USA remote
Principal Software Security Architect
About this role
BeyondTrust is a place where you can bring your purpose to life through the work that you do, creating a safer world through our cyber security SaaS portfolio. Our culture of flexibility, trust, and continual learning means you will be recognized for your growth, and for the impact you make on our success. You will be surrounded by people who challenge, support, and inspire you to be the best version of yourself. The Role The Principal Software Security Architect owns security architecture for BeyondTrust's product suite end to end, including endpoint agents, thick clients, SaaS platforms, APIs, identity systems, and cloud-native services.
This is an engineering leadership role embedded within Engineering and Architecture teams in the Office of the CTO, accountable for designing security into products from first principles through to what ships and runs in production, rather than reviewing other teams' work from the outside. We operate AI-first: Claude and LLM-driven workflows are how the team performs threat modeling, secure design reviews, vulnerability analysis, and developer enablement today, and this role is expected to operate at that level from day one and help extend that practice further.
The ideal candidate brings 10+ years of hands-on software engineering and security architecture experience, deep expertise in threat modeling and attack surface reduction at scale, and practical experience applying LLM platforms to security engineering work. What You’ll Do Own end-to-end security architecture for assigned product lines, from concept through production, defining the target-state architecture and secure-by-default patterns each product builds on.
Lead threat modeling, attack surface analysis, and secure design reviews across products, platform services, endpoint agents, and cloud-native systems, driving the architectural decisions that eliminate unnecessary exposure rather than just documenting risk. Use LLM platforms (Claude, OpenAI) as core tools to scale threat analysis, abuse-case generation, architecture review, and remediation guidance, building the prompts, plugins, skills, and agent workflows that make the engineering org faster and more consistent.