Cyber Security Architect Jobs in California
Cyber Security Architect jobs in California sit at the center of one of the most active cybersecurity markets in the country, with sustained demand across defense contracting, enterprise technology, financial services, and healthcare from entry-level security engineers moving into architecture roles through principal and distinguished-level architects. The largest concentrations of openings are in San Francisco, Los Angeles, and San Diego, where employers such as Northrop Grumman, Salesforce, and Kaiser Permanente maintain significant security teams. Zero-trust architecture, cloud security, and OT/ICS security are the specialties drawing the most consistent hiring attention in California right now. Find a role that fits below and apply directly.
Find Cyber Security Architect JobsOverview
Showing 5 of 88+ Cyber Security Architect jobs











About Knightscope
Knightscope is a security technology company building the Nation’s First Autonomous Security Force. The Company combines autonomous machines, advanced software, and human expertise to help protect people, property, and critical infrastructure. Knightscope’s long-term mission is to make the United States of America the safest country in the world.
Job Summary
Knightscope is seeking a seasoned Cybersecurity Architect with 10+ years of experience to lead the security architecture function across our ASR platform, robotics systems, cloud services, and client-facing applications. This role is the authoritative voice for “secure by design” principles – shaping threat models, architectural patterns, compliance postures, and security engineering standards spanning embedded robotics, IoT communications, and enterprise cloud infrastructure.
About The Role
The Cybersecurity Architect operates at the strategic and technical intersection of robotics security, software platform security, and regulatory compliance, ensuring security is built in, not bolted on. This is not a coding developer/programmer role.
Location: Knightscope HQ, Sunnyvale, CA (This position is not remote)
Key Responsibilities
Secure by Design Architecture:
- Define and own Knightscope’s enterprise-wide Secure by Design framework – architectural patterns, security reference architectures, and ADRs applied from initial concept through production deployment.
- Lead threat modeling (STRIDE, PASTA, Attack Trees) and security architecture reviews for ASR embedded systems, robotics pipelines, cloud APIs, and client-facing applications; drive zero-trust, least-privilege, defense-in-depth, and cryptographic hygiene as foundational design principles.
- Evaluate and gate third-party integrations, vendor systems, and supply chain components for security compliance before production onboarding.
Robotics Systems Cybersecurity Architecture:
- Architect end-to-end ASR fleet security: embedded OS hardening, secure boot chains, firmware integrity verification, HSM/TPM key management, ROS/ROS 2 node authentication, SROS2/DDS-Security plugins, topic-level access control, and secure parameter management.
- Design authenticated robot-to-cloud and robot-to-client communications (TLS 1.3, mTLS, certificate lifecycle); architect sensor fusion anti-spoofing, tamper-evident telemetry logging, CAN bus/ECU hardening, OBD interface protection, OTA update integrity, and multi-tenant fleet segmentation.
- Establish forensic readiness and incident response architecture: tamper-evident audit logging, remote attestation, and field recovery procedures for deployed ASR platforms.
Software & Cloud Systems Security Architecture:
- Architect security across the full Knightscope stack (AWS/GCP/Azure, microservices, APIs, web/mobile): IAM/PAM, identity federation, RBAC/ABAC, vault-class secrets management, VPC/security group segmentation, container security (image signing, runtime policies, service mesh mTLS), and encryption at rest and in transit.
- Own SSDLC architecture – security requirements gates, threat modeling checkpoints, mandatory SAST/DAST/SCA integration, security-focused QA, and post-release vulnerability management; architect SIEM/SOAR pipelines for unified observability across fleet telemetry, cloud, and endpoints.
- Define Ubuntu hardening architecture for embedded platforms (ICM, ACM): CIS Benchmark alignment, AppArmor/SELinux policy frameworks, kernel hardening parameters, and automated patch management.
Compliance Architecture – FIPS 140-3 | Common Criteria | ISO/SAE 21434:
- FIPS 140-3: Lead cryptographic module compliance architecture – validated library selection and integration, key management architecture, and cryptographic boundary documentation required for module validation across all Knightscope products.
- Common Criteria: Define and oversee CC evaluation architecture – Security Target (ST) authorship, Protection Profile (PP) alignment, TOE boundary definition, and evaluation laboratory coordination for applicable products.
- ISO/SAE 21434: Architect cybersecurity processes for Knightscope’s autonomous platforms – Cybersecurity Management System (CSMS), Threat Analysis and Risk Assessment (TARA), cybersecurity goals derivation, and post-development monitoring.
- SOC 2 Type II, NIST CSF, FedRAMP, CMMC, CJIS: Map architecture controls to framework requirements; maintain compliance traceability matrix; partner with legal and product on emerging autonomous systems and AI regulations.
Required Qualifications
- 10+ years of progressive cybersecurity experience; at least 3 years in an architecture-focused role.
- Demonstrated expertise in Secure by Design and security-by-architecture methodologies, with a delivered portfolio of secure architectures for complex, multi-component systems.
- Deep knowledge of cryptographic principles: symmetric/asymmetric encryption, PKI, key lifecycle management, TLS/mTLS, and FIPS 140-3 validated cryptographic module integration.
- Hands-on threat modeling (STRIDE, PASTA, Attack Trees) applied to software systems and cyber-physical/robotics platforms.
- Zero-trust network architecture, network segmentation, and authentication protocol design (OAuth 2.0, OIDC, SAML, X.509).
- Embedded/IoT security architecture: secure boot, firmware integrity, hardware-assisted security (TPM, HSM, Secure Enclave), and resource-constrained cryptography.
- ROS/ROS 2 security architecture, DDS-Security, autonomous vehicle communication protocols, and OTA update security.
- Demonstrated experience leading or supporting FIPS 140-3 validation, Common Criteria evaluation, or ISO/SAE 21434 compliance programs.
- Cloud security architecture (AWS, GCP, or Azure): IAM, VPC, container security, and compliance-aligned posture management.
- Security Target authorship, ADRs, security reference architectures, and compliance traceability matrix documentation.
- S. in Computer Science, Information Security, Systems Engineering, or equivalent. CISSP, CSSLP, CCSP, SABSA, or equivalent architecture credential required.
Preferred Qualifications
- Prior experience securing autonomous systems, robotics platforms, or physical security technology environments, including hands-on work with ROS 2 Security (SROS2), DDS-Security plugin configuration, and ROS node-level access control.
- Familiarity with automotive and autonomous vehicle cybersecurity standards including ISO/SAE 21434, UN/ECE WP.29 (R155/R156), and SAE J3061, and their application to ground vehicle and robotics platforms.
- Experience with Common Criteria Protection Profiles relevant to network devices, operating systems, or autonomous systems, including participation in formal evaluation engagements.
- In-depth knowledge of government and public-sector security frameworks: FedRAMP High, CJIS Security Policy, FISMA, and CMMC Level 2/3, with experience mapping architecture controls to regulatory requirements.
- Hardware security architecture experience: TPM 2.0 integration, secure element provisioning, anti-tamper design, and physical unclonable function (PUF) technologies in embedded or robotics platforms.
- Background in formal security risk management frameworks such as ISO 27005, NIST SP 800-30, or the SAE J3061 TARA methodology applied to safety-critical or cyber-physical systems.
- Experience architecting security for AI/ML inference pipelines, including model integrity assurance, adversarial input detection, and secure model deployment in edge environments.
Compensation & Benefits
- Base Salary: $160,000 – $210,000 (DOE)
- Equity: Stock options
- Benefits: Medical, dental, vision, 401(k), paid time off
- Location Requirement: Full-time, on-site at Sunnyvale HQ
See All 88 Cyber Security Architect Jobs in California
Find roles in California that match your experience and apply in just a few clicks.
Find Cyber Security Architect JobsCyber Security Architect Jobs by City in California
Where California roles are concentrated, by current openings.
Cyber Security Architect Job Market in California
A snapshot from current California openings, updated as new roles post.
Who's Hiring
- Apple6

- NVIDIA4

- SanDisk3

- Adobe2

- Aurora Innovation2

Top Industries Hiring
- Technology & Software39
- Electronics & Hardware17
- Consulting & Professional Services7
- Manufacturing6
- Science & Research4
What California Employers Look For
The qualifications that appear most often in cyber security architect jobs across California.
- Bachelor's degree in computer science, information security, or a closely related technical field
- Active CISSP certification, with SABSA or TOGAF credentials valued for enterprise architecture roles
- Seven or more years of progressive experience in information security or network engineering
- Hands-on expertise designing zero-trust, cloud-native, or hybrid security architectures
- Experience communicating security strategy to executive stakeholders and non-technical leadership
- Familiarity with California Consumer Privacy Act compliance requirements and related data protection frameworks
Cyber Security Architect Jobs in California: Frequently Asked Questions
How do you become a cyber security architect in California?
The most direct path is to build several years of hands-on security engineering or network security experience, then earn the CISSP, which is the credential California employers most consistently require for architect-level roles. California has no state-issued license specific to cyber security architects, so hiring decisions turn on certifications, demonstrated architecture experience, and a portfolio of security design work. A bachelor's degree in computer science or information security, combined with cloud platform certifications such as AWS or Azure security specialties, strengthens candidacy at larger California employers.
How much do cyber security architects make in California?
Cyber security architects in California earn a median of about $138,570 a year, based on May 2025 Bureau of Labor Statistics wage data, ranging from around $66,070 for the lowest 10% to over $221,000 for the top 10%. Pay rises with experience, specialty, and employer.
Which companies hire cyber security architects in California?
Employers hiring cyber security architects in California right now include Apple, NVIDIA, and SanDisk, based on current listings on Migrate Mate as of June 2026. California's concentration of defense contractors, major technology firms, and large healthcare systems means architect roles appear across a wide range of industries, not just pure-play tech.
Which California cities have the most cyber security architect jobs?
Santa Clara, San Francisco, and San Jose account for the largest share of cyber security architect openings in California. The San Francisco Bay Area leads because of its density of enterprise technology headquarters and venture-backed security firms, while Los Angeles draws demand from aerospace and defense contractors, and San Diego's openings are heavily shaped by the presence of major military installations and the defense industry surrounding them.
Are there remote cyber security architect jobs in California?
Yes, and more than most technical roles, because architecture work centers on design, documentation, and cross-functional collaboration that translates well to distributed teams. About 27% of cyber security architect openings tied to California are remote or hybrid as of June 2026, reflecting strong employer comfort with flexible arrangements at the senior level. The portions of the role most commonly performed remotely are threat modeling, security standards development, and stakeholder advisory work, while hands-on OT or on-premise infrastructure assessments typically require some site presence.
How can I get hired as a cyber security architect in California with little or no experience?
The most realistic entry path is a security analyst or network engineer role at a large California employer, using that position to build architecture exposure before moving into a formal architect title. California defense contractors such as Northrop Grumman and Leidos run structured early-career security programs that place candidates without architect experience into roles where they assist senior architects directly. Earning the CompTIA Security+ and pursuing an associate cloud security certification while in an analyst role signals intent to hiring managers. Targeting companies with internal promotion cultures, such as large financial institutions headquartered in San Francisco or major health systems across the state, improves the odds of moving up without needing an outside hire.
Where can I find and apply to cyber security architect jobs in California?
You can find and apply to cyber security architect jobs in California on Migrate Mate, which lists current California openings updated on an ongoing basis. Search for roles that match your experience and specialization, then apply directly to the ones that fit.
See All 88 Cyber Security Architect Jobs in California
Find roles in California that match your experience and apply in just a few clicks.
Find Cyber Security Architect Jobs