ICS Security Architect

signatureperformancecareers

United States

On-site

USD 140,000 - 170,000

Full time

7 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Health Insurance
Fully Paid Life Insurance
Fully Paid Short- & Long-Term Disabil

Job summary

Signature Performance seeks an ICS Security Architect to drive security architecture for regulated SaaS and cloud deployments, including Azure Government and hybrid environments. You will translate federal standards into secure designs, implement IAM and zero-trust patterns, and lead security reviews with cross-functional teams.

The role requires deep expertise in FedRAMP Moderate/High, NIST, CMMC, and FIPS, plus strong DevSecOps integration, risk assessments, and evidence development across

Qualifications

  • Bachelor's degree in a technical field or equivalent experience.
  • CISSP, CCSP, CISM or comparable certification is strongly preferred.
  • 8+ years of progressive information security and architecture experience.

Responsibilities

  • Lead security architecture planning and implementation guidance for regulated SaaS and cloud environments.
  • Define boundaries, data flows, and interconnections for secure design.
  • Embed DevSecOps practices, logging, monitoring, and evidence collection.
  • Develop SSPs, control narratives, and architectural diagrams.

Skills

FedRAMP
NIST SP 800-53
CMMC
IAM
PIV/CAC
Zero Trust
DevSecOps
Threat Modeling
SSP/POA&M
Cloud Security

Education

Bachelor's degree in technical field
CISSP or equivalent

Tools

Azure
Azure Government
PKI tooling
SIEM tools

Job description

About You

You are a person who is passionate about leading security architecture planning and design recommendations for regulated SaaS, cloud, on-premises, hybrid, and future multi-cloud environments, including Azure Government and other federal or high-compliance environments. We need someone who has experience translating FedRAMP Moderate/High, NIST, FIPS, HIPAA, FISMA, CMMC, and other applicable security requirements into technical designs, implementation guidance, standards, and audit-ready evidence, with depth in identity, authentication and authorization, password less access, PIV/CAC, federal integrations, encryption, segmentation, logging, DevSecOps, and continuous monitoring).

In the role of ICS Security Architect, you will be responsible for supporting regulated cloud, SaaS, federal enclave, and high-compliance architecture priorities. Secondary support may include corporate and enterprise security architecture initiatives as business priorities require, consistent with the position's responsibility to advance Signature's security posture across cloud, on-premises, hybrid, and SaaS environments.

  • Tell us about your experience with Information, Security & Architecture.
  • Are you a team player and a self-motivator?
  • We are counting on you to manage multiple projects using your problem-solving skills.
  • We are looking for someone UNCOMMON. What is uncommon about you?

Are you highly committed? Are you team-oriented? Do you value professionalism, trust, honesty, and integrity? If so, we cannot wait to meet you.

About The Position
  • Lead security architecture planning, design recommendations, and implementation guidance for regulated SaaS solutions, federal cloud environments, high-compliance enclaves, and hybrid/on-premises deployments.
  • Define authorization boundaries, trust zones, data flows, interconnections, and inheritance.
  • Translate FedRAMP Moderate/High, NIST, CMMC, HIPAA, FISMA, FIPS, and other applicable security requirements into secure designs, standards, implementation guidance, and evidence.
  • Design IAM, least privilege, passwordless, PIV/CAC, privileged/service access, and federal integrations.
  • Define and recommend FIPS-aligned cryptography, PKI, key/secret management, TLS/mTLS, and encryption patterns.
  • Establish secure Azure, Azure Government, on-premises, hybrid, and multi-cloud patterns.
  • Design reusable security architecture patterns that can be adapted across customer-managed, company-managed, SaaS, cloud-hosted, on-premises, and hybrid deployment models.
  • Evaluate deployment models, shared-responsibility boundaries, authorization boundaries, inherited controls, customer-managed responsibilities, and interconnection risks to ensure security requirements are clearly defined and supportable.
  • Lead threat modeling, security design reviews, risk assessments, and development of security architecture artifacts.
  • Embed SAST/SCA/DAST, SBOM, secrets, IaC, container, and release gates into DevSecOps.
  • Define logging, SIEM, audit, continuous monitoring, vulnerability management, incident response, and POA&M requirements in coordination with responsible operational teams.
  • Develop SSPs, control narratives, diagrams, interconnections, standards, and evidence.
  • Support SaaS, federal, corporate, and enterprise security architecture initiatives as business priorities require, with primary focus on regulated technology environments and high-compliance architecture needs.
  • Assess vendor, contractor, supply-chain, and shared-responsibility risk; recommend action.
Minimum Requirements:
  • Must be able to meet applicable federal background, credentialing, and access requirements, including NACLC or successor federal suitability/clearance requirements when applicable.
  • Bachelor's degree in a relevant technical field or equivalent experience.
  • CISSP, CCSP, CISM, or comparable advanced certification strongly preferred.
  • Eight (8)+ years of progressive experience in information security, security architecture, application security, cloud security, or related regulated-technology environments.
  • Deep expertise: FedRAMP Moderate/High; NIST 800-53/171; CMMC; FIPS; HIPAA; FISMA.
  • Azure/Azure Government, on-premises, and hybrid experience; multi-cloud preferred.
  • Expert IAM: OIDC/SAML, MFA/passwordless, PIV/CAC, PKI, RBAC/ABAC, and PAM.
  • Experience with VA or other federal-customer integrations.
  • Architecture artifacts: boundaries, data flows, threat models, interconnections, and ADRs.
  • Experience with SSPs, POA&Ms, ConMon, 3PAO/audit, assessments, and evidence.
  • Experience supporting security architecture for SaaS offerings operating in regulated or federally authorized environments, including shared-responsibility models, inherited controls, customer responsibility matrices, system interconnections, evidence support, and continuous monitoring obligations.
  • Experience designing security patterns for configurable workflow, case management, or business process automation platforms that may be deployed across cloud, on-premises, hybrid, or customer-managed environments.
  • SIEM, vulnerability management, DevSecOps, API security, Zero Trust, segmentation, and keys.
  • Proficient understanding of computer and network systems, security protocols, vulnerability assessment tools, security software, and secure system design.
  • Skilled in technical writing, including IT security policies, procedures, standards, reports, control narratives, and architectural drawings.
  • Strong decision leadership, risk communication, vendor management, and prioritization.
About Us

You are uncommon. We are, too. We are looking for people to help us in our mission of working hard at lowering healthcare administrative costs for federal government agencies, payers, and providers. At Signature, our mission is to improve the health of our clients' business and make the lives of the people we work with better. As we continue to experience exponential growth, we are looking for uncommon individuals to enhance our vision. We will continue to accomplish our mission by leading with our values of Passion, Courage, Integrity, and Respect in all interactions, making us a consistent annual Best Places to Work organization. We need uncommon leaders with uncommon qualities to shape our uncommon culture and achieve our uncommon mission.

About the Benefits

When you are a member of Signature Performance, you are a part of a solutions-based organization where the values of passion, integrity, courage, and respect are the driving forces behind all our decision-making. We trust you to do important work and bring the best version of yourself to work every day, so we want to help you achieve a work-life balance while consistently challenging yourself. Signature believes in fully developing each one of our Associates. Our performance-driven philosophy boasts competitive pay and additional position specific incentives, where world-class training and development, resources, and events drive our award-winning culture where everyone thrives.

  • Health Insurance
  • Fully Paid Life Insurance
  • Fully Paid Short- & Long-Term Disability
  • Paid Vacation
  • Paid Sick Leave
  • Paid Holidays
  • Professional Development and Tuition Assistance Program
  • 401(k) Program with Employer Match
  • U.S. Citizenship or naturalized citizenship is required for this position.
  • All work on all positions at Signature Performance must be completed in the continental United States, Alaska, or Hawaii.

Signature Performance requires candidates to participate in interviews with their camera enabled. Interviews may be recorded for evaluation, training, quality assurance, and hiring purposes. Candidates will be provided the opportunity to consent during the application process and notified before recording begins. These requirements are applied consistently to all applicants and are a condition of participation in the selection process. Failure to meet these requirements may result in removal from consideration. Candidates who have questions, concerns or require accommodation regarding recording should notify the Talent Attraction & Strategy team before proceeding.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

ICS Security Architect - Remote/Nationwide
ICS Security Architect - Remote/Nationwide

MaineGuide • Portland (ME), Northern (KY)

Hybrid
USD 135,000 - 151,000
Health Insurance
Life Insurance
Disability Insurance
+4
ICS Security Architect
ICS Security Architect

Signature Performance, Inc • United States

On-site
USD 135,000 - 151,000
Health Insurance
Life Insurance
Paid Vacation
+2
ICS Security Architect
ICS Security Architect

Signature Performance, Inc. • United States

On-site
USD 160,000 - 220,000
Health Insurance
Fully Paid Life Insurance
Fully Paid Short- & Long-Term Disable
+4
IT Security Administrator
IT Security Administrator

signatureperformancecareers • United States

On-site
USD 90,000 - 120,000
Health Insurance
Fully Paid Life Insurance
Disability coverage
+5
Solutions Configuration Analyst III
Solutions Configuration Analyst III

signatureperformancecareers • United States

Remote
USD 75,000 - 95,000
Health Insurance
Fully Paid Life Insurance
Paid Vacation
+1
Business Analyst III
Business Analyst III

signatureperformancecareers • United States

On-site
USD 90,000 - 120,000
Health Insurance
Fully Paid Life Insurance
Fully Paid Short- & Long-Term Disabled
+5
ClaimsXM Security Administrator I
ClaimsXM Security Administrator I

signatureperformancecareers • United States

On-site
USD 70,000 - 90,000
Health Insurance
Paid Vacation
401(k) Program with Employer Match
Solutions Configuration Analyst III
Solutions Configuration Analyst III

Signature Performance, Inc. • United States

On-site
USD 90,000 - 120,000
Health Insurance
Fully Paid Life Insurance
Fully Paid Short- & Long-Term Disab.
+4
IT Security Administrator
IT Security Administrator

Signature Performance, Inc. • United States

On-site
USD 90,000 - 130,000
Health Insurance for Our Associates
Fully Paid Life Insurance
Fully Paid Short- & Long-Term Disabil
+5
Software Application Engineer II
Software Application Engineer II

Worky • United States

On-site
USD 90,000 - 130,000
Health Insurance
Fully Paid Life Insurance
Fully Paid Short- & Long-Term Disabled
+5