
Enterprise Cybersecurity Architect
Posted 2 days ago

Posted 2 days ago
This is a fully remote position, open to applicants in Texas.
• Develop, sustain, and oversee PAM Health’s enterprise security architecture, technical security standards, design patterns, and reference architectures.
• Evaluate enterprise, cloud, clinical, network, application, data, artificial intelligence, and medical device initiatives for security requirements.
• Perform threat modeling and security design reviews for systems, major changes, integrations, and third-party solutions.
• Establish security requirements and architecture guardrails in accordance with NIST, HIPAA, MITRE ATT&CK, OWASP, and relevant regulations.
• Identify architectural risks, document controls, recommend remediation strategies, and communicate both technical and clinical implications.
• Set up secure design standards for cloud, identity, network, endpoint, application, data protection, logging, monitoring, and incident response.
• Collaborate with IT, Network Operations, Clinical Informatics, Compliance, Privacy, Legal, and business leaders.
• Provide technical guidance and oversight to managed security service providers, vendors, consultants, and third parties.
• Support application security through secure development requirements, architecture reviews, vulnerability management, penetration testing, and remediation guidance.
• Assess AI and machine learning systems for data protection, access control, model risk, dependencies, and misuse scenarios.
• Evaluate medical devices and connected clinical technologies for cybersecurity risks and suggest compensating controls.
• Assist with security incidents through architecture analysis, containment guidance, root-cause analysis, and recommendations for preventing recurrence.
• Stay informed about emerging threats, security technologies, healthcare cybersecurity requirements, and industry best practices.
• Mentor security and IT personnel and promote consistent security standards throughout the enterprise.
• Coach, assess, develop, and motivate staff; set expectations and acknowledge achievements.
• Advocate for customer service, confidentiality, safety, OSHA training, universal precautions, and emergency procedures.
• Provide support for significant security incidents outside regular business hours as needed.
• Bachelor’s degree in Computer Science, Cybersecurity, Engineering, Information Systems, or a related technical field, or an equivalent combination of education and experience.
• Certification as a Certified Information Systems Security Professional (CISSP) must be obtained within six (6) months of hire and maintained in good standing.
• A minimum of ten (10) years of progressive experience in cybersecurity.
• At least seven (7) years of cybersecurity experience in healthcare, including provider, health system, or similarly regulated clinical environments.
• Five (5) years of experience in a security architecture or senior technical role.
• Three (3) years of application security experience.
• Proven experience providing technical direction to third-party security providers and managed security service providers.
• Demonstrated knowledge of the OWASP Top 10 and secure development practices.
• Familiarity with MITRE ATT&CK, the NIST Cybersecurity Framework, and the HIPAA Security Rule.
• Ability to convey technical risk in terms of business and clinical impact for executive and clinical audiences.
• Excellent written and verbal communication skills.
• Capability to produce highly technical architectural documentation and explain complex concepts to non-technical executive leadership.
• Facility access, screening, and health requirements may apply during visits to clinical facilities.
• Preferred: Master’s degree in Computer Science, Cybersecurity, or a related technical field.
• Preferred certifications include GDSA, SABSA, CCSP, OSCP, GPEN, or HCISPP.
• Preferred experience with medical and connected clinical device security, penetration testing, red team operations, adversarial design review, AI/ML security, HITRUST, SOC 2 Type II, ISO 27001, 42 CFR Part 2, PCI DSS, FDA software-as-a-medical-device requirements, and geographically distributed clinical environments.
• Familiarity with OWASP Top 10 for Large Language Model Applications, NIST AI Risk Management Framework, and MITRE ATLAS is preferred.
• Experience in cloud security architecture across multiple cloud service providers is preferred.
• Remote work arrangement.
• Travel reimbursement or support for travel to facilities across the enterprise (not explicitly stated as a benefit).
• Opportunities for professional development through professional organizations and/or continuing education.
• Employee health requirements and OSHA-required training.
• Chance to mentor and develop security and information technology staff.
Sony Interactive Entertainment
Squads
Neo4j
PingWind Inc. (SDVOSB)
Get handpicked remote jobs straight to your inbox weekly.