Principal Architect, Website Cybersecurity
SephoraAbout the role
Job ID: 268853
Location Name: CA-FSC SF Off (0174)
Address: 350 Mission St, 20th Floor, San Francisco, CA 94105, United States (US)
Job Type: Full Time
Position Type: Regular
Job Function: Information Technology
Remote Eligible:Hybrid Schedule
Company Overview:
At Sephora we inspire our customers, empower our teams, and help them become the best versions of themselves. We create an environment where people are valued, and differences are celebrated. Every day, our teams across the world bring to life our purpose: to expand the way the world sees beauty by empowering the Extra Ordinary in each of us. We are united by a common goal - to reimagine the future of beauty.
The Opportunity:
Technology
Join our dynamic and highly skilled Cybersecurity Engineering team, responsible for protecting critical systems and sensitive data from potential cyber threats. We are a group of passionate engineers dedicated to building secure solutions across our enterprise. Our team collaborates closely with IT, development, and business units to ensure all systems are designed and implemented with the highest levels of security. As a Principal Architect, you will play a leadership role within this team, setting security standards, mentoring junior engineers, and guiding the implementation of innovative cybersecurity practices.
Your role at Sephora:
The Principal Architect for Cybersecurity will be responsible for defining, designing, and implementing the organization’s cybersecurity architecture and strategy. This role requires a visionary leader with deep technical expertise in cybersecurity, risk management, and emerging technologies. The Principal Architect will work closely with cross-functional teams to ensure the security of our systems, applications, and data while aligning with business objectives and regulatory requirements. This role will also collaborate with peers at LVMH, Sephora Global, and other Sephora Regions.
Responsibilities:
- Application Security: Secure web applications from cyber threats including identifying and fixing vulnerabilities, implementing security best practices, and educating development teams on secure coding practices.
- Security Architecture Design: Owns the design, implementation, and management of our organization's cybersecurity architecture.
- Mentorship & Leadership: Guide and mentor security engineers, architects, and other technical professionals, fostering a strong security culture.
- Cloud Security: Develop and enforce security policies and controls for cloud platforms (Azure, GCP, OCI), including IAM, encryption, and monitoring.
- Innovation & Research: Stay ahead of emerging cybersecurity trends, threats, and technologies, recommending proactive security enhancements.
- Incident Response & Forensics: Provide guidance on security monitoring, incident detection, and response strategies to strengthen organizational resilience.
- DevSecOps & Automation: Integrate security into CI/CD pipelines, leveraging automation, Infrastructure as Code (IaC), and security-as-code principles.
We're excited about you if you have:
- 15-20 years of web development and/or experience with programming languages, secure coding practices, and common web technologies.
- 15-20 years experience in cybersecurity, with at least 5 years in a senior architecture or leadership role.
- 15-20 years hands-on experience with security tools such as SIEM, EDR, WAFs, NDR, Bot Protection, IDS/IPS, and vulnerability management platforms.
- 15-20 years hands-on experience with website security tools such as Akamai
- 15-20 years strong expertise in security frameworks (e.g., NIST, PCI-DSS, CIS Controls, MITRE ATT&CK).
- 15-20 years strong understanding of network security, application security, identity, and access management (IAM), and data protection.
- Strong analytical, problem-solving, and communication skills with the proven ability to influence stakeholders across different technology functions and various levels – from executive leadership to individual contributor
- Experience with modern cloud security architectures (Azure, GCP, OCI)
- Knowledge of DevSecOps practices, container security (Kubernetes, Docker), and CI/CD
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s