--- title: 'Principal Software Security Architect at BeyondTrust' canonical: 'https://feeny.ai/job/principal-software-security-architect-beyondtrust-united-states-tb1kkx2h6jxq' type: 'job' last_seen: '2026-09-11' --- # Principal Software Security Architect at BeyondTrust - **Company:** BeyondTrust - **Location:** United States - **Work type:** remote - **Posted:** 2026-05-14 - **Last confirmed live:** 2026-09-11 - **Apply:** https://job-boards.greenhouse.io/beyondtrust/jobs/7885501 ## Job description BeyondTrust is a place where you can bring your purpose to life through the work that you do, creating a safer world through our cyber security SaaS portfolio. Our culture of flexibility, trust, and continual learning means you will be recognized for your growth, and for the impact you make on our success. You will be surrounded by people who challenge, support, and inspire you to be the best version of yourself. ## The Role The Principal Software Security Architect owns security architecture for BeyondTrust's product suite end to end, including endpoint agents, thick clients, SaaS platforms, APIs, identity systems, and cloud-native services. This is an engineering leadership role embedded within Engineering and Architecture teams in the Office of the CTO, accountable for designing security into products from first principles through to what ships and runs in production, rather than reviewing other teams' work from the outside. We operate AI-first: Claude and LLM-driven workflows are how the team performs threat modeling, secure design reviews, vulnerability analysis, and developer enablement today, and this role is expected to operate at that level from day one and help extend that practice further. The ideal candidate brings 10+ years of hands-on software engineering and security architecture experience, deep expertise in threat modeling and attack surface reduction at scale, and practical experience applying LLM platforms to security engineering work. ## What You’ll Do - Own end-to-end security architecture for assigned product lines, from concept through production, defining the target-state architecture and secure-by-default patterns each product builds on. - Lead threat modeling, attack surface analysis, and secure design reviews across products, platform services, endpoint agents, and cloud-native systems, driving the architectural decisions that eliminate unnecessary exposure rather than just documenting risk. - Use LLM platforms (Claude, OpenAI) as core tools to scale threat analysis, abuse-case generation, architecture review, and remediation guidance, building the prompts, plugins, skills, and agent workflows that make the engineering org faster and more consistent. - Embed secure-by-default patterns directly into product development, contributing reference architectures, reusable components, and automated guardrails, and building self-service security capabilities that let engineers make secure decisions without a bottleneck. - Own and expand the Product Security handbook, a living system that feeds the team's AI workflows to enforce secure design standards, architecture guidance, and engineering best practices. - Set technical direction for secure design across the org as a principal-level engineer, mentoring engineers, architects, and Security Champions on secure design, attack surface reduction, and AI-first security workflows. - Help evolve BeyondTrust's AI-first Product Security Architecture strategy, identifying where AI workflows can replace manual processes, where they need human oversight, and where the next capability gaps are. ## What You’ll Bring - 10+ years in Software Engineering, Security Architecture, Product Security, or Application Security, with a track record of owning architecture for shipping products - Deep, practical experience with threat modeling, attack surface analysis, secure design reviews, and architecture risk analysis at scale, not just in theory - Strong hands-on engineering background, with the ability to read and contribute to the codebase, design systems, and earn credibility with senior engineers as a peer - Strong understanding of cloud-native systems, APIs, endpoint agents, thick clients, and identity/security platforms - Hands-on experience using LLM platforms (Claude, OpenAI, or similar) in engineering or security workflows - Ability to influence engineering and product teams from within, acting as a persuasive, credible, and practical partner rather than a gatekeeper - Builder mindset, having created scalable security workflows, frameworks, or enablement programs, not just consumed them - Experience building AI-native security workflows, plugins, agents, or developer tooling What Success Looks Like - Measurable reduction in product attack surface and recurring architecture risks, measured by risk eliminated, not findings produced - Security architecture for owned product lines is defined, documented, and demonstrably adopted in shipping products - Increased scale and consistency of secure design reviews through AI-first workflows - Faster identification and remediation of design-level and architecture-level risks - Engineering teams actively using self-service security capabilities that have been built - Expansion of AI-first Product Security Architecture capabilities across the SDLC ## Nice To Have - Background in securing endpoint technologies, identity systems, or enterprise security platforms - Offensive security experience or adversarial testing background - Cloud security experience across AWS, Azure, or Kubernetes environments Better Together Diversity. Inclusion. They’re more than just words for us. They are the guiding values of how we build our teams, cultivate leaders, and create a culture where people feel connected. We take care of our employees so they can take care of our customers. Customers who come from all walks of life just like us. We hire incredible people from diverse backgrounds because when we are different together, we are stronger together. ## About Us BeyondTrust is the global identity security leader protecting Paths to Privilege™. Our identity-centric approach goes beyond securing privileges and access, empowering organizations with the most effective solution to manage the entire identity attack surface and neutralize threats, whether from external attacks or insiders. BeyondTrust is leading the charge in transforming identity security to prevent breaches and limit the blast radius of attacks, while creating a superior customer experience and operational efficiencies. We are trusted by 20,000 customers, including 75 of the Fortune 100, and our global ecosystem of partners. Learn more at [www.beyondtrust.com](http://www.beyondtrust.com/). #LI- ## About BeyondTrust ## Company Overview - **One-liner**: BeyondTrust provides a unified identity and access security platform that protects identities, remediates threats, and delivers dynamic access across human, non-human, and AI identities. - **Entity Type**: Private (backed by private equity; no public ticker) - **Headquarters**: Not publicly available in provided sources (global company with offices in the US, Canada, UK, Germany, Netherlands, Switzerland, India, Indonesia, Philippines, Australia, and more) - **Founded**: Not publicly available (roots trace to earlier companies; current entity formed through mergers and acquisitions) - **Founders**: Not publicly available ## Core Business - **Primary industry**: Cybersecurity – Identity and Access Security (Privileged Access Management, Identity Threat Detection and Response, Secrets Management, Cloud Infrastructure Entitlement Management, Secure Remote Access) - **Target customers**: B2B, primarily large enterprises (75% of the Fortune 100 are customers), also government, mid-market, and SMBs - **Mission**: "Fight every day to secure identities, intelligently remediate threats, and deliver dynamic access to empower and protect organizations around the world." Vision: "A world where all identities and access are protected from cyber threats." ## Products & Services - **BeyondTrust Pathfinder Platform**: Unified platform that integrates PAM, ITDR, Secrets Management, CIEM, and Secure Remote Access. Enforces least privilege, zero standing privilege, just-in-time access, and discovers hidden privilege paths. - **Endpoint Privilege Management**: Removes local admin rights and enforces least privilege on endpoints. - **Password Safe**: Enterprise password and secrets vault with rotation and just-in-time access. - **Secure Remote Access**: Zero-trust remote support and vendor access (including Remote Support), with session management and credential vaulting. - **Identity Security Insights**: Analytics and reporting on identity risk. - **AI Analysis & AI Chat**: AI-powered threat detection and conversational interface for incident response. - **Entitle**: Cloud infrastructure entitlement management (CIEM) for multi-cloud environments. - **MCP Integration**: Integration with Model Context Protocol for controlling AI agent privileges. ## Market Standing - **Valuation/Market Cap**: Not publicly available (private company) - **Key Metric**: Not disclosed; recognized as a Leader in the Gartner Magic Quadrant for PAM (7 years in a row), Forrester Wave Leader for PIM, KuppingerCole Leader for ITDR, and GigaOm Leader for CIEM. - **Notable Investors/Partners**: Private equity owned (Francisco Partners and others per general knowledge, not explicitly in provided sources). Key partners include ServiceNow (integration with service desk workflows). - **Growth Signals**: 75% of the Fortune 100 are customers; continuously hiring across 45+ open positions globally; named Inc. Best Workplaces 2023, Nova Scotia's Top Employer 2022, Best Workplaces in Tech UK 2022. ## Competitive Advantages - **Unified Pathfinder Platform**: Single platform covering all identity security use cases (human, non-human, AI) rather than disconnected tools. - **True Privilege™ Technology**: Maps actual identity attack paths (lateral movement, shadow access, inherited entitlements) to uncover hidden Paths to Privilege. - **Analyst Validation**: Consistently ranked as a Leader by Gartner, Forrester, KuppingerCole, and GigaOm. - **AI Governance**: First-to-market governance for AI agent identities across multiple cloud and SaaS environments (AWS, Azure, Google, OpenAI, Salesforce, ServiceNow). - **Zero Standing Privilege**: Automates just-in-time access and auto-revokes privileges to reduce attack surface. ## Strategic Focus - **Convergence of Identity Security**: Moving beyond siloed PAM to a connected, privilege-centric identity security strategy. - **AI Identity Governance**: Enforcing privilege controls on rapidly growing AI agents and non-human identities. - **Cloud and OT Expansion**: Protecting identities across cloud, SaaS, and operational technology environments. - **Integrating with Service Management**: Streamlining workflows through integrations with ServiceNow and other IT service management tools. - **Customer Experience**: Maintaining industry-leading customer satisfaction scores through exceptional support and customer success. ## Why Work Here - **Remote-First Culture**: Most roles are fully remote with flexible work arrangements; offices exist in multiple countries. - **Award-Winning Workplace**: Recognized by Inc., Nova Scotia's Top Employer, and Best Workplaces in Tech UK. - **Core Values**: Teamwork, Integrity, Humility, Passion, Accountability, Results. Emphasis on continuous learning and growth, with training resources and career development programs. - **Diversity & Inclusion**: BeyondTrust Resource Groups (BTRGs) for affinity groups, community building, and educational events. - **Transparency**: Monthly all-hands town halls where executives share business priorities and success metrics. - **Community Impact**: BeyondGiving program supports employee-led sponsorships and global fundraising. - **Benefits**: Competitive benefits package (details not fully disclosed but includes development tools). - **Recruitment Authenticity**: The company warns about recruitment fraud, indicating a high focus on candidate safety. ## Sources 1. [beyondtrust.com - Company Overview](https://www.beyondtrust.com/company/overview) 2. [beyondtrust.com - Employee Life](https://www.beyondtrust.com/company/overview/employee-life) 3. [beyondtrust.com - Careers](https://www.beyondtrust.com/company/overview/careers) 4. [beyondtrust.com - Homepage](https://www.beyondtrust.com/) 5. [greenhouse.io - Current Openings](http://job-boards.greenhouse.io/beyondtrust) ## Other roles at BeyondTrust - [Business Development Representative](https://feeny.ai/job/business-development-representative-beyondtrust-atlanta-g1rrkmkvpfmt) — Atlanta, GA - [Business Development Representative](https://feeny.ai/job/business-development-representative-beyondtrust-atlanta-07vccj4438pw) — Atlanta, GA - [Solutions Engineer](https://feeny.ai/job/solutions-engineer-beyondtrust-calgary-fpfkcc49bhxg) — Calgary, Canada / British Columbia, Canada - [Sr SOC Analyst](https://feeny.ai/job/sr-soc-analyst-beyondtrust-canada-united-states-qc3k8g7rxgm7) — Canada / United States - [Business Development Representative - Italian Speaking](https://feeny.ai/job/business-development-representative-italian-speaking-beyondtrust-manchester-2v2ngd0y06en) — Manchester, United Kingdom - [Cloud Engineer](https://feeny.ai/job/cloud-engineer-beyondtrust-canada-united-states-2m0xr4bg9e73) — Canada / United States - [Sr Software Development Engineer](https://feeny.ai/job/sr-software-development-engineer-beyondtrust-canada-united-states-spqedr4s2t1a) — Canada / United States - [Business Development Representative](https://feeny.ai/job/business-development-representative-beyondtrust-manchester-hvta3veashjk) — Manchester, United Kingdom - [Account Executive II - Riyadh (Saudi National)](https://feeny.ai/job/account-executive-ii-riyadh-saudi-national-beyondtrust-riyadh-fvbs1avsw66x) — Riyadh, Saudi Arabia - [Customer Retention Executive](https://feeny.ai/job/customer-retention-executive-beyondtrust-united-states-us-east-coast-hfpkxt9pc784) — United States / US East Coast