talent through effective training and development strategies. Join Our Team Discover the exciting job opportunities at Eli Lilly by exploring open positions that match your skills and interests. We are continuously hiring and looking for individuals who are passionate, innovative, and ready to contribute to our mission of making life better for people around the globe. Stay Connected Keep up to date with the latest at Eli Lilly by following our careers blog. Gain insights from industry leaders and get tips on everything from crafting the perfect resume to preparing for your interview. Eli Lilly is not just a company—it's a place where you can make a difference. Explore the positions available and find out how your talents can help change the world. SEARCH ELI LILLY JOBS Stay ahead in your career with Eli Lilly, where innovation, leadership, and a commitment to diversity and growth lead the way to future advancements.
Learn more about Eli Lilly
Size
35,000 employees
Market Cap
$344.2 billion
Industry
Net Income
$6.1 billion
Founded
1876
5 Year Trend
+5.9%
Revenue
$24.5 billion
NASDAQ

Similar Jobs

More Jobs at Eli Lilly

More Information Technology Jobs

Find similar Principal Security Architect jobs: