Security Architect

Texas Health and Human Services Commission

• $108K — $130K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in cybersecurity, computer science, or related field.
  • 7 years of experience in information security or systems security analysis.
  • 3 years in security architecture or design work.
  • Experience with Texas state agency cybersecurity frameworks and programs.
  • Relevant certifications such as CISSP, CCSP, or TOGAF preferred.

Responsibilities

  • Develop and maintain the agency's enterprise security architecture and reference architectures.
  • Define agency security standards and secure design patterns based on regulatory frameworks.
  • Evaluate proposed solutions for compliance with security standards as part of the architecture review process.
  • Document common and hybrid control baselines for enterprise platforms.
  • Lead the rationalization of the security tooling portfolio to reduce redundancy and overhead.
  • Assess cloud services against TXRAMP requirements and advise on compliance pathways.
  • Advise leadership on emerging threats and mentor staff on secure design practices.

Benefits

  • Comprehensive insurance options for employees and their families.
  • Retirement plans to support long-term financial security.
  • Flexible work schedule to promote work-life balance.
Full Job Description
Work Hours

Monday through Friday, 40 hours a week with occasional evening, weekend hours and holidays. Hours may change based on business need.

General Description

Join Information Security Division (ISD) as a Security Architect. This role performs advanced cybersecurity analysis and security architecture support work for the ISD. Serves as the agency's principal security architect responsible for defining the enterprise security architecture, supporting security standards, and common control baselines that govern how security is designed into agency platforms, systems, and services. Serves as the ISD counterpart to the Enterprise Architect in Enterprise IT: the Security Architect will support the defining of security standards, control baselines, and security reference architectures; the Enterprise Architect embeds them into enterprise platforms as inheritable common controls. Aligns security architecture with TAC 477, the Texas Cybersecurity Framework, NIST SP 80053, and TXRAMP requirements. This is an individual contributor position with no supervisory responsibilities.

Minimum Qualifications
  • Graduation from an accredited college or university with major coursework in cybersecurity, computer science, management information systems, computer engineering, or a related field.
  • Seven (7) years of progressively responsible experience in information security, security engineering, or systems security analysis, including at least three (3) years performing security architecture or security design work.


Preferred Qualifications
  • Experience in a Texas state agency or other publicsector environment, including TAC 477, Texas Cybersecurity Framework, TXCC security programs, and TXRAMP.
  • Experience defining common control frameworks or control inheritance models (e.g., NIST SP 80053 common/hybrid controls) and authoring control implementation statements.
  • Experience rationalizing or consolidating security tooling portfolios with measurable cost or operational savings.
  • CISSP (ISSAP concentration preferred), CCSP, SABSA, GIAC security architecture credential (e.g., GDSA), or TOGAF certification.
  • Experience supporting security assessment and authorization (A&A) or audit activities using inherited control documentation.


Substitutions
  • One (1) additional year of minimum experience as stated above may substitute for thirty (30) semester hours of the required education with a maximum substitution of 120 semester hours (four years).


Licenses and Certifications
  • Preferred: CISSP (ISSAP concentration preferred), CCSP, SABSA, GIAC security architecture credential (e.g., GDSA), or TOGAF certification.


Essential Job Duties:

Security Architecture Strategy Support & Standards
  • Support with developing and maintaining the agency's enterprise security architecture, security reference architectures, and targetstate security patterns aligned with the enterprise architecture roadmap, agency risk posture, and TXCC statewide security direction.
  • Assist in defining agency security standards, secure design patterns, and platform security requirements derived from TAC 477, the Texas Cybersecurity Framework, NIST SP 80053, and the agency information security policies and control standards.
  • Serve as the Information Security Division's voting member of the architecture review process; evaluate proposed solutions, platforms, and exceptions for conformance with security standards and risk tolerance.

Common Control Baseline Analysis & Inheritance
  • Define and document common and hybrid control baselines for enterprise platforms (identity, logging, encryption, configuration management, vulnerability management), including implementation statements and inheritance models consumable by system owners.
  • Partner with the Enterprise Architect to ensure enterprise platforms operationalize defined control baselines so that consuming systems inherit controls consistently, reducing persystem control implementation and assessment burden.
  • Validate that implemented platform controls satisfy the defined baselines; maintains traceability between platform capabilities, control statements, and compliance requirements to support assessment and audit activities.

Security Tooling Rationalization
  • Define the security tooling reference architecture and leads rationalization of the security tooling portfolio to eliminate duplicative agents, overlapping capabilities, and administrative overhead across platforms.
  • Establish standard, enterprisewide implementations for core security services identity and access management, logging and SIEM, endpoint protection, and encryption consumed uniformly by all platforms.
  • Coordinate with Enterprise IT on platformlevel deployment of consolidated security tooling and measure resulting cost and operational savings.

Compliance & Risk Alignment
  • Assess cloud services and platforms against TXRAMP requirements and advise on certification pathways, continuous monitoring obligations, and inherited control documentation.
  • Support security risk assessments of proposed architectures, major platform changes, and consolidation initiatives; document residual risk and recommend compensating controls.
  • Review security exception requests against defined standards and advise the CISO on risk impact decisions.

Advisory & Expertise Development
  • Advise the CISO and ISD leadership on emerging threats, security technologies, and architectural implications of agency modernization initiatives.
  • Mentor ISD and Enterprise IT staff on secure design practices; develop and maintain security architecture documentation, patterns, and standards to institutionalize knowledge.
  • Represent the agency in interagency, TXCC, and security community workgroups.
  • Perform related work as assigned. May also perform work listed in previous levels of the Cybersecurity Analyst series.

Maximize Your Earnings!

At the Comptroller's office, we know potential employees are looking for more than just a paycheck. The agency offers a strong benefits package for you and your family. Insurance, retirement plans, and a flexible work schedule are just the start. See our benefits offering

Similar Jobs

More Jobs at Texas Health and Human Services Commission

More Information Technology Jobs

Find similar Security Architect jobs: