Job DescriptionThe Dir Chief Information Security Architect proactively and holistically defines, guides, and governs the enterprise information security architecture, partnering with clinical, business, and IT leaders, product managers, product owners, and distributed product delivery teams to embed security into transformation and optimization initiatives. Reporting to the VP & Chief Information Security Officer, this leader translates business strategy, risk appetite, and regulatory obligations into secure, resilient, and scalable architecture. The role's scope of activities includes helping the organization achieve targeted outcomes related to protecting patient and enterprise data, reducing cyber risk, enabling safe clinical and digital innovation, optimizing security investment, and improving resilience. They focus on the development of the security strategy and the enterprise security architecture of the organization as a whole.
ResponsibilitiesThe Dir Chief Information Security Architect responsibilities include, but are not limited to, the following:
- Define, maintain, and evolve the enterprise information security reference architecture, standards, patterns, and guardrails that enable secure-by-design and secure-by-default delivery.
- Facilitate alignment between security, business, and IT, and across the democratized IT and clinical technology landscape.
- Engage business, clinical, and IT stakeholders, building and maintaining trusted relationships.
- Lead security architecture across identity and access management, data protection and encryption, network segmentation, cloud, application security, and Zero Trust.
- Analyze threat, technology, and regulatory trends and disruptions, and assess their impact on targeted business and risk-reduction outcomes.
- Translate risk assessments and threat intelligence into architecture decisions and prioritized roadmaps that visualize the future state and trigger long-term planning.
- Ensure security architecture aligns with HIPAA, HITRUST CSF, and other applicable healthcare and privacy regulatory requirements.
- Provide security architecture review and guidance for new initiatives, major projects, cloud adoption, medical device and IoT integration, mergers and acquisitions, and third-party/vendor solutions.
- Support various operating models such as project-centric and product-centric delivery.
- Communicate the value of the security architecture function and its portfolio of services.
- Drive the evolution of the security architecture team's services and operating model.
- Coach and mentor other architects, engineers, product owners/managers, and business stakeholders to instill security-architecture thinking.
Qualifications- Master's or bachelor's degree in cybersecurity, computer science, computer engineering, information systems, or a related field of study, or equivalent experience.
- 8+ years of experience in information security, security architecture, or strategic and operations planning, or experience as a security architecture consultant.
- 8+ years of experience across at least three disciplines, such as security architecture, identity and access management, cloud security, network and infrastructure security, application/product security, data protection, or security operations in a multitier environment.
- Knowledge of business ecosystems, SaaS, infrastructure as a service (IaaS), platform as a service (PaaS), SOA, APIs, microservices, event-driven IT, and predictive analytics, and the security implications of each.
- Depth in Zero Trust architecture, IAM, encryption and PKI, secure network design, cloud security (AWS/Azure/GCP), SIEM/SOAR, EDR, and DevSecOps.
- Understanding of business models, operating models, financial models, cost-benefit analysis, budgeting, and risk management as applied to security investment.
- Insight into information management practices, system development life cycle management, IT service management, agile and lean methodologies, infrastructure and operations, and EA and ITIL frameworks.
- Working knowledge of NIST Cybersecurity Framework, NIST SP 800-53, and ISO/IEC 27001.
- CISSP required; CISSP-ISSAP (Information Systems Security Architecture Professional) or SABSA strongly preferred; TOGAF a plus.
- HITRUST CSF and HIPAA Security Rule expertise, with a strong understanding of healthcare regulatory and privacy obligations.
- Understanding of various operating models such as project-centric and product-centric, and different agile principles, methodologies, and frameworks, especially those designed to be scaled at the enterprise level.
- Effective leadership skills with exceptional soft and interpersonal skills, including teamwork, facilitation, and negotiation.
- Written and verbal communication skills with the ability to present complex information in a clear, concise manner to all audiences.