ICS Security Architect - Remote/Nationwide

MaineGuide

Portland, Northern (ME, KY)

Hybrid

USD 135,000 - 151,000

Full time

3 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Health Insurance
Life Insurance
Disability Insurance
Paid Vacation
Paid Holidays
Tuition Assistance
401(k) Match

Job summary

Signature Performance seeks an ICS Security Architect to lead security architecture for regulated cloud and hybrid deployments, including federal enclosures and Azure Government. The role focuses on translating federal requirements into practical designs, architectures, and audit-ready evidence.

You will define authorization boundaries, data flows, and interconnections while driving threat modeling, risk assessments, and DevSecOps integration across SaaS and on-premises environments.

Qualifications

  • Bachelor's degree in a technical field or equivalent experience.
  • Eight or more years in information security, architecture, or regulated environments.
  • Strong knowledge of FedRAMP Moderate/High; NIST, FIPS, HIPAA, FISMA, CMMC.
  • Experience with Azure/Azure Government, on-premises, and hybrid environments.
  • Expert IAM experience: OIDC/SAML, MFA/passwordless, PIV/CAC, RBAC/ABAC, PAM.
  • Ability to translate security requirements into secure designs and evidence.

Responsibilities

  • Lead security architecture planning, design recommendations, and implementation guidance across regulated cloud and hybrid deployments.
  • Define authorization boundaries, trust zones, data flows, and interconnections.
  • Translate security requirements into secure designs, standards, and evidence for audits.
  • Design IAM controls including passwordless access and PIV/CAC integrations.
  • Lead threat modeling, design reviews, risk assessments, and security architecture artifacts.
  • Embed DevSecOps practices: SAST, SCA, DAST, SBOM, and IaC into pipelines.

Skills

Threat modeling
DevSecOps
Security architecture
Risk communication
Vendor management
IAM design

Education

Bachelor's degree in a relevant field

Tools

Azure
Azure Government
PKI
SIEM
ConMon

Job description

ICS Security Architect

This is a remote based position. Applicants can be located nationwide

Position Description

About You You are a person who is passionate about leading security architecture planning and design recommendations for regulated SaaS, cloud, on-premises, hybrid, and future multi-cloud environments, including Azure Government and other federal or high-compliance environments. We need someone who has experience translating FedRAMP Moderate/High, NIST, FIPS, HIPAA, FISMA, CMMC, and other applicable security requirements into technical designs, implementation guidance, standards, and audit-ready evidence, with depth in identity, authentication and authorization, password less access, PIV/CAC, federal integrations, encryption, segmentation, logging, DevSecOps, and continuous monitoring.

In the role of IC Security Architect, you will be responsible for supporting regulated cloud, SaaS, federal enclave, and high-compliance architecture priorities. Secondary support may include corporate and enterprise security architecture initiatives as business priorities require, consistent with the position's responsibility to advance Signature's security posture across cloud, on-premises, hybrid, and SaaS environments.

About the Position
  • Lead security architecture planning, design recommendations, and implementation guidance for regulated SaaS solutions, federal cloud environments, high-compliance enclaves, and hybrid/on-premises deployments.
  • Define authorization boundaries, trust zones, data flows, interconnections, and inheritance.
  • Translate FedRAMP Moderate/High, NIST, CMMC, HIPAA, FISMA, FIPS, and other applicable security requirements into secure designs, standards, implementation guidance, and evidence.
  • Design IAM, least privilege, passwordless, PIV/CAC, privileged/service access, and federal integrations.
  • Define and recommend FIPS-aligned cryptography, PKI, key/secret management, TLS/mTLS, and encryption patterns.
  • Establish secure Azure, Azure Government, on-premises, hybrid, and multi-cloud patterns.
  • Design reusable security architecture patterns that can be adapted across customer-managed, company-managed, SaaS, cloud-hosted, on-premises, and hybrid deployment models.
  • Evaluate deployment models, shared-responsibility boundaries, authorization boundaries, inherited controls, customer-managed responsibilities, and interconnection risks to ensure security requirements are clearly defined and supportable.
  • Lead threat modeling, security design reviews, risk assessments, and development of security architecture artifacts.
  • Embed SAST/SCA/DAST, SBOM, secrets, IaC, container, and release gates into DevSecOps.
  • Define logging, SIEM, audit, continuous monitoring, vulnerability management, incident response, and POA&M requirements in coordination with responsible operational teams.
  • Develop SSPs, control narratives, diagrams, interconnections, standards, and evidence.
  • Support SaaS, federal, corporate, and enterprise security architecture initiatives as business priorities require, with primary focus on regulated technology environments and high-compliance architecture needs.
  • Assess vendor, contractor, supply-chain, and shared-responsibility risk; recommend action.
Minimum Requirements:
  • Must be able to meet applicable federal background, credentialing, and access requirements, including NACLC or successor federal suitability/clearance requirements when applicable.
  • Bachelor's degree in a relevant technical field or equivalent experience.
  • CISSP, CCSP, CISM, or comparable advanced certification strongly preferred.
  • Eight (8)+ years of progressive experience in information security, security architecture, application security, cloud security, or related regulated-technology environments.
  • Deep expertise: FedRAMP Moderate/High; NIST 800-53/171; CMMC; FIPS; HIPAA; FISMA.
  • Azure/Azure Government, on-premises, and hybrid experience; multi-cloud preferred.
  • Expert IAM: OIDC/SAML, MFA/passwordless, PIV/CAC, PKI, RBAC/ABAC, and PAM.
  • Experience with VA or other federal-customer integrations.
  • Architecture artifacts: boundaries, data flows, threat models, interconnections, and ADRs.
  • Experience with SSPs, POA&Ms, ConMon, 3PAO/audit, assessments, and evidence.
  • Experience supporting security architecture for SaaS offerings operating in regulated or federally authorized environments, including shared-responsibility models, inherited controls, customer responsibility matrices, system interconnections, evidence support, and continuous monitoring obligations.
  • Experience designing security patterns for configurable workflow, case management, or business process automation platforms that may be deployed across cloud, on-premises, hybrid, or customer-managed environments.
  • SIEM, vulnerability management, DevSecOps, API security, Zero Trust, segmentation, and keys.
  • Proficient understanding of computer and network systems, security protocols, vulnerability assessment tools, security software, and secure system design.
  • Skilled in technical writing, including IT security policies, procedures, standards, reports, control narratives, and architectural drawings.
  • Strong decision leadership, risk communication, vendor management, and prioritization.
About Us

You are uncommon. We are, too. We are looking for people to help us in our mission of working hard at lowering healthcare administrative costs for federal government agencies, payers, and providers. At Signature, our mission is to improve the health of our clients' business and make the lives of the people we work with better. As we continue to experience exponential growth, we are looking for uncommon individuals to enhance our vision. We will continue to accomplish our mission by leading with our values of Passion, Courage, Integrity, and Respect in all interactions, making us a consistent annual Best Places to Work organization. We need uncommon leaders with uncommon qualities to shape our uncommon culture and achieve our uncommon mission.

About the Benefits

When you are a member of Signature Performance, you are a part of a solutions-based organization where the values of passion, integrity, courage, and respect are the driving forces behind all our decision-making. We trust you to do important work and bring the best version of yourself to work every day, so we want to help you achieve a work-life balance while consistently challenging yourself. Signature believes in fully developing each one of our Associates. Our performance-driven philosophy boasts competitive pay and additional position specific incentives, where world-class training and development, resources, and events drive our award-winning culture where everyone thrives.

  • Health Insurance
  • Fully Paid Life Insurance
  • Fully Paid Short- & Long-Term Disability
  • Paid Vacation
  • Paid Sick Leave
  • Paid Holidays
  • Professional Development and Tuition Assistance Program
  • 401(k) Program with Employer Match
Security Requirements
  • U.S. Citizenship or naturalized citizenship is required for this position.
  • All work on all positions at Signature Performance must be completed in the continental United States, Alaska, or Hawaii.

Signature Performance requires candidates to participate in interviews with their camera enabled. Interviews may be recorded for evaluation, training, quality assurance, and hiring purposes. Candidates will be provided the opportunity to consent during the application process and notified before recording begins. These requirements are applied consistently to all applicants and are a condition of participation in the selection process. Failure to meet these requirements may result in removal from consideration. Candidates who have questions, concerns or require accommodation regarding recording should notify the Talent Attraction & Strategy team before proceeding.

Work Schedule

Monday through Friday, 8am to 5pm CST (40 Hours)

Compensation Range

$135,000-$151,000/annually

Position Type

Full Time

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

ICS Security Architect
ICS Security Architect

signatureperformancecareers • United States

On-site
USD 140,000 - 170,000
Health Insurance
Fully Paid Life Insurance
Fully Paid Short- & Long-Term Disabil
ICS Security Architect
ICS Security Architect

Signature Performance, Inc • United States

On-site
USD 135,000 - 151,000
Health Insurance
Life Insurance
Paid Vacation
+2
ICS Security Architect
ICS Security Architect

Signature Performance, Inc. • United States

On-site
USD 160,000 - 220,000
Health Insurance
Fully Paid Life Insurance
Fully Paid Short- & Long-Term Disable
+4
IT Security Administrator
IT Security Administrator

signatureperformancecareers • United States

On-site
USD 90,000 - 120,000
Health Insurance
Fully Paid Life Insurance
Disability coverage
+5
Solutions Configuration Analyst III
Solutions Configuration Analyst III

signatureperformancecareers • United States

Remote
USD 75,000 - 95,000
Health Insurance
Fully Paid Life Insurance
Paid Vacation
+1
Business Analyst III
Business Analyst III

signatureperformancecareers • United States

On-site
USD 90,000 - 120,000
Health Insurance
Fully Paid Life Insurance
Fully Paid Short- & Long-Term Disabled
+5
Data Analyst - Remote/Nationwide
Data Analyst - Remote/Nationwide

MaineGuide • Northern (KY)

Hybrid
USD 90,000 - 110,000
Health Insurance
Fully Paid Life Insurance
Fully Paid Short- & Long-Term Disabled
+5
ClaimsXM Security Administrator I
ClaimsXM Security Administrator I

Signature Performance, Inc. • Northern (KY)

On-site
USD 72,000 - 79,000
Health Insurance
Fully Paid Life Insurance
Fully Paid Short- & Long-Term Disable
+4
ClaimsXM Security Administrator I
ClaimsXM Security Administrator I

signatureperformancecareers • United States

On-site
USD 70,000 - 90,000
Health Insurance
Paid Vacation
401(k) Program with Employer Match
Solutions Configuration Analyst III
Solutions Configuration Analyst III

Signature Performance, Inc. • United States

On-site
USD 90,000 - 120,000
Health Insurance
Fully Paid Life Insurance
Fully Paid Short- & Long-Term Disab.
+4