Principal Architect - Security

SCA Health
United States
25 days ago
Apply on careers.sca.health
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
2 years minimum
Compensation
$150,000.0
Working hours
Regular working hours

Tech stack

Microsoft Access Access Network Active Directory Architectural Patterns Authentication Protocols Microsoft Azure Software as a Service Cloud Computing Security Cyber Security Continuous Integration Federated Identity Management Identity and Access Management
+25 more
Virtual Private Networks (VPN) Information Systems Security Architecture Professional Key Management Microsoft Software Network Segmentation Citrix Systems OAuth OpenID PCI Data Security Standards Systems Development Life Cycle Role-Based Access Control Azure Active Directory Zero Trust Network Access Sherwood Applied Business Security Architecture Security Assertion Markup Language (SAML) Web Application Security Security Information and Event Management Software Engineering Systems Integration Software Vulnerability Management Policy as Code Data Logging Technical Debt Togaf Devsecops

Job description

We currently have an exciting opportunity for a Principal Architect - Security, responsible for working with stakeholders, both leadership and subject matter experts, to build a holistic view of the organization’s security architecture, controls, and risk posture. This individual will utilize knowledge and experience to link the business mission, strategy, and processes of the organization to a secure-by-design IT strategy, and document this utilizing multiple architectural models or views that show how the current and future needs of the organization will be met in an efficient, sustainable, agile, adaptable, and secure manner. A central focus of this role is embedding security into architecture decisions across SCA’s hybrid, partner-driven environment and serving as the authoritative security voice at the Architecture Review Board. Because SCA maintains its own identity boundary with no federation to its Optum/UHG parent, this role treats identity as the primary control plane and delivers secure access through a Zero Trust, Zscaler-anchored model., * Develop, maintain, promote, and evangelize an enterprise view of the security architecture blueprint and roadmap for the organization

  • Align the security strategy, controls, and solutions with the Company’s business objectives and defined risk appetite
  • Serve as the authoritative security reviewer at the ARB/DRB, evaluating architectures for security fitness and recording the Security domain sign-off
  • Partner with the CISO organization to ensure architecture aligns with the NIST CSF-aligned security remediation framework, coordinating it with the EA-owned Technical Debt Management Framework
  • Establish and lead the threat modeling practice required by Optum for qualifying solution architectures - defining which architectures trigger a threat model, the method applied (e.g., STRIDE), and how threat-model findings are remediated and carried into the ARB security sign-off
  • Perform architecture risk assessments across initiatives, mapping mitigations to the design and reducing project risk
  • Provide strategic security consultation to assigned business customers in designing technology-based solutions, and identify enabling security technologies based on requirements
  • Design and publish security patterns and reference architectures spanning identity and access management, zero-trust, data protection, network segmentation, secrets management, and logging/detection
  • Own the enterprise identity and access management architecture as the primary control plane for Zero Trust - directory and identity services (Microsoft Entra ID and Active Directory), authentication and federation standards (SAML, OIDC, OAuth 2.0, SCIM), Conditional Access, MFA and passwordless, and RBAC/ABAC authorization models
  • Architect identity governance and privileged access - joiner/mover/leaver lifecycle and automated provisioning/deprovisioning, access certification and entitlement reviews, and privileged access management (e.g., Entra Privileged Identity Management) with just-in-time, least-privilege elevation
  • Design cross-boundary, workforce, and partner identity for SCA’s separated identity model - Optum-issued contractor identities, B2B/guest access, and Citrix - where SCA and the Optum parent maintain distinct identity stores without federation; define workload and non-human identity patterns (service principals, managed identities, workload federation) and secrets management to eliminate long-lived credentials
  • Architect data protection for PHI and PII in the ASC context, including encryption in transit and at rest, key management, and masking/tokenization
  • Establish the Zero Trust network and secure-access architecture on the Zscaler SSE/SASE platform - Zscaler Private Access (ZPA) for identity- and posture-aware access to private applications, Zscaler Internet Access (ZIA) for secure web/egress and inline inspection, and Zscaler Digital Experience (ZDX) for monitoring - replacing implicit-trust VPN patterns and enforcing segmentation and ingress/egress controls
  • Extend the Zscaler platform into the broader control set where it fits - CASB and DLP for SaaS, posture control, and device-posture signals feeding Conditional Access - with clean integration to Entra ID, endpoint tooling, and logging/detection
  • Provide cloud and SaaS security architecture, in particular for Microsoft Azure, including landing-zone guardrails, policy-as-code, and shared-responsibility clarity
  • Map security controls to applicable frameworks (NIST CSF, HIPAA, HITRUST, SOC 2, PCI) with ownership and an evidence approach
  • Guide vulnerability management and supply-chain security, including SBOM, patching, and security gates in the SDLC/CI-CD pipeline
  • Lead the security architecture review of third-party and vendor solutions, with particular rigor for Tier 1 PHI vendors
  • Monitor and manage security-related technical debt within the environment, coordinating remediation priority with the CISO framework
  • Contribute to the growth and maturity of the IT department through mentorship, knowledge transfer, and thought leadership by example
  • Articulate security architecture concepts, risk, and analytical findings to Executive Management, business leadership, software developers, and end users
  • Additional duties as assigned., We currently have an exciting opportunity for a Principal Architect - Security, responsible for working with stakeholders, both leadership and subject matter experts, to build a holistic view of the organization’s security architecture, controls, and risk posture. This individual will utilize knowledge and experience to link the business mission, strategy, and processes of the organization to a secure-by-design IT strategy, and document this utilizing multiple architectural models or views that show how the current and future needs of the organization will be met in an efficient, sustainable, agile, adaptable, and secure manner. A central focus of this role is embedding security into architecture decisions across SCA’s hybrid, partner-driven environment and serving as the authoritative security voice at the Architecture Review Board. Because SCA maintains its own identity boundary with no federation to its Optum/UHG parent, this role treats identity as the primary control plane and delivers secure access through a Zero Trust, Zscaler-anchored model.

Requirements

  • Bachelor’s degree or equivalent work experience
  • 8-10+ years of experience in security architecture and engineering, with the most recent role in an architect or technical leadership capacity
  • 2-5+ years of experience working in an architect or technical leadership capacity
  • Solid understanding of healthcare provider (ASC) security and compliance obligations (HIPAA, HITRUST), with the ability to provide a trusted voice at the decision-making table
  • Strong command of security frameworks and control catalogs: NIST CSF, NIST 800-53, HITRUST, SOC 2, and PCI DSS
  • Deep identity and access management expertise: directory and identity platforms (Microsoft Entra ID and Active Directory), federation and authentication protocols (SAML, OIDC, OAuth 2.0, SCIM), Conditional Access, MFA and passwordless, and RBAC/ABAC authorization
  • Identity governance and privileged access experience: IGA lifecycle and provisioning, access certification and entitlement management, and PAM with just-in-time elevation (e.g., Entra Privileged Identity Management); experience with workforce/partner identity across separated, non-federated identity stores - including externally issued contractor identities, B2B/guest, and Citrix - is a strong plus
  • Thorough understanding of cloud security and governance, in particular Microsoft Azure (landing zones, guardrails, policy-as-code)
  • Data protection expertise: encryption in transit and at rest, key management, and masking/tokenization for PHI and PII
  • Strong network and boundary security background, including segmentation and zero-trust network access
  • Hands-on Zscaler experience across the SSE platform - Zscaler Private Access (ZPA), Zscaler Internet Access (ZIA), and Zscaler Digital Experience (ZDX) - designing zero-trust access to replace legacy VPN, with an understanding of how Zscaler integrates with identity (Entra ID) and device posture
  • Proficiency with threat modeling (e.g., STRIDE) and risk assessment methodologies as they relate to integration and software engineering
  • Demonstrated experience operationalizing a threat-modeling program - establishing trigger criteria, applying a recognized methodology (e.g., STRIDE, PASTA, or attack-tree analysis), and integrating findings into architecture governance - not just performing individual threat models
  • Experience with security logging, monitoring, and detection, including SIEM and SOC integration
  • Experience with vulnerability management, SBOM, and DevSecOps / secure SDLC practices, including CI/CD security gates
  • Knowledge of TOGAF and a security architecture framework such as SABSA required; certification preferred (CISSP, CISSP-ISSAP, CCSP, SABSA, Microsoft SC-300 Identity and Access Administrator, Azure security certifications, or Zscaler certifications such as ZCCA/ZCCP)
  • Excellent conceptual and security design pattern skills irrespective of technology, and willingness to assume total ownership of security architecture from inception to delivery
  • Experience creating an effective framework and process model for establishing enterprise-wide security architecture
  • Ability and willingness to document security architecture, integrations, and dependencies for existing platforms and systems currently in use at SCA
  • Understanding and experience implementing the strategic alignment of business and security
  • Experience with third-party and vendor security risk management, particularly for Tier 1 PHI SaaS vendors
  • Demonstrated competency in communicating the value of security architecture to stakeholders and senior management
  • Strong interpersonal, verbal, and written communication skills, with the ability to develop and conduct executive-level presentations
  • Ability to collaborate with various levels of individuals - both IT and business
  • Self-directed with the ability to work effectively under tight deadlines
  • Experience with Mergers & Acquisitions, in areas of security diligence and integration, is desirable.

Benefits & conditions

At SCA Health, we offer a comprehensive benefits package to support your health, well-being, and financial future. Our offerings include medical, dental, and vision coverage, 401k plan with company match, paid time off, life and disability insurance, and more. Please visit, https://careers.sca.health/why-sca, to learn more about our benefits.

About the company

At SCA Health, we believe health care is about people - the patients we serve, the physicians we support and the teammates who push us forward. Behind every successful facility, procedure or innovation is a team of 15,000+ professionals working together, learning from each other and living out the mission, vision and values that define our organization.

As part of Optum, SCA Health is redefining specialty care by developing more accessible, patient-centered practice solutions for a network of more than 370 ambulatory surgical centers, over 400 specialty physician practice clinics and numerous labs and surgical hospitals. Our work spans a broad spectrum of services, all designed to support physicians, health systems and employers in delivering efficient, value-based care to patients without compromising quality or autonomy.

What sets SCA Health apart isn’t just what we do, it’s how we do it. Each decision we make is rooted in seven core values

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on careers.sca.health
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:46 min

Defining the security champion role in software teams

Tanya Janca · World Congress 2021

4:35 min

Setting up passwordless federated identity configuring OpenID Connect patterns

Marcel Lupo · LIVE

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

2:22 min

Adapting OpenID Connect for decentralized data sharing

Adam Larter Adam Larter · World Congress 2024

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

Videos

See all

Related articles

See all