7 часов назад
Sr Staff Security Architect (Healthcare)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Sr Staff Security Architect (Healthcare): Defining and governing security architecture for cloud infrastructure, applications, corporate systems, and virtual care delivery with an accent on PHI protection, threat modeling, and secure-by-default design. Focus on building scalable architecture review processes, establishing zero trust and identity controls, and translating HIPAA and SOC 2 requirements into concrete technical safeguards.
Location: Remote in the United States or Toronto, Canada
Company
provides telehealth support solutions that help companies deliver virtual care across all 50 U.S. states.
What you will do
- Own and continuously evolve security architecture across cloud infrastructure, applications, and corporate systems.
- Lead threat modeling and architecture reviews for product, engineering, infrastructure, patient-facing interfaces, and PHI data flows.
- Design a scalable, risk-tiered architecture review process with self-service patterns and clear review criteria.
- Define application security standards covering secure design, API security, OAuth/OIDC, SAML, data protection, HL7, and FHIR.
- Establish zero trust architecture and govern identity, network, endpoint, key, secrets, certificate, and third-party integration controls.
- Translate GRC, privacy, audit, HIPAA, and SOC 2 requirements into architectural controls while mentoring the security team.
Requirements
- Bachelor’s degree in Computer Science, Information Security, or a related field, or equivalent experience.
- 10+ years of progressive security experience, including at least 5 years in security architecture across enterprise and cloud environments.
- Deep expertise in application, cloud, identity and access management, network, and data security.
- Experience with cloud security architecture, IAM, encryption, key and secrets management, PKI, and cloud-native security services.
- Proficiency in structured threat modeling, SSDLC, OWASP principles, and modern authentication and authorization patterns.
- Working knowledge of HIPAA Security Rule technical safeguards, HITRUST CSF, NIST CSF, and SOC 2, with the ability to communicate risk to technical and executive audiences.
Nice to have
- Healthcare, digital health, or other highly regulated industry experience.
- Production experience with zero trust architecture and scalable architecture review processes.
- Familiarity with HL7, FHIR, SABSA, or TOGAF security extensions.
- Experience mentoring senior engineers or establishing architecture practices from scratch.
Culture & Benefits
- Remote work with a relatively flat organizational structure.
- Autonomy, competence, and belonging are core organizational values.
- Medical, dental, and vision plans.
- Flexible spending or health savings accounts, flexible PTO, and 401(k) with company match.
- Life insurance, pet insurance, and additional benefits.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
2 дня назад
Cybersecurity Architect
163 700 - 245 500$
5 дней назад
Product Security Engineer III (Healthcare Security)
157 250 - 185 000$
5 дней назад
Senior Security Engineer | AppSec
3 дня назад
Senior Security Engineer I, AI
163 944 - 215 176$
9 часов назад
Principal Engineer – Security Architecture
7 часов назад