Security Architect Jobs in California
Security Architect jobs in California are among the most active in the country, with demand concentrated in technology, defense, financial services, and healthcare across roles from associate security architect through principal and CISO-track positions. The largest hiring markets are San Francisco, Los Angeles, and San Diego, where employers such as Google, Northrop Grumman, and Wells Fargo maintain deep security engineering teams. The most in-demand specialties in California are cloud security architecture, zero-trust network design, and compliance-focused security for regulated industries. Find a role that fits below and apply directly.
Find Security Architect JobsOverview
Showing 4 of 46+ Security Architect jobs







Hi,
Role : Security Architect
Work location : Sunnyvale,CA(On-site Mandatory)
Duration : On-Going Project
## Key Responsibilities
Security architecture and design review
- Review the security architecture of enterprise applications and services: trust boundaries, identity and tenancy models, authorisation models, and sensitive-data flows
- Conduct threat modelling (STRIDE or equivalent) with engineering teams and derive prioritised, testable review plans from the model
- Identify design-level weaknesses that automated tooling does not surface — perimeter and gateway bypass, internal-trust assumptions that fail under external exposure, loss of end-user identity across service-to-service hops, and client-side-enforced tenant isolation
- Review authentication and authorisation architecture: OAuth2/OIDC usage, token validation completeness, service-to-service authentication, and object- and function-level authorisation across roles and tenants
- Review data-protection design: encryption in transit and at rest, key management, secrets handling, and logging hygiene for sensitive data
- Review platform architecture: container and Kubernetes security posture, infrastructure-as-code, and cloud IAM least privilege
Target-state design and patterns
- Specify target-state designs for architectural weaknesses, not problem statements alone
- Develop and publish reusable secure-design patterns and reference architectures for adoption across engineering teams
- Act as the design authority engineering teams consult before implementing security remediation
- Feed systemic recommendations into SDLC and CI/CD controls to prevent recurrence
Assurance and standards
- Define security review standards, assessment criteria and scoring or rating models, and defend them under challenge
- Assess applications against those standards and produce the resulting assurance findings and ratings
- Provide technical direction and quality assurance for a small security review team, including offshore members
- Mentor engineers in architecture-level security review
Stakeholder engagement
- Partner with central information security functions on assessment scope, coverage and findings
- Advise application owners and engineering leads on remediation design and prioritisation
- Escalate risks and blockers clearly and early
---
## Required Skills and Experience
- 10+ years in application or product security, including time in a named security architect or design authority role on enterprise systems
- Demonstrable track record of identifying design-level security weaknesses and specifying target-state designs that were adopted
- Experience authoring reference architectures or secure-design patterns used by multiple engineering teams
- Experience on, or running, an architecture or design review board or equivalent design gate
- Threat modelling at architecture level, including facilitating sessions with teams new to the practice
- Java and Spring Boot secure design and code review, including Spring Security and API gateway layers; awareness of reactive/non-blocking codebases
- Identity and access architecture — OAuth2/OIDC, JWT validation, federated enterprise identity providers, service-to-service authentication (HMAC-signed requests, app-to-app token exchange), session and token lifecycle
- Multi-tenant authorisation architecture — broken object- and function-level authorisation, tenant isolation design and verification
- Cloud and container security architecture — Kubernetes and Helm, container hardening, infrastructure-as-code review, cloud IAM across at least two major providers
- Working knowledge of OWASP ASVS, OWASP Top 10, OWASP API Security Top 10, and **CVSS v4.0
- Experience handling confidential or regulated data under a formal classification scheme
- Ability to build the security model of a proprietary or undocumented internal framework from its source code
- Strong written communication — designs, findings and rationale must be actionable by engineers
- Ability to influence without direct authority, and to work credibly with both central security functions and delivery teams
---
## Preferred
- AI / LLM application security architecture — retrieval-augmented generation design, tenant isolation on retrieval, prompt and template provenance, treating model output as untrusted, agent and tool credential scope, Model Context Protocol (MCP) exposure
- Hands-on security testing or penetration testing background, sufficient to validate and demonstrate a finding
- API security architecture and authorisation-matrix testing
- Software supply chain, SBOM and dependency risk management
- Experience establishing a security assurance programme where no formal process previously existed
- Familiarity with enterprise CI/CD security gates (SAST, SCA, secrets scanning)
---
## Certifications
Demonstrable architectural depth is weighted above certification. One or more of the following is expected:
- CISSP, **CSSLP, **CISSP-ISSAP, or **SABSA
- Valuable additions: CCSP, **CKS, **OSCP, **GWAPT, or a recognised threat-modelling credential
---
## Education
Bachelor's degree in Computer Science, Information Security, Engineering or a related field — or equivalent professional experience.
Pay: $65.00 - $70.00 per hour
Expected hours: 40.0 per week
Work Location: In person
See All 46 Security Architect Jobs in California
Find roles in California that match your experience and apply in just a few clicks.
Find Security Architect JobsSecurity Architect Jobs by City in California
Where California roles are concentrated, by current openings.
Security Architect Job Market in California
A snapshot from current California openings, updated as new roles post.
Who's Hiring



Top Industries Hiring
- Electronics & Hardware
- Technology & Software
- Staffing & Recruiting
- Manufacturing
- Fashion & Apparel
What California Employers Look For
The qualifications that appear most often in security architect jobs across California.
- Bachelor's degree in computer science, information security, or a closely related field
- Active CISSP certification recognized as the baseline credential across California employers
- Five or more years of hands-on experience in security engineering or network security
- Deep knowledge of cloud security architecture across AWS, Azure, or Google Cloud Platform
- Experience designing zero-trust frameworks and security controls for enterprise environments
- Familiarity with California compliance requirements including CCPA and CPRA data protection rules
Security Architect Jobs in California: Frequently Asked Questions
How do you become a security architect in California?
The path into security architecture in California typically starts with a bachelor's degree in computer science, cybersecurity, or information systems, followed by several years working in security engineering, network security, or systems administration. California has no state-issued license for security architects, but employers consistently require the CISSP credential from ISC2, and many also value CISM or cloud-specific certifications. Building experience with enterprise environments and compliance frameworks relevant to California, such as CCPA, strengthens candidacy significantly.
How much do security architects make in California?
Security architects in California earn a median of about $138,570 a year, based on May 2025 Bureau of Labor Statistics wage data, ranging from around $66,070 for the lowest 10% to over $221,000 for the top 10%. Pay rises with experience, specialty, and employer.
Which companies hire security architects in California?
Employers hiring security architects in California right now include NVIDIA, AMD, and Apple, based on current listings on Migrate Mate as of September 2026. California's concentration of major technology headquarters, defense contractors, and large financial institutions means steady and recurring demand for experienced security architecture talent.
Which California cities have the most security architect jobs?
Santa Clara, San Jose, and Irvine have the most security architect openings in California. The San Francisco Bay Area leads because of its density of technology company headquarters and venture-backed firms with mature security programs, while Los Angeles draws demand from entertainment, aerospace, and defense sectors, and San Diego's openings are largely driven by the region's strong defense contractor and biotech presence.
Are there remote security architect jobs in California?
Yes, and more than most fields. Security architecture is largely analytical and design-focused, making it well suited to remote work compared to hands-on technical roles. About 46% of security architect openings tied to California are remote or hybrid as of September 2026, reflecting how broadly California employers have embraced distributed security teams. The most consistently remote portions of the work are threat modeling, policy development, and architecture review rather than hands-on infrastructure deployment.
How can I get hired as a security architect in California with little or no experience?
The most realistic entry path is moving laterally from a security analyst, network engineer, or systems administrator role into architecture work. Large California technology companies and defense contractors such as those in the greater Los Angeles and San Diego corridors often post associate security engineer roles that serve as a direct on-ramp. Completing the CISSP or an entry-level cloud security certification and building a portfolio of architecture diagrams or threat models gives candidates a concrete edge when competing for California positions without a long security architecture title history.
Where can I find and apply to security architect jobs in California?
You can find and apply to security architect jobs in California on Migrate Mate, which lists current California openings. Find the roles that fit your background and apply directly to the ones that match.
See All 46 Security Architect Jobs in California
Find roles in California that match your experience and apply in just a few clicks.
Find Security Architect Jobs