Eli Lilly and Company Logo

Eli Lilly and Company

Principal Security Architect

Posted 7 Hours Ago
Be an Early Applicant
Remote
Hiring Remotely in US
164K-297K Annually
Senior level
Remote
Hiring Remotely in US
164K-297K Annually
Senior level
Own end-to-end security architecture and risk posture for a strategic, AWS-heavy program protecting trade secrets and sensitive intellectual property. Lead cloud and application security reviews, threat modeling, risk assessments, control design, and risk acceptance. Develop secure reference architectures, design patterns, standards, and guidance across cloud platforms, data flows, identity, and integrations. Provide technical leadership, mentorship, and security direction while communicating risks effectively to technical, business, audit, and executive stakeholders.
The summary above was generated by AI

At Lilly, the work is demanding because patients are waiting. We unite caring with discovery to help make life better for people around the world, knowing that every decision, every detail, and every day matters. Headquartered in Indianapolis, Indiana, our over 50,000 employees around the globe take on complex challenges to discover and deliver life-changing medicines, strengthen how health is understood and managed, and support the communities we serve. This is hard, urgent, selfless work—but it’s work worth doing. If you’re driven by purpose and ready to bring your best to work that truly matters for patients, we invite you to join us. 


Principal Security Architect

Main Attributes

Role summary: Security Architecture & Engineering needs a senior architect to serve as the dedicated security architect for a major strategic program. The program is cloud-heavy, built primarily on AWS with additional cloud platforms in scope, and its workloads handle trade secrets and highly sensitive intellectual property. This person owns the security architecture end to end and is the definitive technical voice on cloud and application security for the program.

Qualifications: Deep security expertise across cloud, application security, identity, and integration patterns. Experience designing controls for workloads handling trade secrets or sensitive intellectual property. Background is open—building and operating secure systems, security engineering, incident response, and security architecture are all relevant paths, provided the depth supports sound judgment on real designs.

Key responsibilities: Own the security architecture and risk posture for the assigned program; lead architecture reviews, threat modeling, and risk assessments; drive risk acceptance where residual risk remains; and develop reference architectures, design patterns, and security guidance from recurring requirements.

Collaboration: This role works directly with program leadership, engineering teams, and partners across Security Architecture & Engineering, Tech@Lilly, privacy, legal, and audit.

What You'll Be Doing

As Principal Security Architect on the Security Architecture & Engineering team, you will be the dedicated security architect for a major strategic program built primarily on AWS, with workloads handling trade secrets and highly sensitive intellectual property. You will own its security architecture across cloud platforms, data flows, identity, and third-party integrations, and lead architecture reviews, threat modeling, and risk assessments. You will develop reference architectures and design patterns that scale across the program, provide technical direction to engineers supporting the work, and ensure technology is deployed securely and in alignment with enterprise security standards.

How You'll Succeed

Technical authority: You will be senior enough to be taken seriously by experienced engineering leaders and technical enough to demonstrate why a proposed design does not hold up—and to show teams a viable secure alternative.

Cloud security depth: You will bring hands-on cloud security architecture expertise—identity and access management, network architecture, workload protection, encryption and key management, and posture management—with enough breadth to design consistently across a multi-cloud environment.

Protecting sensitive intellectual property: You will design and review controls for workloads handling trade secrets, reasoning about segmentation, access boundaries, egress paths, encryption and key management, monitoring, and third-party exposure, and holding designs to a standard appropriate to what they protect.

Security built in early: You will engage at design time rather than at the end, grounded in a strong understanding of secure application development and the secure software development lifecycle, so security is built in rather than bolted on.

Risk evaluation and mitigation: You will evaluate technical security risk, design mitigations appropriate to the exposure, and communicate both the risk and the recommended approach clearly to technical and non-technical audiences.

Key Responsibilities

  • Own the security architecture and risk posture for an assigned strategic program spanning cloud platforms, data flows, identity, and third-party integrations.
  • Conduct architecture and design reviews, threat modeling, and risk assessments across cloud platforms, application components, identity, and integrations.
  • Design and review controls for workloads handling trade secrets and highly sensitive intellectual property, covering segmentation, access boundaries, egress controls, encryption and key management, and monitoring.
  • Establish secure cloud architecture patterns and extend them consistently across the cloud platforms in scope.
  • Apply threat modeling frameworks alongside recognized industry security standards, frameworks, and best practices when evaluating designs and documenting technical guidance.
  • Perform threat analysis and modeling to enable business and technical partners to deliver secure solutions integrated with the secure development and operations lifecycle.
  • Drive risk acceptance where residual risk cannot be eliminated, framing the decision accurately, securing approvals, and documenting the outcome.
  • Develop reference architectures, design patterns, and security guidance from recurring requirements, and partner across Security Architecture & Engineering to bring the right expertise into engagements.
  • Provide technical leadership and mentorship to architects and engineers supporting the program.

What You Should Bring

  • Security depth sufficient to make sound judgment calls on real designs. Backgrounds vary and all of the following are relevant paths: building and operating secure systems, security engineering, incident response, penetration testing, or security architecture.
  • Depth in at least one major cloud platform (AWS, Azure, or GCP), covering identity and access management, network architecture, workload protection, encryption and key management, and cloud security posture management, with the ability to apply that depth across additional providers.
  • Demonstrated experience securing workloads handling trade secrets or highly sensitive intellectual property, including segmentation, access boundaries, and egress controls.
  • Strong understanding of secure application development and the secure software development lifecycle, including threat mitigation techniques.
  • Strong experience in threat analysis and modeling, and a solid understanding of cybersecurity engineering and operations.
  • Exceptional critical thinking and analytical reasoning, with proven ability to define and influence security strategy while also guiding tactical work.
  • Ability to translate technical risk into clear business language and to document risk decisions in a form that holds up to audit and executive review.
  • Excellent communication and presentation skills, with the ability to adapt messaging for technical and non-technical audiences.
  • Experience developing and documenting architecture references, security guidelines, and standards, and mentoring more junior architects and engineers.

Your Basic Qualifications

  • High School Diploma/equivalent with 4+ years of experience in Cyber Security, Information Technology, or a related field.
  • 8+ years of professional experience across security, software engineering,
  • Qualified applicants must be authorized to work in the United States on a full-time basis. Lilly will not provide support for or sponsor work authorization or visas for this role, including but not limited to F-1 CPT, F-1 OPT, F-1 STEM OPT, J-1, H-1B, TN, O-1, E-3, H-1B1, or L-1.

    cloud engineering, or a combination, including hands-on cloud security work.

Lilly is dedicated to helping individuals with disabilities to actively engage in the workforce, ensuring equal opportunities when vying for positions. If you require accommodation to submit a resume for a position at Lilly, please complete the accommodation request form (https://careers.lilly.com/us/en/workplace-accommodation) for further assistance. Please note this is for individuals to request an accommodation as part of the application process and any other correspondence will not receive a response.


Lilly is proud to be an EEO Employer and does not discriminate on the basis of age, race, color, religion, gender identity, sex, gender expression, sexual orientation, genetic information, ancestry, national origin, protected veteran status, disability, or any other legally protected status.


Our employee resource groups (ERGs) offer strong support networks for their members and are open to all employees. Our current groups include: Africa, Middle East, Central Asia (AMECA), Black Employees at Lilly (BE@Lilly), Chinese Culture Network (CCN), EnAble, Evolve, Lilly Indian Network (LIN), Organization of Latinx at Lilly (OLA), Pride (LGBTQ+ Allies), Veterans Leadership Network (VLN) and Women’s Initiative for Leading at Lilly (WILL).


Actual compensation will depend on a candidate’s education, experience, skills, and geographic location.  The anticipated wage for this position is

$163,500 - $297,000

Full-time equivalent employees also will be eligible for a company bonus (depending, in part, on company and individual performance). In addition, Lilly offers a comprehensive benefit program to eligible employees, including eligibility to participate in a company-sponsored 401(k); pension; vacation benefits; eligibility for medical, dental, vision and prescription drug benefits; flexible benefits (e.g., healthcare and/or dependent day care flexible spending accounts); life insurance and death benefits; certain time off and leave of absence benefits; and well-being benefits (e.g., employee assistance program, fitness benefits, and employee clubs and activities).Lilly reserves the right to amend, modify, or terminate its compensation and benefit programs in its sole discretion and Lilly’s compensation practices and guidelines will apply regarding the details of any promotion or transfer of Lilly employees.

#WeAreLilly

Eli Lilly and Company Concord, North Carolina, USA Office

1420 Concord Parkway South, Concord, NC , United States, 28027

Similar Jobs

13 Days Ago
Remote
Minnesota, USA
111K-221K Annually
Expert/Leader
111K-221K Annually
Expert/Leader
Healthtech • Logistics • Pharmaceutical
Defines and governs enterprise cybersecurity architecture across cloud, infrastructure, applications, data, AI, identity, and cyber defense. Establishes security principles, reference architectures, standards, roadmaps, and Zero Trust patterns; influences technology strategy, architecture decisions, modernization, integrations, and build-versus-buy choices. Partners with engineering, enterprise architecture, risk, legal, and business teams to implement scalable security capabilities, improve resilience, reduce architectural complexity, and address emerging threats across complex enterprise environments.
Top Skills: APIsAWSAws Well-Architected FrameworkAzureCi/CdCis ControlsCloud Security AllianceDevsecopsDlpEncryptionGCPGenerative AiGoogle Cloud Architecture FrameworkHitrustIamInfrastructure-As-CodeIso/Iec 27001Key ManagementKubernetesMachine LearningMicrosoft Azure Well-Architected FrameworkNist Cybersecurity FrameworkNist Sp 800-53Ot/IotOwaspRagSaaSServerlessTokenizationZero Trust
21 Days Ago
Remote or Hybrid
United States
162K-273K Annually
Expert/Leader
162K-273K Annually
Expert/Leader
Artificial Intelligence • Cloud • Sales • Security • Software • Cybersecurity • Data Privacy
Lead the development of SailPoint’s cybersecurity architecture practice. Create holistic and reference architectures, define security domains, develop strategic roadmaps, identify security gaps, and translate architectural concepts into viable engineering solutions. Partner with leadership to prioritize initiatives, secure funding, and operationalize the practice. The role also includes hands-on security projects, cross-functional collaboration, stakeholder influence, and mentoring architects and engineers across cloud, application, identity, and network security.
Top Skills: AgileApplication SecurityCloud SecurityEnterprise ArchitectureIdentity SecurityIsoNetwork SecurityNistSabsaSecurity Engineering
22 Days Ago
Remote or Hybrid
173K-303K Annually
Senior level
173K-303K Annually
Senior level
Artificial Intelligence • Cloud • HR Tech • Information Technology • Productivity • Software • Automation
Leads customer consulting, presales solutioning, architecture, and delivery for ServiceNow Risk, Security, and Operational Technology Management solutions. Responsibilities include scoping engagements, designing integrations with customer technology environments, advising executives, overseeing delivery teams, supporting product stakeholders, presenting solutions, creating service offerings, mentoring teams, and maintaining technical certifications. The role requires deep expertise in OT security, ITOM, regulatory frameworks, industrial protocols, network visibility, and ServiceNow platform architecture, with up to 20% annual travel.
Top Skills: BacnetC2M2Configuration Management Database (Cmdb)DiscoveryDnp3ErspanEthernet/IpHyper-VIec 60870-5-104Isa-95Isa/Iec 62443KvmModbusNerc CipNist CsfOpc Ua/DaProfinetPurdue ModelService Graph ConnectorsServicenowServicenow Certified Application Developer (Cad)Servicenow Certified Implementation Specialist (Cis)Servicenow Certified System Administrator (Csa)Servicenow Certified Technical Architect (Cta)Servicenow ItomServicenow OtmServicenow RiskServicenow SecopsSiemens S7Vmware Esxi

What you need to know about the Charlotte Tech Scene

Ranked among the hottest tech cities in 2024 by CompTIA, Charlotte is quickly cementing its place as a major U.S. tech hub. Home to more than 90,000 tech workers, the city’s ecosystem is primed for continued growth, fueled by billions in annual funding from heavyweights like Microsoft and RevTech Labs, which has created thousands of fintech jobs and made the city a go-to for tech pros looking for their next big opportunity.

Key Facts About Charlotte Tech

  • Number of Tech Workers: 90,859; 6.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lowe’s, Bank of America, TIAA, Microsoft, Honeywell
  • Key Industries: Fintech, artificial intelligence, cybersecurity, cloud computing, e-commerce
  • Funding Landscape: $3.1 billion in venture capital funding in 2024 (CED)
  • Notable Investors: Microsoft, Google, Falfurrias Management Partners, RevTech Labs Foundation
  • Research Centers and Universities: University of North Carolina at Charlotte, Northeastern University, North Carolina Research Campus

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account