Principal Cybersecurity Architect β Network Security Posture Management
Job Description
IonQ is seeking a Principal Cybersecurity Architect to lead security posture strategy for its Network Security Posture Management (NSPM) platform. This role focuses on designing and operationalizing posture assessment rules tied to recognized security standards, along with risk scoring and scalable rule lifecycle management for large, heterogeneous network environments.
Location: San Francisco, CA (hybrid). Travel: Up to 10%. Job ID: 1560.
What you will do
- Design and own the security posture assessment rule framework, evaluating device configurations, network behaviors, and access controls against standards including NIST CSF, CIS Benchmarks, ISO 27001, FISMA, and FedRAMP.
- Build and maintain a scalable rule authoring and lifecycle management system to onboard new security standards and custom organizational policies, with versioning and deployment that avoids platform re-architecture.
- Continuously monitor the evolving threat and compliance landscape by translating new standards, regulatory changes, and emerging CVE information into updated posture assessment rules.
- Define a risk scoring and prioritization model that aggregates individual posture findings into an actionable posture score across device, segment, and enterprise levels.
- Partner with platform engineering teams to ensure posture assessment rules execute efficiently at scale across large network device fleets, including well-defined APIs for rule ingestion, evaluation, and results delivery.
- Engage with enterprise customers and internal stakeholders to understand compliance requirements, translating them into platform capabilities and serving as an authoritative security subject matter expert for the product.
- Collaborate with Product and Engineering to shape the NSPM roadmap so security posture capabilities remain aligned with regulatory expectations and deliver measurable value to network security and compliance teams.
- Mentor engineers and security analysts on posture rule design, threat modeling, and compliance mapping, establishing rigorous review processes to ensure assessment rules are accurate and defensible.
What you bring
- 12+ years of experience in cybersecurity, network security, or security architecture, including at least 5 years in a senior or principal capacity focused on network security posture, compliance, or policy enforcement at scale.
- Deep, hands-on experience with Network Security Posture Management (NSPM) platforms and tools, with a track record of designing and operationalizing posture assessment rules across large enterprise networks.
- Comprehensive knowledge of NIST CSF, CIS Benchmarks, ISO 27001, FISMA, and FedRAMP, including the ability to interpret control requirements and translate them into precise, automatable assessment rules.
- Strong understanding of network device security, including firewall policy analysis, routing protocol security, access control, and configuration hardening across multi-vendor environments such as Cisco, Juniper, Palo Alto, and Fortinet.
- Ability to operate across strategic and technical areas, engaging executive stakeholders on compliance risk while working with engineering teams on rule design, data modeling, and platform integration.
Technologies
- Network Security Posture Management (NSPM)
- NIST CSF, CIS Benchmarks, ISO 27001, FISMA, FedRAMP
- APIs
- CVE lifecycle management
Preferred qualifications
- Industry certifications such as CISSP, CISM, CCNP Security, or equivalent credentials.
- Prior experience at a network security vendor, MSSP, or large enterprise security team, including exposure to posture policy enforcement across complex, multi-vendor networks.
- Familiarity with Zero Trust principles, including practical application to segmentation, device trust, and least-privilege access enforcement.
- Experience contributing to or authoring security standards, CIS Benchmark profiles, or DISA STIGs, or participation in industry working groups related to network security policy and compliance.
- Understanding of CVE lifecycle management, SBOM analysis, and vulnerability correlation for network device firmware and software supply chain risk assessment.
Compensation
- Approximate base salary range: $248,557 - $325,425 per year.
- Total compensation may include base, bonus, equity, and a range of benefit options available on the career site.
- Compensation may vary based on education, qualifications, experience, office location, and internal calibration to market data and team equity; posted figures are subject to change.
Benefits
- Comprehensive medical, dental, and vision plans
- Matching 401(k)
- Unlimited PTO and paid holidays
- Parental/adoption leave
- Legal insurance
- Home technology stipend
- Plan participation details are provided upon offer of employment
U.S. employment and export control
The position requires access to technology subject to U.S. export control and government contract restrictions. IonQ employment is contingent on verifying U.S. Person status for export controls and government contracts work (for example, U.S. citizen, U.S. national, U.S. permanent resident, or lawfully admitted into the U.S. as a refugee or granted asylum), obtaining any necessary license and/or confirming availability of a license exception under U.S. export controls. If U.S. Person status cannot be confirmed for these purposes, IonQ may choose not to apply for a license or decline to use a license exception (if available), and may decline to proceed with the application based on those determinations.
IonQ also requests additional questions regarding immigration status for export control and compliance review by compliance personnel.
Location note: Onsite or Hybrid in Santa Clara / Bay Area, CA.