Principal, Security Architect

ServiceTitan ServiceTitan · Enterprise · United States · Remote

Principal Security Architect role focused on designing and enforcing secure architectures for AI-enabled product capabilities, including LLM workflows, RAG pipelines, and agentic systems. The role also involves corporate AI governance and leveraging AI for security enhancements, with a strong emphasis on guardrails, isolation, and compliance with regulations like PCI DSS, CCPA, SOC2, ISO 27001, ISO 27701, and ISO 42001.

What you'd actually do

  1. Architect and Enforce Secure Cloud Native Guardrails
  2. Security as Code and Platform Guardrails: Design and implement enforceable security controls directly into Infrastructure as Code, CI CD pipelines, and cloud control planes. Define reusable, opinionated reference patterns that bake in least privilege IAM, secure defaults, encryption standards, workload identity, network segmentation, and tenant isolation across AWS, Azure, or GCP. Ensure guardrails are preventative by default rather than detective after deployment.
  3. Secure SaaS Architecture and Isolation: Own and evolve security reference architectures for multi tenant customer facing platforms, including API security, strong service to service authentication, authorization boundaries, secrets management, and blast radius containment. Embed data level protections and isolation controls that scale with product growth.
  4. Automated Architecture Assurance: Institutionalize automated architecture reviews through policy as code, static analysis, and runtime controls that continuously validate alignment with Zero Trust principles, regulatory requirements, and internal security standards. Replace manual review bottlenecks with scalable, measurable security enforcement.
  5. Product AI Security: Design and review secure architectures for AI enabled product capabilities, including LLM workflows, RAG pipelines, agentic systems, and Model Context Protocol integrations. Define rigorous guardrails for tenant isolation, data ingestion, tool permissions, sensitive data handling, prompt safety, authorization boundaries, output controls, and auditability.

Skills

Required

  • Security Architecture
  • Cloud-native security (AWS, Azure, GCP)
  • Infrastructure as Code
  • CI/CD pipelines
  • API security
  • Zero Trust principles
  • NIST
  • ISO 27001
  • SOC2
  • PCI DSS
  • CCPA
  • LLM security
  • RAG pipeline security
  • Agentic system security
  • Prompt safety
  • Data isolation
  • Tenant isolation
  • Identity and Access Management (IAM)
  • Endpoint security
  • Security automation

Nice to have

  • Software engineering
  • Product security
  • Enterprise architecture
  • AWS
  • Azure
  • GCP
  • macOS
  • Windows
  • Mobile platforms
  • SIEM
  • EDR
  • MDM
  • Model Context Protocol
  • ISO 27701
  • ISO 42001

What the JD emphasized

  • security architecture
  • AI enabled product capabilities
  • LLM workflows
  • RAG pipelines
  • agentic systems
  • guardrails
  • tenant isolation
  • data ingestion
  • tool permissions
  • prompt safety
  • authorization boundaries
  • output controls
  • auditability
  • PCI DSS
  • CCPA
  • SOC2
  • ISO 27001
  • ISO 27701
  • ISO 42001
  • Zero Trust principles
  • regulatory requirements
  • internal security standards

Other signals

  • AI enabled product capabilities
  • LLM workflows
  • RAG pipelines
  • agentic systems
  • AI Driven Security