Director, Chief Information Security Architect

Jobtailor

Oklahoma City (OK)

On-site

USD 140,000 - 190,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Jobtailor is seeking a senior Security Architect to define and evolve secure-by-design reference architecture across IAM, data protection, and cloud security in a healthcare-focused environment.

You will collaborate with business and IT to translate risk into roadmaps, ensure HIPAA/HITRUST compliance, and mentor a team of architects and engineers. This role requires CISSP and strong leadership; experience with AWS/Azure/GCP, NIST, and DevSecOps is preferred.

Qualifications

  • 8+ years of experience in information security, security architecture, or strategic and operations planning.
  • Experience across at least three disciplines such as IAM, cloud security, network security, application security, data protection, or security operations.
  • Knowledge of SaaS, IaaS, PaaS, APIs, microservices, event-driven IT, and predictive analytics and the security implications of each.
  • Depth in Zero Trust architecture, IAM, encryption and PKI, secure network design, cloud security (AWS/Azure/GCP), SIEM/SOAR, EDR, and DevSecOps.
  • Understanding of business models, operating models, financial models, cost-benefit analysis, budgeting, and risk management as applied to security investment.
  • Familiarity with NIST Cybersecurity Framework, NIST SP 800-53, and ISO/IEC 27001.
  • CISSP required; CISSP-ISSAP or SABSA preferred; TOGAF a plus.
  • HITRUST CSF and HIPAA Security Rule expertise, with healthcare regulatory/privacy obligations.
  • Understanding of operating models and agile methodologies for enterprise-scale delivery.
  • Leadership and communication skills to partner with stakeholders.

Responsibilities

  • Define, maintain, and evolve the enterprise information security reference architecture, standards, patterns, and guardrails.
  • Align security with business and IT across the democratized IT and clinical technology landscape.
  • Engage business, clinical, and IT stakeholders, building and maintaining trusted relationships.
  • Lead security architecture across IAM, data protection and encryption, network segmentation, cloud, application security, and Zero Trust.
  • Analyze threat, technology, and regulatory trends and disruptions, and assess their impact on risk-reduction outcomes.
  • Translate risk assessments and threat intelligence into architecture decisions and prioritized roadmaps.
  • Ensure security architecture aligns with HIPAA, HITRUST CSF, and healthcare regulatory requirements.
  • Provide security architecture review for new initiatives, cloud adoption, and third-party/vendor solutions.
  • Support project-centric and product-centric delivery models.
  • Communicate the value of the security architecture function and its services.
  • Drive evolution of the security architecture team’s services and operating model.
  • Coach and mentor other architects, engineers, product owners/managers, and stakeholders to instill security-thinking.

Skills

Security Architecture
Zero Trust Architecture
Identity And Access Management
Cloud Security
Data Protection
Encryption
Risk Management
Threat Intelligence
DevSecOps
Predictive Analytics

Education

Master’s or Bachelor’s degree in cybersecurity, computer science, information systems, or related field

Tools

AWS
Azure
GCP
SIEM
SOAR
EDR
NIST CSF
ITIL
Agile Methodologies
Lean Methodologies

Job description

  • Define, maintain, and evolve the enterprise information security reference architecture, standards, patterns, and guardrails that enable secure-by-design and secure-by-default delivery.
  • Facilitate alignment between security, business, and IT, and across the democratized IT and clinical technology landscape.
  • Engage business, clinical, and IT stakeholders, building and maintaining trusted relationships.
  • Lead security architecture across identity and access management, data protection and encryption, network segmentation, cloud, application security, and Zero Trust.
  • Analyze threat, technology, and regulatory trends and disruptions, and assess their impact on targeted business and risk-reduction outcomes.
  • Translate risk assessments and threat intelligence into architecture decisions and prioritized roadmaps that visualize the future state and trigger long-term planning.
  • Ensure security architecture aligns with HIPAA, HITRUST CSF, and other applicable healthcare and privacy regulatory requirements.
  • Provide security architecture review and guidance for new initiatives, major projects, cloud adoption, medical device and IoT integration, mergers and acquisitions, and third-party/vendor solutions.
  • Support various operating models such as project-centric and product-centric delivery.
  • Communicate the value of the security architecture function and its portfolio of services.
  • Drive the evolution of the security architecture team’s services and operating model.
  • Coach and mentor other architects, engineers, product owners/managers, and business stakeholders to instill security-architecture thinking.
Requirements
  • Master’s or bachelor’s degree in cybersecurity, computer science, computer engineering, information systems, or a related field of study, or equivalent experience.
  • 8+ years of experience in information security, security architecture, or strategic and operations planning, or experience as a security architecture consultant.
  • 8+ years of experience across at least three disciplines, such as security architecture, identity and access management, cloud security, network and infrastructure security, application/product security, data protection, or security operations in a multitier environment.
  • Knowledge of business ecosystems, SaaS, infrastructure as a service (IaaS), platform as a service (PaaS), SOA, APIs, microservices, event-driven IT, and predictive analytics, and the security implications of each.
  • Depth in Zero Trust architecture, IAM, encryption and PKI, secure network design, cloud security (AWS/Azure/GCP), SIEM/SOAR, EDR, and DevSecOps.
  • Understanding of business models, operating models, financial models, cost-benefit analysis, budgeting, and risk management as applied to security investment.
  • Insight into information management practices, system development life cycle management, IT service management, agile and lean methodologies, infrastructure and operations, and EA and ITIL frameworks.
  • Working knowledge of NIST Cybersecurity Framework, NIST SP 800-53, and ISO/IEC 27001.
  • CISSP required; CISSP-ISSAP (Information Systems Security Architecture Professional) or SABSA strongly preferred; TOGAF a plus.
  • HITRUST CSF and HIPAA Security Rule expertise, with a strong understanding of healthcare regulatory and privacy obligations.
  • Understanding of various operating models such as project-centric and product-centric, and different agile principles, methodologies, and frameworks, especially those designed to be scaled at the enterprise level.
  • Effective leadership skills with exceptional soft and interpersonal skills, including teamwork, facilitation, and negotiation.
  • Written and verbal communication skills with the ability to present complex information in a clear, concise manner to all audiences.
Core Competencies

Demonstrates expertise in security architecture, including Zero Trust, IAM, and cloud security, while ensuring compliance with HIPAA and HITRUST CSF. Capable of translating risk assessments into actionable architecture decisions and fostering collaboration among diverse stakeholders.

Highest-signal resume keywords
  • Security Architecture
  • Zero Trust Architecture
  • Identity And Access Management
  • CISSP Certification
  • HIPAA Compliance
ATS Optimization Keywords
Hard Skills
  • Information Security
  • Data Protection
  • Cloud Security
  • Network Security
  • Application Security
  • Encryption
  • Risk Management
  • Threat Intelligence
  • DevSecOps
  • Predictive Analytics
Soft Skills
  • Leadership
  • Teamwork
  • Facilitation
  • Negotiation
  • Communication
Certifications & Qualifications
  • CISSP
  • CISSP-ISSAP
  • TOGAF
Industry Keywords
  • Healthcare Compliance
  • HITRUST CSF
  • HIPAA Security Rule
  • Information Management Practices
  • System Development Life Cycle
Tools & Technologies
  • AWS
  • Azure
  • GCP
  • SIEM
  • SOAR
  • EDR
  • NIST Cybersecurity Framework
  • ITIL Framework
  • Agile Methodologies
  • Lean Methodologies
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Enterprise Technology Architect
Senior Enterprise Technology Architect

Jobtailor • Little Rock (AR)

On-site
USD 120,000 - 190,000
Senior Software Architect
Senior Software Architect

Jobtailor • Washington

On-site
USD 170,000 - 210,000
Principal Security Engineer
Principal Security Engineer

Jobtailor • Town of Texas (WI)

On-site
USD 140,000 - 190,000
Associate Information Security Engineer
Associate Information Security Engineer

Jobtailor • Louisiana (MO)

On-site
USD 90,000 - 130,000
Senior Application Security Architect
Senior Application Security Architect

Jobtailor • Cary (NC)

On-site
USD 120,000 - 180,000
Senior Lead Info Security Architect
Senior Lead Info Security Architect

Jobtailor • Illinois

On-site
USD 150,000 - 230,000
Senior Manager, Information Security
Senior Manager, Information Security

Jobtailor • North Carolina

On-site
USD 140,000 - 180,000
Senior System Architect
Senior System Architect

Jobtailor • Kentucky

On-site
USD 120,000 - 180,000
Security Architect
Security Architect

Digital-Global-Connectors • McLean (VA)

Hybrid
USD 130,000 - 180,000
Security Architect
Security Architect

Digital Global Connectors • McLean (VA)

Hybrid
USD 140,000 - 180,000