> Markdown version of [/jobs/ext/1825265-hpc-security-architect](https://www.wearedevelopers.com/jobs/ext/1825265-hpc-security-architect). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # HPC Security Architect - **Company:** Stony Brook University - **Location:** Stony Brook, NY, United States (Remote available) - **Experience:** Expert - **Salary:** $142,000.0 - $182,000.0 - **Contract:** Permanent contract - **Skills:** Cerner, Microsoft Access, Artificial Intelligence, Microsoft Azure, Clinical Data Repository, Cyber Security, Data Governance, Data Infrastructure, Data Security, Data Sharing, Linux, Distributed Systems, Ethernet, Federated Identity Management, General Parallel File Systems, Identity and Access Management, InfiniBand, Key Management, OnyX for Mac, OpenID, Security Assertion Markup Language (SAML), Software Vulnerability Management, Cloud Platform System, High Performance Computing, Containerization, Kubernetes, Storage Technologies, Information Technology, Slurm, Machine Learning Operations, SailPoint - **Published:** July 9, 2026 - **Apply:** https://dejobs.org/x/x/80D9808C3BFB42EAA9A8BF61AEDF98EE/job/ ## About the Role Bachelor's degree. In lieu of a degree, a combination of directly related full-time experience in cybersecurity, with experience in research computing or large-scale distributed systems totaling nine [9] years may be considered. Five [5] years of experience in cybersecurity, with experience in research computing or large-scale distributed systems. Experience in NIST 800-171, HIPAA, and regulated data environments. Experience with Identity and access management architectures. Experience with Network and system security design. Experience with Linux systems, high-performance networking, and storage architectures. Experience with translating complex regulatory requirements into technical implementations., Advanced degree (foreign equivalent or higher). Experience supporting HPC environments or research infrastructure. Experience in AI/ML security, model governance, and data provenance. Experience with federated identity (InCommon, SAML, OIDC) and research collaboration frameworks. Certified in CISSP, CISM, CCSP, or similar. ## Description The HPC Security Architect leads the design, implementation, and governance of security architecture across Stony Brook University's advanced research computing ecosystem, including AMA27 (https://researchconnect.stonybrook.edu/en/projects/category-i-ama27-sustainable-cyber-infrastructure-for-expanding-p/) , SeaWulf (https://rci.stonybrook.edu/HPC/understanding-SeaWulf) , NVWulf (https://rci.stonybrook.edu/HPC/nvwulf/about) , and ClinWulf (https://rci.stonybrook.edu/HPC/clinwulf/about) . This role establishes a comprehensive, risk-based security framework ensuring compliance with HIPAA, NIST 800-171, NIH GDS, and emerging AI governance standards. The incumbent operates at the intersection of research enablement and enterprise security, partnering with the Division of Information Technology (DoIT) (https://it.stonybrook.edu/) , Stony Brook Medicine IT (SBMIT), Research Security, IRB, and faculty to embed secure-by-design principles across compute, storage, data workflows, and collaborative research environments. The HPC Security Architect must have the ability to communicate with others effectively. HPC Security Architecture & Strategy * Design and maintain a multi-tier security architecture for research computing environments spanning SeaWulf, NVWulf, ClinWulf, and AMA27 (NSF Tier-1 HPC). * Define reference architectures for secure compute, storage (GPFS/Arcastream), and high-speed networking (InfiniBand). * Establish segmentation strategies (network, identity, workload isolation) across research tiers. * Lead adoption of zero trust principles in HPC and research environments. * Align HPC security strategy with institutional and SUNY-wide initiatives (e.g., Empire AI). Compliance & Regulatory Alignment * Lead implementation of security controls aligned to HIPAA Security Rule, NIST 800-171/CMMC, NIH Genomic Data Sharing (GDS) Policy, and federal export control requirements. * Partner with Research Security, Privacy, IRB, and Legal to define compliant research computing patterns and support Data Use Agreements (DUAs). * Enable secure data acquisition, storage, and sharing workflows. * Develop and maintain System Security Plans (SSPs) and supporting documentation for regulated environments. Identity, Access, and Data Security * Architect and enforce identity and access management (IAM) integration (e.g., SailPoint, federated access, MFA). * Implement role-based and attribute-based access controls for HPC and research datasets. * Define secure onboarding workflows for faculty, research staff, external collaborators, and federated/national computing environments (e.g., NSF ACCESS, Empire AI). * Oversee data protection strategies, including encryption, key management, and secure data lifecycle controls. Secure Research Environments & Data Governance * Design and operationalize tiered secure research environments (open, restricted, regulated). * Collaborate with Data Brokerage and Honest Broker services to ensure privacy-preserving data access. * Define secure data pipelines for clinical data (EMR integrations, TriNetX, OnCore/Cerner RPE), genomic and imaging data, and large-scale AI/ML datasets. * Establish controls for secure collaboration and data sharing, including external access frameworks. Threat Modeling, Risk Management & Incident Response * Conduct threat modeling for HPC and AI workloads, including supply chain and model security risks. * Lead risk assessments for new research initiatives and infrastructure deployments. * Partner with enterprise security teams to integrate HPC into SOC monitoring, vulnerability management, and incident response processes. * Develop playbooks for research-specific incident scenarios (e.g., data exfiltration, misuse of compute resources). Infrastructure & Platform Security Engineering * Provide security guidance for Linux-based HPC environments, container platforms (Singularity/Apptainer, Kubernetes), and scheduler systems (SLURM). * Define secure configurations for GPU systems, AI pipelines, high-performance storage systems (GPFS), and research cloud integrations (Azure HIPAA environments). * Support high-speed Networking (InfiniBand & Ultra Ethernet) design, including topology and switch configurations. * Familiarity with one or more of Cumulus, Mellanox Onyx, or SONiC NOSes. * Storage design, configuration, and benchmarking experience spanning high-speed flash, spinning disk, and archival solutions. Training, Outreach & Research Enablement * Develop and deliver security guidance and training tailored to researchers and technical staff. * Serve as a trusted advisor to faculty on secure research design and grant proposals. * Contribute to letters of support and DMSP guidance related to secure computing environments. Other duties and projects as assigned and appropriate to rank and area mission. Special Notes: This is a full-time appointment. FLSA Exempt position, not eligible for the overtime provisions of the FLSA. Minimum salary threshold must be met to maintain FLSA exemption. For this position, we are unable to sponsor candidates for work visas. SUNY implemented a hybrid telecommuting pilot program. This position has been approved to participate in the pilot, which allows for up to 5 remote days per pay period. ## Related Videos - [Running Secure Life Science Research at Scale using Hybrid GPU HPC and Kubernetes 🧬](https://www.wearedevelopers.com/videos/100355-running-secure-life-science-research-at-scale-using-hybrid-gpu-hpc-and-kubernetes) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Discover the open source trio you didn’t expect: .NET and PostgreSQL on Linux](https://www.wearedevelopers.com/videos/2042-discover-the-open-source-trio-you-didn-t-expect-net-and-postgresql-on-linux) ## Related Articles - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Top 6 Hackathons for Developers in 2023](https://www.wearedevelopers.com/magazine/263-top-6-hackathons-for-developers-in-2023) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [7 Cloud Computing Trends Coming in 2025 for Developers](https://www.wearedevelopers.com/magazine/412-7-cloud-computing-trends-coming-in-2025-for-developers)