Principal Security Architect

Bank of America Bank of America · Banking · Chicago, IL +2

This role is for a Principal Security Architect at Bank of America, focusing on defining, designing, and delivering scalable security architectures and capabilities. It involves shaping enterprise security architecture, influencing technology strategy, and driving execution across multiple engineering initiatives within the Cyber Security Technology (CST) organization. The role requires broad expertise in information security technologies, processes, and control frameworks, with a strong ability to research and evaluate emerging technologies and align security capabilities with regulatory frameworks.

What you'd actually do

  1. Define solution intent and architectural vision in partnership with senior business and technology leaders, ensuring alignment with GIS policy and enterprise standards.
  2. Collaborate with senior architects and product managers to develop and execute security roadmaps that deliver on strategic outcomes.
  3. Advise senior executives on security risks, technology gaps, and architectural trade-offs; develop secure solutions through domain expertise, experimentation, and proofs of concept.
  4. Lead the evolution of enterprise-level security architecture, ensuring designs are secure, resilient, and adaptable to emerging requirements.
  5. Partner with governance and control owners to resolve policy issues and strengthen standards and best practices.

Skills

Required

  • 10+ years of experience in security architecture
  • some people management experience
  • Broad expertise across information security technologies, processes, and control frameworks
  • Strong ability to research, evaluate, and recommend emerging technologies and strategies
  • Demonstrated experience aligning security capabilities with regulatory, legal, and industry frameworks (e.g., NIST CSF)
  • Familiarity with common security bodies of knowledge (e.g., NIST, ISACA, SANS, ISC2)
  • Proven ability to operate effectively in a complex, globally distributed organization
  • Exceptional communication, stakeholder engagement, and executive influencing skills
  • Experience working in agile and product-based delivery models, with a track record of successful transformation
  • Experience evaluating vendors and supporting deployment and integration decisions

Nice to have

  • Automation
  • Influence
  • Result Orientation
  • Stakeholder Management
  • Technical Strategy Development
  • Application Development
  • Architecture
  • Business Acumen
  • Risk Management
  • Solution Design
  • Agile Practices
  • Analytical Thinking
  • Collaboration
  • Data Management
  • Solution Delivery Process

What the JD emphasized

  • security architecture
  • security roadmaps
  • enterprise security architecture
  • emerging technologies
  • regulatory