Information Security Architect

Health Management Associates

$120K — $145K *
US-AnywhereRemote in United States
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • In-depth knowledge of security architecture, frameworks, standards, risk management, and threat assessment.
  • Hands-on experience with Azure and/or AWS environment security.
  • Familiarity with identity, network, workload, application, and endpoint security controls.
  • Expertise in EDR platforms, malware investigation, threat hunting, and incident response.
  • Experience with firewalls, IDS/IPS, FortiGate/Fortinet, and FortiManager security platforms.
  • Knowledge of application security practices, including secure design and automation.
  • Awareness of compliance standards like HIPAA, SOC 2, HITRUST, and disaster recovery practices.

Responsibilities

  • Design and manage security architecture for on-premises and cloud environments.
  • Develop and enforce security policies and guidelines based on regulatory frameworks.
  • Lead security assessments and develop risk mitigation strategies.
  • Conduct threat hunting and manage incident response efforts through resolution.
  • Evaluate and maintain security technologies to ensure consistent governance.
  • Secure application development with a focus on AI systems and compliance.
  • Collaborate with IT and development teams to integrate security practices.

Benefits

  • Professional development opportunities and mentoring.
  • Collaborative work environment with IT and development teams.
  • Involvement in innovative security initiatives, particularly in AI.
  • Flexible work arrangements and potential for remote work.
Full Job Description
Overview

Job Summary

The Information Security Architect is responsible for designing, implementing, and managing the organization's security infrastructure. This role involves developing and enforcing security policies, ensuring the protection of sensitive data, and mitigating security risks across the enterprise.

Responsibilities

Work Performed and Job Requirements

  • Security Architecture and Engineering
    • Design, implement, and govern security architecture for on-premises and cloud environments, including Azure and AWS identity, network, workload, and data-protection controls.
  • Security Governance and Standards
    • Develop, maintain, and enforce security policies, standards, guidelines, and architecture principles aligned with applicable regulatory and security frameworks.
  • Security Assessment and Risk Management
    • Lead security assessments, audits, penetration-testing activities, vulnerability reviews, and configuration assessments. Develop risk-based mitigation strategies addressing least privilege, RBAC, hardening, encryption, TLS, network security, and SaaS controls.
  • Threat Detection and Incident Response
    • Conduct threat monitoring and proactive threat hunting; independently investigate, triage, and run down malware and EDR alerts (e.g., SentinelOne) through containment and resolution.
    • Develop and manage incident response plans, and lead incident response efforts, malware analysis, and forensic investigations through resolution.
  • Security Technology Architecture
    • Evaluate, recommend, and maintain security technologies, including firewalls, IDS/IPS, encryption solutions, endpoint security platforms, and related network controls. Leverage centralized management through FortiManager to maintain consistent Fortinet policy, configuration, and governance across the environment.
  • Application and Cloud Security
    • Secure in-house and cloud-hosted application development through secure design review, code and configuration review, and scripting and automation across the full stack.
    • Provide security architecture guidance for AI-enabled and agentic AI systems, including review of technology stacks, data flows, tool and API access, identity and permission boundaries, prompt and output controls, logging, monitoring, vendor/model risk, and governance requirements to support responsible and compliant AI use.
  • Compliance, Resilience, and Audit Support
    • Ensure compliance with applicable laws, regulations, and standards (HIPAA, SOC 2, HITRUST, GDPR, etc.), and develop and enforce security governance frameworks.
    • Support SOC 2 audits, penetration testing engagements, and disaster recovery and business continuity planning, documentation, and testing.
  • Collaboration and Security Enablement
    • Partner with IT, development, and business teams to integrate security into organizational processes.
    • Mentor staff and produce clear technical documentation, procedures, and architecture diagrams.
  • All other duties as assigned.
Qualifications

Knowledge, Skills, and Abilities

  • In-depth knowledge of security architecture, frameworks, standards, risk management, and threat assessment.
  • Demonstrated hands-on experience designing and securing Azure and/or AWS environments.
  • Knowledge of identity, network, workload, data, application, and endpoint security controls.
  • Experience with EDR platforms, malware investigation, threat hunting, and incident response.
  • Experience with firewalls, IDS/IPS, encryption, FortiGate/Fortinet, FortiManager, or comparable security platforms.
  • Application security knowledge, including secure design, code and configuration review, scripting, and automation.
  • Knowledge of HIPAA, SOC 2, HITRUST, penetration testing, disaster recovery, and business continuity practices.
  • Knowledge of security considerations for AI-enabled and agentic AI systems, including generative AI, AI application stacks, secure development, data protection, model and vendor risk, identity and access controls, monitoring, and governance frameworks for responsible AI use.
  • Strong analytical, problem-solving, organizational, and project-management skills.
  • Excellent verbal and written communication skills, with the ability to mentor others and explain technical risk to varied audiences.
  • Ability to produce clear technical and user-facing documentation, procedures, and architecture diagrams.
Additional Info

#LI-BR1

Similar Jobs

More Jobs at Health Management Associates

More Information Technology Jobs

Find similar Information Security Architect jobs: