Avatar for IonQ
IonQ
Actively Hiring
Building the world’s best quantum computers to solve the world’s most ecomplex problems
  • B2B
  • Public Stage
    Publicly traded company
  • Top Investors
    This company has received a significant amount of investment from top investors
  • +1

Principal Cybersecurity Architect – Network Security Posture Management

Posted: 3 months ago
Job Location
Visa Sponsorship

Not Available

RelocationNot Allowed
Hiring contact
Matthew Keesan
VP Product Development • 9 years
Brooklyn
image

About the job

Location: Onsite or Hybrid in Santa Clara / Bay Area, CA

Travel: Up to 10%

Job ID: 1560

The Role:

We are looking for a Principal Cybersecurity Architect to own the security posture strategy for our Network Security Posture Management (NSPM) platform. You’ll work at the intersection of network security, compliance, and platform engineering — defining how the platform assesses, measures, and enforces security posture across large, heterogeneous network environments.

In this role, your primary focus is designing and codifying security posture assessment rules that map network device configurations and behaviors against established security standards — and building the framework that makes it easy to onboard new standards as they emerge. You bring deep NSPM expertise, a strong understanding of network security principles, and the ability to translate complex compliance requirements into actionable, automatable rules that operate at scale across thousands of devices.

Responsibilities:

  • Design and own the security posture assessment rule framework, defining how device configurations, network behaviors, and access controls are evaluated against security standards including NIST CSF, CIS Benchmarks, ISO 27001, FISMA, and FedRAMP.
  • Build and maintain a scalable rule authoring and lifecycle management system that allows new security standards and custom organizational policies to be onboarded, versioned, and deployed without platform re-architecture.
  • Continuously monitor the evolving threat and compliance landscape — translating emerging standards, regulatory changes, and new CVEs into updated posture assessment rules that keep the platform current and defensible.
  • Define the risk scoring and prioritization model that aggregates individual posture findings into a coherent, actionable security posture score at the device, segment, and enterprise level.
  • Collaborate with platform engineering teams to ensure posture assessment rules execute efficiently at scale across large network device fleets, with well-defined APIs for rule ingestion, evaluation, and results delivery.
  • Engage with enterprise customers and internal stakeholders to understand their compliance requirements, translating them into platform capabilities and serving as the authoritative security subject matter expert for the product.
  • Partner with Product and Engineering to shape the NSPM roadmap, ensuring security posture capabilities remain ahead of the regulatory curve and deliver measurable value to network security and compliance teams.
  • Mentor engineers and security analysts on posture rule design, threat modeling, and compliance mapping, establishing rigorous review processes that ensure accuracy and defensibility of every assessment rule shipped.

Requirements:

  • 12+ years of experience in cybersecurity, network security, or security architecture, with at least 5 years in a senior or principal capacity focused on network security posture, compliance, or policy enforcement at scale.
  • Deep, hands-on experience with Network Security Posture Management (NSPM) platforms and tools, with a demonstrable track record of designing and operationalizing posture assessment rules across large enterprise networks.
  • Comprehensive knowledge of major security standards and frameworks including NIST CSF, CIS Benchmarks, ISO 27001, FISMA, and FedRAMP, with the ability to interpret control requirements and translate them into precise, automatable assessment rules.
  • Strong understanding of network device security — including firewall policy analysis, routing protocol security, access control, and configuration hardening across multi- vendor environments (Cisco, Juniper, Palo Alto, Fortinet).
  • Proven ability to operate across both strategic and technical dimensions — engaging executive stakeholders on compliance risk while working closely with engineering teams on rule design, data modeling, and platform integration.

Preferred Qualifications:

  • Industry certifications such as CISSP, CISM, CCNP Security, or equivalent credentials that demonstrate deep, validated expertise in network security and information security management.
  • Prior experience at a network security vendor, MSSP, or large enterprise security team, with direct exposure to how security posture policies are enforced across complex, multi- vendor network infrastructures.
  • Familiarity with Zero Trust architecture principles and their practical application to network segmentation, device trust, and least-privilege access enforcement in enterprise environments.
  • Experience contributing to or authoring security standards, CIS Benchmark profiles, or DISA STIGs, or participation in industry working groups focused on network security policy and compliance.
  • Understanding of CVE lifecycle management, SBOM analysis, and vulnerability correlation as they apply to network device firmware and software supply chain risk assessment.

The approximate base salary range for this position is $248,557 - $325,425. The total compensation package includes base, bonus, equity, and a range of benefit options found on our career site.

About the company

IonQ company logo

IonQ

Actively Hiring
Building the world’s best quantum computers to solve the world’s most ecomplex problems201-500 Employees
Company Size
201-500
Company Type
Technology Provider
  • B2B
  • Public Stage
    Publicly traded company
  • Top Investors
    This company has received a significant amount of investment from top investors
  • Growing fast
    Showed strong hiring growth in the past month
Learn more about IonQ image

Funding

AMOUNT RAISED
$75M
FUNDED OVER
3 rounds
Rounds
IPO
Undisclosed amount
IPO - Sep 2021+2

Perks

401(k) match
Save in our 401(k) and we'll match up to 5% (vesting over five years).
Parental leave
100% paid maternity/paternity/bonding leave for eligible employees.
Flexible time off
We believe in achieving our goals and then taking the vacation we need.
Catered lunch
We bring food in from a variety of local establishments twice a week.
University facilities
Access to UMD library, gym, and more, if based in the DC area.
Commuter benefits
Spend pre-tax dollars on public transportation or your bicycle (we provide secure, covered storage).

Similar Jobs

Nextdoor company logo
Nextdoor
Nextdoor is the private social network for your neighborhood
Instrumentl company logo
Instrumentl
The best platform for nonprofits looking to grow revenue (YC S16)
Shef company logo
Shef
Authentic dishes. Homemade. Delivered. Explore who's cooking in your neighborhood
MOLTEN Cloud company logo
MOLTEN Cloud
Multi-cloud SaaS arming digital rights holders with better operations to manage & monetize content
Archesys company logo
Archesys
Improving the government services that impact everyday lives
Sponsor a Pet company logo
Sponsor a Pet
We are a fundraising company for animal non-profits
Layer company logo
Layer
Accounting software that embeds directly within SMB NeoBanks & SMB SaaS