HPC Security Architect

Stony Brook University

New York (NY)

On-site

USD 140,000 - 190,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Stony Brook University invites applications for an HPC Security Architect to design, implement, and govern security across its advanced research computing ecosystem, including AMA27, SeaWulf, NVWulf, and ClinWulf.

The role partners with DoIT, SBMIT, Research Security, IRB, and faculty to embed secure-by-design principles, ensure HIPAA/NIST 800-171/NIH GDS compliance, and advance AI governance in a university-scale HPC environment.

Qualifications

  • Bachelor's degree; or nine years of related cybersecurity experience in research computing or large-scale distributed systems.
  • 5+ years of cybersecurity experience in research computing or large-scale distributed systems.
  • Experience with HIPAA, NIST 800-171, and regulated data environments.
  • Experience with Identity and access management architectures.
  • Experience with network and system security design.
  • Experience with Linux systems, high-performance networking, and storage architectures.
  • Ability to translate complex regulatory requirements into technical implementations.

Responsibilities

  • Lead design, implementation, and governance of security architecture across Stony Brook University's advanced research computing ecosystem (AMA27, SeaWulf, NVWulf, ClinWulf).
  • Establish a comprehensive, risk-based security framework ensuring HIPAA, NIST 800-171, NIH GDS, and AI governance compliance.
  • Collaborate with DoIT, SBMIT, Research Security, IRB, and faculty to embed secure-by-design principles across compute, storage, data workflows, and collaborative research environments.
  • Design and maintain multi-tier security architecture for research computing environments spanning SeaWulf, NVWulf, ClinWulf, and AMA27 (NSF Tier-1 HPC).
  • Define reference architectures for secure compute, storage (GPFS/Arcastream), and high-speed networking (InfiniBand).
  • Establish segmentation strategies across research tiers and lead adoption of zero trust principles in HPC environments.
  • Align HPC security strategy with institutional and SUNY-wide initiatives (Empire AI).
  • Architect and enforce IAM integration (e.g., SailPoint, federated access, MFA); implement RBAC/ABAC for HPC datasets.
  • Design secure data pipelines for clinical/genomic/imaging datasets; oversee data protection strategies and encryption.

Skills

Cybersecurity
IAM architectures
Network security design
Linux systems
High-performance networking
Storage architectures
Regulatory translation
Research computing

Education

Bachelor's degree
Experience in cybersecurity 9 years in lieu of degree

Tools

SailPoint
Federated access (InCommon)
SAML/OIDC
GPFS/Arcastream
InfiniBand

Job description

HPC Security Architect
Required Qualification

(as evidenced by an attached resume)

Bachelor's degree. In lieu of a degree, a combination of directly related full-time experience in cybersecurity, with experience in research computing or large-scale distributed systems totaling nine [9] years may be considered. Five [5] years of experience in cybersecurity, with experience in research computing or large-scale distributed systems. Experience in NIST 800-171, HIPAA, and regulated data environments. Experience with Identity and access management architectures. Experience with Network and system security design. Experience with Linux systems, high-performance networking, and storage architectures. Experience with translating complex regulatory requirements into technical implementations.

Preferred Qualifications:
  • Advanced degree (foreign equivalent or higher).
  • Experience supporting HPC environments or research infrastructure.
  • Experience in AI/ML security, model governance, and data provenance.
  • Experience with federated identity (InCommon, SAML, OIDC) and research collaboration frameworks.
  • Certified in CISSP, CISM, CCSP, or similar.
Brief Description of Duties:

The HPC Security Architect leads the design, implementation, and governance of security architecture across Stony Brook University's advanced research computing ecosystem, including AMA27 (https://researchconnect.stonybrook.edu/en/projects/category-i-ama27-sustainable-cyber-infrastructure-for-expanding-p/) , SeaWulf (https://rci.stonybrook.edu/HPC/understanding-SeaWulf) , NVWulf (https://rci.stonybrook.edu/HPC/nvwulf/about) , and ClinWulf (https://rci.stonybrook.edu/HPC/clinwulf/about) . This role establishes a comprehensive, risk-based security framework ensuring compliance with HIPAA, NIST 800-171, NIH GDS, and emerging AI governance standards. The incumbent operates at the intersection of research enablement and enterprise security, partnering with the Division of Information Technology (DoIT) (https://it.stonybrook.edu/) , Stony Brook Medicine IT (SBMIT), Research Security, IRB, and faculty to embed secure-by-design principles across compute, storage, data workflows, and collaborative research environments. The HPC Security Architect must have the ability to communicate with others effectively.

HPC Security Architecture & Strategy
  • Design and maintain a multi-tier security architecture for research computing environments spanning SeaWulf, NVWulf, ClinWulf, and AMA27 (NSF Tier-1 HPC).
  • Define reference architectures for secure compute, storage (GPFS/Arcastream), and high-speed networking (InfiniBand).
  • Establish segmentation strategies (network, identity, workload isolation) across research tiers.
  • Lead adoption of zero trust principles in HPC and research environments.
  • Align HPC security strategy with institutional and SUNY-wide initiatives (e.g., Empire AI).
Compliance & Regulatory Alignment
  • Lead implementation of security controls aligned to HIPAA Security Rule, NIST 800-171/CMMC, NIH Genomic Data Sharing (GDS) Policy, and federal export control requirements.
  • Partner with Research Security, Privacy, IRB, and Legal to define compliant research computing patterns and support Data Use Agreements (DUAs).
  • Enable secure data acquisition, storage, and sharing workflows.
  • Develop and maintain System Security Plans (SSPs) and supporting documentation for regulated environments.
Identity, Access, and Data Security
  • Architect and enforce identity and access management (IAM) integration (e.g., SailPoint, federated access, MFA).
  • Implement role-based and attribute-based access controls for HPC and research datasets.
  • Define secure onboarding workflows for faculty, research staff, external collaborators, and federated/national computing environments (e.g., NSF ACCESS, Empire AI).
  • Oversee data protection strategies, including encryption, key management, and secure data lifecycle controls.
Secure Research Environments & Data Governance
  • Design and operationalize tiered secure research environments (open, restricted, regulated).
  • Collaborate with Data Brokerage and Honest Broker services to ensure privacy-preserving data access.
  • Define secure data pipelines for clinical data (EMR integrations, TriNetX, OnCore/Cerner RPE), genomic and imaging data, and large-scale AI/ML datasets.
  • Establish controls for secure collaboration and data sharing, including external access frameworks.
Threat Modeling, Risk Management & Incident Response
  • Conduct threat modeling for HPC and AI workloads, including supply chain and model security risks.
  • Lead risk assessments for new research initiatives and infrastructure deployments.
  • Partner with enterprise security teams to integrate HPC into SOC monitoring, vulnerability management, and incident response processes.
  • Develop playbooks for research-specific incident scenarios (e.g., data exfiltration, misuse of compute resources).
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

HPC Security Architect: Secure Research Compute
HPC Security Architect: Secure Research Compute

Stony Brook University • New York (NY)

On-site
USD 140,000 - 190,000
Senior HPC Administrator, Secure HPC Platform - High Performance Computational and Data Ecosystem - Technology Specialist III - Hybrid/Onsite
Senior HPC Administrator, Secure HPC Platform - High Performance Computational and Data Ecosystem - Technology Specialist III - Hybrid/Onsite

Mount Sinai • United States

On-site
USD 130,000 - 170,000
Senior HPC Administrator: Secure, Compliant Compute Platform
Senior HPC Administrator: Secure, Compliant Compute Platform

Mount Sinai • United States

On-site
USD 130,000 - 170,000
HPC Engineer - Privacy Research Program
HPC Engineer - Privacy Research Program

Tufts University • Massachusetts

On-site
USD 89,000 - 134,000
Senior HPC Admin: Secure Regulated Research Compute
Senior HPC Admin: Secure Regulated Research Compute

Mount Sinai Morningside • New York (NY)

On-site
USD 113,000 - 202,000
HPC Engineer - Privacy Research Program
HPC Engineer - Privacy Research Program

Tufts University • Boston (MA)

On-site
USD 89,000 - 134,000
Associate Vice President, Research Computing and Emerging Technologies
Associate Vice President, Research Computing and Emerging Technologies

Koitecc Solutions • Kennesaw (GA), Northern (KY)

Hybrid
USD 150,000 - 230,000
Secure HPC Platform Lead for Research Compute
Secure HPC Platform Lead for Research Compute

Mount Sinai Medical Center • New York (NY)

On-site
USD 113,000 - 202,000
Senior HPC Administrator: Secure, Regulated Compute & Data
Senior HPC Administrator: Secure, Regulated Compute & Data

Mount Sinai • New York (NY)

On-site
USD 113,000 - 202,000
RESEARCHING COMPUTING SECURITY & COMPLIANCE ENG-ENT
RESEARCHING COMPUTING SECURITY & COMPLIANCE ENG-ENT

University of Alabama at Birmingham • University (FL)

On-site
USD 70,000 - 90,000