Security Architect
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+14 more
Job description
The Client is seeking a Security Architect to join the Enterprise Information Technology Services (EITS), Information Security and Risk Management team. This role will provide enterprise-level security architecture leadership, conduct security risk reviews, support AI-related security risk assessments, and ensure compliance with healthcare industry regulations and security frameworks. The Security Architect will collaborate with business and technical teams to design, implement, and maintain secure technology solutions across the organization.
Tasks
- Lead the definition, development, and implementation of enterprise security architecture and security administration processes across all platforms.
- Conduct security risk reviews and provide recommendations to address identified vulnerabilities and security gaps.
- Support AI adoption initiatives by evaluating and mitigating security risks associated with AI technologies and solutions.
- Participate in security architecture planning and solution design for new and existing systems prior to implementation.
- Identify, evaluate, and implement emerging security technologies, safeguards, and data access control solutions.
- Develop and recommend risk mitigation strategies based on security assessments and architecture reviews.
- Provide security architecture guidance and recommendations to senior leadership and cross-functional teams.
- Conduct application vulnerability assessments and security scans, analyze findings, and design appropriate countermeasures.
- Design and implement security controls based on Information Assurance (IA) principles and industry best practices.
- Collaborate with enterprise architecture teams to align business, technical, and security requirements.
- Partner with security engineering teams to implement controls and configurations that comply with organizational policies and regulatory requirements.
- Develop security metrics, performance measurements, and reporting mechanisms.
- Monitor current cybersecurity threats, vulnerabilities, and emerging industry trends.
- Serve as a subject matter expert on information security, risk management, and regulatory compliance initiatives.
- Support compliance efforts related to HIPAA, HITECH, Joint Commission requirements, DSRIP, COBIT, PCI-DSS, ISO 27001/27002, NIST Cybersecurity Framework, and applicable state privacy laws.
- Participate in special projects and perform additional duties as assigned.
Requirements
- Bachelor’’s degree in Information Systems, Computer Science, Cybersecurity, or a related field.
- Minimum of 10 years of IT experience, including at least 7 years focused on cybersecurity, information security, or security architecture.
- Experience designing and implementing enterprise security solutions and security architectures.
- Strong background in security risk assessments, security architecture reviews, and risk mitigation planning.
- Experience evaluating security risks associated with emerging technologies, including AI-enabled solutions.
- Deep knowledge of HIPAA/HITECH, NIST Cybersecurity Framework (CSF), ISO 27001/27002, PCI-DSS, COBIT, and healthcare security compliance requirements.
- Strong understanding of infrastructure security, application security, security protocols, configuration management, risk management, audit standards, and compliance frameworks.
- Knowledge of encryption technologies, algorithms, and secure communication methods.
- Experience with network security architecture, including TCP/IP, OSI model, defense-in-depth principles, network topology, protocols, and traffic flows.
- Experience with Identity and Access Management (IAM), Active Directory, access federation, multifactor authentication (MFA), and Public Key Infrastructure (PKI).
- Experience securing and supporting Microsoft Windows, Linux, UNIX, and macOS environments.
- Knowledge of vulnerability management, security monitoring, secure configuration management, and software security principles.
- Ability to translate business security requirements into technical security controls and architecture standards.
- Experience developing security metrics, reporting frameworks, and performance measurements.
- Strong communication, collaboration, and leadership skills with the ability to work effectively across technical and business teams.
- Ability to work independently and manage multiple priorities in a fast-paced environment.
Desired
- CISSP, CISM, GSEC, CEH, or other relevant cybersecurity certifications.
- Experience within healthcare organizations or highly regulated industries.
- Knowledge of IT supply chain security and third-party risk management practices.
- Experience assessing the resilience, reliability, and dependability of security architectures and systems.
- Demonstrated ability to lead enterprise-wide security initiatives and strategic security programs.
- Strong analytical, problem-solving, and decision-making skills.
- Flexibility to work at multiple locations and support varying schedules when required.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on dice.comGood distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
9 Ways to Make Money Hacking
Understanding and Mitigating Common Web Vulnerabilities
What Are The Top Skills Required For Azure Developers?
Best Paying Jobs in Technology