Principal IT Security Architect

RingCentral - Belmont, CA

Hiring: Principal IT Security Architect Company: RingCentral Location: Belmont, CA Job Posted Time: 2026-09-17 06:56:59 Target Skills & Keywords : DNS, OAuth, OAuth2, OIDC, Okta, PowerShell, Python, R, RBAC, SAML, SIEM, SOC 2, SSL, SaaS, Splunk, Zero Trust About the job Experience: •10+ years in security engineering or architecture, a substantial portion of it hands-on-keyboard in production. Certifications do not substitute for demonstrated configuration depth. Required Skills: •Live inside the admin consoles of Okta, Zscaler, Google Workspace, and Microsoft 365, reconstruct how our environment and security tools are configured, challenge inherited assumptions and exceptions, identify exploitable attack paths, and personally architect, prototype, automate, and drive durable fixes into production •Combine an adversary’s mindset with disciplined defensive engineering. •Hunt shadow admins, orphaned integrations, over-scoped OAuth grants, and legacy authentication paths. •Quantify how much company data is currently shared to “anyone with the link” — and then reduce it. •Brief the CIO and security leadership on residual risk in plain language. Qualifications: •Expert-level, in-console administration of Okta — you can explain policy evaluation order, the difference between a global session policy and an app authentication policy, and how you would detect a maliciously created app integration. •Production experience administering Zscaler ZIA and ZPA, including the operational tradeoffs of SSL inspection, bypass exceptions, and least-privilege application segmentation. •Deep working knowledge of both Google Workspace Admin and Microsoft 365 / Entra ID administration — specifically the sharing, external-collaboration, OAuth app-consent, and DLP surfaces. •Demonstrated offensive capability against identity and SaaS environments. You have found real, exploitable misconfigurations, not just reported scanner output. Comfort with tooling such as BloodHound / AzureHound, ROADrecon, GraphRunner, and Burp Suite. •Fluency in SAML, OIDC, OAuth 2.0, and SCIM — and the specific ways each is abused. Working knowledge of MITRE ATT&CK, including the cloud and SaaS matrices. •Automation ability: Python or PowerShell against the Okta, Microsoft Graph, Google Admin SDK, and Zscaler APIs. This role is not survivable by clicking through consoles alone. •The judgment to push a change through change control, quantify user-experience impact, and defend the decision to a skeptical business owner. You will be told “that will break workflows.” You need to be right, and you need to bring the data. •OSCP, GPEN, GCPN, GWAPT, or CRTO; Okta Certified Administrator or Consultant; Zscaler ZIA/ZPA certification. CISSP or CCSP is welcome but is not what we are screening for. •Detection engineering against identity telemetry in a SIEM (Splunk, Sentinel, or equivalent), and prior work in a SOX or SOC 2 audited environment. •How We Will Evaluate You Compensation: •Comprehensive medical, dental, vision, disability, life insurance Interested candidates, please apply directly through the job posting on company's career page or try via AI auto apply on this platform. Don't miss this opportunity to join a forward-thinking team!