Source description
About the role
Job description: Principal Architect reporting to engineering leadership. Partners closely with the API Governance Lead, Enterprise Architecture, Information Security, IAM, SRE and domain engineering teams. The Role You are the senior technical authority for enterprise API architecture and the enforcement of API governance standards. This role exists to close the gap between governance policy and engineering execution: governance defines the rules, you make them executable through platform capabilities, CI/CD controls, contract validation, and runtime policy. This is a hands-on architecture and engineering leadership role. Your goal is to make the compliant delivery path the default path, so federated teams can move quickly without creating contract drift, security gaps, audit exposure, or inconsistent consumer experiences. What You'll Do Architecture and platform strategy Define the enterprise API architecture model across REST, GraphQL, event-driven APIs, and service-to-service integration Own the technical strategy for gateway architecture, service mesh integration, developer experience, lifecycle tooling, observability, and runtime enforcement Establish supported patterns and guardrails for enterprise-scale API delivery Governance enforcement Translate ratified standards into machine-enforceable controls: OpenAPI/AsyncAPI/Graphql validation, schema checks, linting, contract testing, backward-compatibility validation, CI/CD quality gates, and policy-as-code Define what "compliant" means in code, pipelines, gateway policy, and production telemetry Own the technical rules for API classification and layering: enterprise, domain, channel, data-access, and partner APIs Traffic and migration architecture Define where routing, authN/authZ, rate limiting, resiliency, and audit controls belong across ingress gateways, service mesh, and application services Lead architecture across the gateway estate, including migration-safe patterns for policy parity, consumer cutover, and decommissioning without standards drift Developer enablement Build and maintain reference implementations and golden paths for common API patterns Own the technical requirements for a complete, trustworthy enterprise API catalog: ownership metadata, classification, lifecycle status, consumer dependencies, and audit traceability Security and reliability Own implementation patterns for OAuth2, OIDC, JWT validation, mTLS, workload identity, token propagation, rate limiting, circuit breakers, SLOs, and end-to-end traceability Partner with Security, IAM, SRE, and Compliance to ensure controls are enforceable and audit-ready Technical leadership Serve as senior reviewer for cross-domain, high-blast-radius, externally exposed, and regulated API designs Review critical pull requests, contribute production code to platform primitives, and mentor senior engineers and domain architects Lead through technical depth and credibility, not reporting lines Your Authority Establish mandatory technical controls for enterprise APIs Approve or reject cross-domain and high-risk API designs Require remediation before release when codified, non-negotiable standards are violated Define compliance criteria for delivery pipelines and runtime enforcement Recommend platform roadmap priorities for governance enforcement and developer experience What You Bring 12+ years of software engineering experience in distributed systems, API platforms, or enterprise integration Multi-year experience as a Principal, Staff or Lead Architect Production ownership of enterprise-scale API platforms or high-volume API ecosystems Deep expertise in REST, GraphQL, event-driven architecture, contract-first development and API lifecycle management Strong knowledge of OAuth2, OIDC, JWT, mTLS, and enterprise identity integration Experience building automated controls through CI/CD, policy-as-code, and deployment gates Experience in one or more - APIC, KGateway, Datapower, IBM MQ, Kafka Proven ability to influence engineering teams without direct reporting authority Preferred Banking, payments, insurance, healthcare, or other regulated environments High-transaction-volume platforms and multi-gateway migrations or consolidations Internal developer platforms, API catalogs, developer portals, or API product models Audit-grade traceability and automated regulatory evidence
More at eRay Technologies