Назад
Company hidden
7 часов назад

Sr Staff Security Architect (Healthcare)

Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US/Canada
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Sr Staff Security Architect (Healthcare): Defining and governing security architecture for cloud infrastructure, applications, corporate systems, and virtual care delivery with an accent on PHI protection, threat modeling, and secure-by-default design. Focus on building scalable architecture review processes, establishing zero trust and identity controls, and translating HIPAA and SOC 2 requirements into concrete technical safeguards.

Location: Remote in the United States or Toronto, Canada

Company

hirify.global provides telehealth support solutions that help companies deliver virtual care across all 50 U.S. states.

What you will do

  • Own and continuously evolve security architecture across cloud infrastructure, applications, and corporate systems.
  • Lead threat modeling and architecture reviews for product, engineering, infrastructure, patient-facing interfaces, and PHI data flows.
  • Design a scalable, risk-tiered architecture review process with self-service patterns and clear review criteria.
  • Define application security standards covering secure design, API security, OAuth/OIDC, SAML, data protection, HL7, and FHIR.
  • Establish zero trust architecture and govern identity, network, endpoint, key, secrets, certificate, and third-party integration controls.
  • Translate GRC, privacy, audit, HIPAA, and SOC 2 requirements into architectural controls while mentoring the security team.

Requirements

  • Bachelor’s degree in Computer Science, Information Security, or a related field, or equivalent experience.
  • 10+ years of progressive security experience, including at least 5 years in security architecture across enterprise and cloud environments.
  • Deep expertise in application, cloud, identity and access management, network, and data security.
  • Experience with cloud security architecture, IAM, encryption, key and secrets management, PKI, and cloud-native security services.
  • Proficiency in structured threat modeling, SSDLC, OWASP principles, and modern authentication and authorization patterns.
  • Working knowledge of HIPAA Security Rule technical safeguards, HITRUST CSF, NIST CSF, and SOC 2, with the ability to communicate risk to technical and executive audiences.

Nice to have

  • Healthcare, digital health, or other highly regulated industry experience.
  • Production experience with zero trust architecture and scalable architecture review processes.
  • Familiarity with HL7, FHIR, SABSA, or TOGAF security extensions.
  • Experience mentoring senior engineers or establishing architecture practices from scratch.

Culture & Benefits

  • Remote work with a relatively flat organizational structure.
  • Autonomy, competence, and belonging are core organizational values.
  • Medical, dental, and vision plans.
  • Flexible spending or health savings accounts, flexible PTO, and 401(k) with company match.
  • Life insurance, pet insurance, and additional benefits.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →