Cyber Security Architect

VA Boston Healthcare System

Boston (MA)

On-site

USD 150,000 - 190,000

Full time

2 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

VA Boston Healthcare System seeks a Senior Cybersecurity Architect & Engineer to design, build, and defend a hybrid computing infrastructure across on‑prem and multi‑cloud environments. You will anchor controls within NIST CSF and SP 800‑53, ensuring auditable, hardened security posture across legacy data centers and cloud platforms.

You will join a cross-disciplinary team of clinicians, researchers, data scientists, and software engineers to innovate, define, manage, maintain, and implement

Qualifications

  • Bachelor's degree in Computer Science or higher; or equivalent mix of math, CS coursework.
  • Experience designing, implementing, and governing cybersecurity controls in hybrid on-prem/multi-cloud environments.
  • Ability to map regulatory controls to technical controls and produce artifacts for audits.

Responsibilities

  • Lead adoption of NIST CSF and NIST SP 800-53 across on-prem and cloud.
  • Translate compliance requirements into actionable controls and POA&Ms.
  • Design secure, resilient architectures bridging legacy and cloud platforms.
  • Develop and maintain security telemetry pipelines and centralized SIEM/SOAR alignment.
  • Oversee vulnerability/risk management and incident response escalation at Tier 3.

Skills

NIST CSF
Threat Modeling
Zero Trust
SIEM/SOAR
Cloud Security
IAM & PAM

Education

Bachelor's degree in Computer Science

Tools

NGFW
WAF
ZTNA
KMS
Terraform
Ansible
SSO

Job description

The role is based within the VA Boston Healthcare System, a leading biomedical research center that operates a high-performance computing (HPC) with petabyte-scale biomedical data on a multi-cloud and on-premises hybrid platform. The organization is seeking a senior Cybersecurity Architect & Engineer who designs, builds, and defends the organization's hybrid computing infrastructure while structurally anchoring all technical controls within recognized cybersecurity compliance frameworks. This dual-focus role bridges high-level strategic architecture with hands‑on engineering. The individual is responsible for adopting, implementing, and maintaining strict alignment with frameworks such as NIST (CSF, SP 800-53), ensuring a consistent, auditable, and hardened security posture across legacy on-premises data centers and multi-cloud environments

You will join a multidisciplinary team of clinicians, researchers, data scientists, and software engineers at a nationally recognized research Center. This role offers a unique opportunity to innovate, define, manage, maintain, and implement strong security measures for high-impact.

PRIMARY DUTIES:

Framework Adoption, Governance & Compliance Maintenance

  • Lead the evaluation, adoption, and end-to-end implementation of security frameworks, specifically focusing on the NIST Cybersecurity Framework (CSF) and NIST SP 800-53
  • Translate complex compliance framework requirements into actionable, quantifiable technical controls across on-premises hardware and multi-cloud services
  • Establish continuous monitoring programs to maintain a constant state of compliance, producing necessary artifacts, system security plans (SSPs), and evidence for internal and external audits
  • Map technical architectures directly to regulatory requirements and framework controls to identify, track, and remediate compliance gaps via structured Plans of Action and Milestones (POA&Ms).
  • Define governance, audit, and security strategy
  • Design and maintain secure, resilient blueprint architectures that unify legacy on-premises hardware, virtualized environments, and multi-cloud platforms in compliance with NIST standards
  • Perform comprehensive framework-aligned threat modeling on cross-environment integrations, evaluating risk patterns for data transitioning between on-premises infrastructure and cloud services
  • Establish and govern hybrid identity baselines, ensuring unified directory services, single sign-on (SSO), and privileged access management (PAM) across all environments.
Technical Security Engineering & Control Implementation
  • Define, design, build, and implement security architecture and security systems
  • Configure, optimize, and manage enterprise security tooling—including Next-Generation Firewalls (NGFW), Web Application Firewalls (WAF), and Zero Trust Network Access (ZTNA)—ensuring configurations match NIST baseline hardening guidelines
  • Build and maintain standardized Infrastructure as Code (IaC) templates to automate secure, compliant provisioning across multiple cloud providers and on-premises hypervisors
  • Manage enterprise cryptographic infrastructure, implementing NIST-approved encryption-at-rest, encryption-in-transit, and robust key management systems (KMS)
  • Design and fine-tune security telemetry pipelines to aggregate, correlate, and orchestrate log infrastructure into a centralized SIEM/SOAR platform to satisfy auditing requirements
  • Contribute to defining, designing, and implementing security policies and principles including system security, platform and infrastructure security, application security, user security, data security, data privacy, and data governance.
Vulnerability & Risk Management
  • Orchestrate unified vulnerability scanning and configuration assessment programs spanning on-premises bare-metal, virtual machines, and cloud-native assets
  • Serve as the tier-3 technical escalation point for security incidents, conducting advanced forensic log analysis across diverse cloud and on-premises infrastructure silos
  • Lead automated remediation initiatives to dynamically isolate compromised assets or adjust firewall rules during active security events based on incident response playbooks
MINIMUM QUALIFICATIONS:
  • MUST be a US Citizen and MUST clear a US government background check
  • Resume must indicate full-time or part-time and include hours for each position listed under work experience.

3. DEGREE: Bachelor's degree in computer science or higher, or bachelor's degree with 30 semester hours in a combination of mathematics, statistics, and computer science. At least 15 of the 30 semester hours must have included any combination of statistics and mathematics that included differential and integral calculus. All academic degrees and coursework must be from accredited or pre-accredited institutions.

4. EXPERIENCE: Experience must demonstrate progressively more complex computer scient work (systems design, architecture, research, etc.)

NOTE:

Reference OPM website for more information on Qualification Standards: https://www.opm.gov/policy-data-oversight/classification-qualifications/general-schedule-qualification-standards/1500/computer-science-series-1550/

PREFERRED QUALIFICATIONS:
  • Framework Mastery: Deep, practical knowledge of adopting and scaling the NIST Cybersecurity Framework (CSF), NIST SP 800-53, or ISO 27001 within high-scale enterprise environments
  • Multi-Cloud Expertise: Proven experience architecting and securing native services across major cloud platforms (AWS, Azure)
  • On-Premises Infrastructure: Deep technical knowledge of enterprise data center technologies, including VMware/Hyper-V virtualization, Active Directory, and physical networking hardware.
  • Network & Automation Engineering: Expert-level understanding of core protocols (TCP/IP, BGP, DNS, TLS) and experience utilizing modern IaC tools to enforce automated security compliance policies
  • Exceptional ability to scale security policies consistently across modern cloud-native architectures and legacy on-premises systems while maintaining strict compliance
  • Strong systemic thinking to analyze, map, and secure complex distributed data flows against regulatory baselines
  • Excellent technical communication skills to translate abstract compliance mandates into concrete technical directives for engineering teams
  • Practical working knowledge of cybersecurity tools (Okta, Ping Identity, and other industry-leading tools)
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity Architect
Cybersecurity Architect

Finezi Inc. • Rosemead (CA)

On-site
USD 130,000 - 160,000
Senior Security Engineer
Senior Security Engineer

Hiring Our Heroes • Arlington (VA)

On-site
USD 120,000 - 150,000
Senior Security Engineer
Senior Security Engineer

Zermount, Inc. • United States

On-site
USD 120,000 - 150,000
Senior Security Engineer
Senior Security Engineer

Zermount, Inc. • United States Virgin Islands

On-site
USD 100,000 - 150,000
Cyber Systems Architect, Senior Advisor
Cyber Systems Architect, Senior Advisor

Peraton • Herndon (VA)

On-site
USD 140,000 - 170,000
Cybersecurity Architect
Cybersecurity Architect

OneMain Financial • Washington

On-site
USD 140,000 - 200,000
Cybersecurity Architect
Cybersecurity Architect

KIHOMAC • Colorado Springs (CO)

On-site
USD 160,000 - 195,000
Health Care Plan (Medical, Dental & Vision)
Retirement Plan (401k, IRA)
Paid Time Off (Vacation, Sick & Public Holidays)
+2
Senior Cyber Security & Infrastructure Lead
Senior Cyber Security & Infrastructure Lead

eTeam • Cuyahoga Falls (OH)

Hybrid
USD 140,000 - 190,000
Cybersecurity Architect
Cybersecurity Architect

AITS Defence • Augusta (GA)

On-site
USD 120,000 - 150,000
Medical, Dental and Vision Insurance
Life Insurance
Paid Time Off (PTO)
+2
Cybersecurity SME
Cybersecurity SME

Ignite IT • Washington

Hybrid
USD 140,000 - 190,000
401(k)
401(k) matching
Dental insurance
+8