ICS Security Architect

Signature Performance, Inc.

United States

On-site

USD 160,000 - 220,000

Full time

3 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Health Insurance
Fully Paid Life Insurance
Fully Paid Short- & Long-Term Disable
Paid Vacation
Paid Holidays
Tuition Assistance Program
401(k) Employer Match

Job summary

Signature Performance, Inc. seeks an IC Security Architect to lead security architecture planning and design for regulated SaaS, cloud, on-premises, and hybrid environments.

You will translate FedRAMP, NIST, FIPS, HIPAA, FISMA, and CMMC requirements into secure designs and evidence. You will define authorization boundaries, data flows, and identity and access controls, with focus on secure Azure Gov, multi-cloud, and secure on‑prem deployments.

Qualifications

  • Bachelor's degree in a technical field or equivalent experience.
  • Eight+ years of information security, security architecture, or cloud security experience in regulated environments.
  • CISSP/CCSP/CISM or comparable certification preferred.
  • Deep expertise in FedRAMP Moderate/High; NIST 800-53/171; CMMC; FIPS; HIPAA; FISMA.
  • Azure/Azure Government, on-premises and hybrid experience; multi-cloud preferred.
  • Strong IAM capabilities including OIDC/SAML, MFA/passwordless, PIV/CAC, RBAC/ABAC, and PAM.

Responsibilities

  • Lead security architecture planning, design recommendations, and implementation guidance for regulated SaaS and federal cloud environments.
  • Define authorization boundaries, trust zones, data flows, and interconnections.
  • Translate security requirements into secure designs, standards, and evidence.
  • Design IAM, passwordless, PIV/CAC, privileged access, and federal integrations.
  • Define cryptography, PKI, key management, TLS/mTLS, and encryption patterns.
  • Establish secure multi-cloud patterns and reusable architecture templates.
  • Lead threat modeling, design reviews, risk assessments, and security artifacts.
  • Embed DevSecOps practices and ensure logging, monitoring, and audit readiness.

Skills

Security architecture
Threat modeling
DevSecOps
IAM / PAM
Zero Trust

Education

Bachelor's degree in a technical field
CISSP / CCSP / CISM or equivalent

Tools

Azure Government
SAST/DAST/SCA
SBOM & IaC security

Job description

About You

You are a person who is passionate about leading security architecture planning and design recommendations for regulated SaaS, cloud, on-premises, hybrid, and future multi-cloud environments, including Azure Government and other federal or high-compliance environments. We need someone who has experience translating FedRAMP Moderate/High, NIST, FIPS, HIPAA, FISMA, CMMC, and other applicable security requirements into technical designs, implementation guidance, standards, and audit-ready evidence, with depth in identity, authentication and authorization, password less access, PIV/CAC, federal integrations, encryption, segmentation, logging, DevSecOps, and continuous monitoring.

About You

You are a person who is passionate about leading security architecture planning and design recommendations for regulated SaaS, cloud, on-premises, hybrid, and future multi-cloud environments, including Azure Government and other federal or high-compliance environments. We need someone who has experience translating FedRAMP Moderate/High, NIST, FIPS, HIPAA, FISMA, CMMC, and other applicable security requirements into technical designs, implementation guidance, standards, and audit-ready evidence, with depth in identity, authentication and authorization, password less access, PIV/CAC, federal integrations, encryption, segmentation, logging, DevSecOps, and continuous monitoring.

In the role of IC Security Architect, you will be responsible for supporting regulated cloud, SaaS, federal enclave, and high-compliance architecture priorities. Secondary support may include corporate and enterprise security architecture initiatives as business priorities require, consistent with the position's responsibility to advance Signature's security posture across cloud, on-premises, hybrid, and SaaS environments.

  • Tell us about your experience with Information, Security & Architecture.
  • Are you a team player and a self-motivator?
  • We are counting on you to manage multiple projects using your problem-solving skills.
  • We are looking for someone UNCOMMON. What is uncommon about you?

Are you highly committed? Are you team-oriented? Do you value professionalism, trust, honesty, and integrity? If so, we cannot wait to meet you.

About The Position
  • Lead security architecture planning, design recommendations, and implementation guidance for regulated SaaS solutions, federal cloud environments, high-compliance enclaves, and hybrid/on-premises deployments.
  • Define authorization boundaries, trust zones, data flows, interconnections, and inheritance.
  • Translate FedRAMP Moderate/High, NIST, CMMC, HIPAA, FISMA, FIPS, and other applicable security requirements into secure designs, standards, implementation guidance, and evidence.
  • Design IAM, least privilege, passwordless, PIV/CAC, privileged/service access, and federal integrations.
  • Define and recommend FIPS-aligned cryptography, PKI, key/secret management, TLS/mTLS, and encryption patterns.
  • Establish secure Azure, Azure Government, on-premises, hybrid, and multi-cloud patterns.
  • Design reusable security architecture patterns that can be adapted across customer-managed, company-managed, SaaS, cloud-hosted, on-premises, and hybrid deployment models.
  • Evaluate deployment models, shared-responsibility boundaries, authorization boundaries, inherited controls, customer-managed responsibilities, and interconnection risks to ensure security requirements are clearly defined and supportable.
  • Lead threat modeling, security design reviews, risk assessments, and development of security architecture artifacts.
  • Embed SAST/SCA/DAST, SBOM, secrets, IaC, container, and release gates into DevSecOps.
  • Define logging, SIEM, audit, continuous monitoring, vulnerability management, incident response, and POA&M requirements in coordination with responsible operational teams.
  • Develop SSPs, control narratives, diagrams, interconnections, standards, and evidence.
  • Support SaaS, federal, corporate, and enterprise security architecture initiatives as business priorities require, with primary focus on regulated technology environments and high-compliance architecture needs.
  • Assess vendor, contractor, supply-chain, and shared-responsibility risk; recommend action.
Minimum Requirements
  • Must be able to meet applicable federal background, credentialing, and access requirements, including NACLC or successor federal suitability/clearance requirements when applicable.
  • Bachelor's degree in a relevant technical field or equivalent experience.
  • CISSP, CCSP, CISM, or comparable advanced certification strongly preferred.
  • Eight (8)+ years of progressive experience in information security, security architecture, application security, cloud security, or related regulated-technology environments.
  • Deep expertise: FedRAMP Moderate/High; NIST 800-53/171; CMMC; FIPS; HIPAA; FISMA.
  • Azure/Azure Government, on-premises, and hybrid experience; multi-cloud preferred.
  • Expert IAM: OIDC/SAML, MFA/passwordless, PIV/CAC, PKI, RBAC/ABAC, and PAM.
  • Experience with VA or other federal-customer integrations.
  • Architecture artifacts: boundaries, data flows, threat models, interconnections, and ADRs.
  • Experience with SSPs, POA&Ms, ConMon, 3PAO/audit, assessments, and evidence.
  • Experience supporting security architecture for SaaS offerings operating in regulated or federally authorized environments, including shared-responsibility models, inherited controls, customer responsibility matrices, system interconnections, evidence support, and continuous monitoring obligations.
  • Experience designing security patterns for configurable workflow, case management, or business process automation platforms that may be deployed across cloud, on-premises, hybrid, or customer-managed environments.
  • SIEM, vulnerability management, DevSecOps, API security, Zero Trust, segmentation, and keys.
  • Proficient understanding of computer and network systems, security protocols, vulnerability assessment tools, security software, and secure system design.
  • Skilled in technical writing, including IT security policies, procedures, standards, reports, control narratives, and architectural drawings.
  • Strong decision leadership, risk communication, vendor management, and prioritization.
About Us

You are uncommon. We are, too. We are looking for people to help us in our mission of working hard at lowering healthcare administrative costs for federal government agencies, payers, and providers. At Signature, our mission is to improve the health of our clients' business and make the lives of the people we work with better. As we continue to experience exponential growth, we are looking for uncommon individuals to enhance our vision. We will continue to accomplish our mission by leading with our values of Passion, Courage, Integrity, and Respect in all interactions, making us a consistent annual Best Places to Work organization. We need uncommon leaders with uncommon qualities to shape our uncommon culture and achieve our uncommon mission.

About The Benefits

When you are a member of Signature Performance, you are a part of a solutions-based organization where the values of passion, integrity, courage, and respect are the driving forces behind all our decision-making. We trust you to do important work and bring the best version of yourself to work every day, so we want to help you achieve a work-life balance while consistently challenging yourself. Signature believes in fully developing each one of our Associates. Our performance-driven philosophy boasts competitive pay and additional position specific incentives, where world-class training and development, resources, and events drive our award-winning culture where everyone thrives.

  • Health Insurance
  • Fully Paid Life Insurance
  • Fully Paid Short- & Long-Term Disability
  • Paid Vacation
  • Paid Sick Leave
  • Paid Holidays
  • Professional Development and Tuition Assistance Program
  • 401(k) Program with Employer Match
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

IT Security Administrator
IT Security Administrator

Signature Performance, Inc. • United States

On-site
USD 90,000 - 130,000
Health Insurance for Our Associates
Fully Paid Life Insurance
Fully Paid Short- & Long-Term Disabil
+5
ICS Security Architect
ICS Security Architect

Signature Performance, Inc • United States

On-site
USD 135,000 - 151,000
Health Insurance
Life Insurance
Paid Vacation
+2
Business Analyst III
Business Analyst III

Signature Performance, Inc. • United States

On-site
USD 85,000 - 125,000
Health Insurance
Fully Paid Life Insurance
Fully Paid Short- & Long-Term Disabil
+4
Solutions Configuration Analyst III
Solutions Configuration Analyst III

Signature Performance, Inc. • United States

On-site
USD 90,000 - 120,000
Health Insurance
Fully Paid Life Insurance
Fully Paid Short- & Long-Term Disab.
+4
ClaimsXM Security Administrator I
ClaimsXM Security Administrator I

Signature Performance, Inc. • United States

On-site
USD 70,000 - 110,000
Health Insurance
Fully Paid Life Insurance
Fully Paid Short- & Long-Term DIscount
+4
Software Application Engineer II
Software Application Engineer II

Worky • United States

On-site
USD 90,000 - 130,000
Health Insurance
Fully Paid Life Insurance
Fully Paid Short- & Long-Term Disabled
+5
IT Security Administrator - Remote/Nationwide
IT Security Administrator - Remote/Nationwide

MaineGuide • Portland (ME)

Hybrid
USD 80,000 - 100,000
Health Insurance
Fully Paid Life Insurance
Fully Paid Short- & Long-Term Disabil
+5
Software Application Engineer II
Software Application Engineer II

Signature Performance, Inc. • United States

On-site
USD 90,000 - 130,000
Health Insurance
Fully Paid Life Insurance
Fully Paid Short- & Long-Term Disabil
+5
Project Manager III
Project Manager III

Signature Performance, Inc. • United States

On-site
USD 110,000 - 160,000
Health Insurance
Fully Paid Life Insurance
Fully Paid Short- & Long-Term Disabil
+5
Payer Payment & Reimbursement Analyst
Payer Payment & Reimbursement Analyst

Signature Performance, Inc. • United States

On-site
USD 85,000 - 130,000
Health Insurance
Fully Paid Life Insurance
Fully Paid Short- & Long-Term Disabil​
+5