Program Security Architect/MA/Hybrid

Volantsoft Inc

Boston (MA)

Hybrid

USD 140,000 - 190,000

Full time

13 hours ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Volantsoft Inc. in Boston, MA is seeking a Full-time security program lead to oversee the implementation of infrastructure security, application security, and user authentication controls.

The role collaborates with EOTSS, BEST teams, vendors, and risk managers to ensure compliant security measures. The position requires coordinating secure onboarding for Workday, reviewing security SLAs, and guiding end-to-end risk mitigation and incident response processes within a hybrid, on-site friendly

Qualifications

  • In-depth exposure to technical configurations, technologies, and processing environments in one or more projects of similar size and complexity to BEST.
  • In-depth knowledge and understanding of information risk concepts and principles as a means of relating business needs to security controls.
  • Knowledge of and experience in developing and documenting security architecture and plans, including strategic, tactical and project plans.

Responsibilities

  • Oversee implementation of three major security components: Infrastructure hosting, Application security, and User Authentication security.
  • Coordinate with EOTSS, BEST project team, vendors, SI, and risk management teams to ensure security alignment.
  • Onboard Workday and Workday Prism to work with Commonwealth SSO for employees and vendors; assess options for others with limitations.
  • Remediate department user data in support of CTR Risk and Compliance Unit.
  • Oversee security SLAs with vendors and establish review processes for ongoing monitoring.
  • Work with BEST leadership to develop security strategies, roles, and responsibilities and enforce security requirements.

Skills

Security risk concepts
Security architecture
Documentation & planning

Job description

Full-time, Monday-Friday, 7.5-hour days

Location: Boston, MA - Hybrid (minimum 4 business days/month on-site; must be able to report on-site with little or no notice; reasonable proximity required; no travel reimbursement)

Specific Duties
  • Oversee implementation of the three major security components: Infrastructure (hosting) security, Application Security, and User Authentication security.
  • Align with BEST project team, vendor, SI, EOTSS security, and Comptroller Risk Management Team, including:
  • Partner with EOTSS to onboard Workday and Workday Prism to work with the Commonwealth Single Sign-On (SSO) for employees and vendors as appropriate; for departments, employees, and contractors with limitations on the standard EOTSS SSO solution, assess options and recommend how these individuals will be managed and properly secured.
  • Assist in the remediation of department user data as necessary in support of the CTR Risk and Compliance Unit.
  • Oversee security SLAs with the vendor(s) to ensure appropriate security reports are created, and create a process for review to ensure SLAs are monitored by the Commonwealth.
  • Work with EOTSS on security and compliance testing/documentation and review/remediate results/issues as necessary, in collaboration with the Comptroller Risk Management team.
  • Work with BEST technical leadership to develop strategies, procedures and recommended roles and responsibilities to enforce security requirements and address identified risks related to the use of the new solution and suitability of underlying internal controls and technologies.
  • Provide recommendations regarding end user security roles and groups, data access controls and security role provisioning (onboarding) and de-provisioning (offboarding) protocols, in cooperation with the Comptroller Risk Management Team.
  • Participate in disaster recovery, business continuity, backup, and operational planning; support DR/business continuity testing and documentation.
  • Oversee establishment of the overall Security Incident Event Management (SIEM) across several security operational domains including Cloud SaaS vendor, Comptroller's office, and EOTSS.
  • Support the identification, assessment, documentation, prioritization, mitigation, monitoring, and escalation of program risks.
  • Support the program risk register and ensure risks have clearly identified owners, mitigation actions, target dates, and escalation paths.
  • Oversee integration configuration and testing of EOTSS Single Sign-On (SSO), EOTSS Identity Access Management (IAM), EOTSS Multi-Factor Authentication (MFA), Cloud SaaS vendor user access management, and Workday access controls and provisioning processes, in cooperation with Comptroller Risk Management Team.
  • Implement agreed mitigations and solutions to address business and technology vulnerabilities.
  • Document and implement technical controls, processes and procedures related to data security in conjunction with the BEST Phase 2 Technical Lead, Assistant Comptroller for Statewide Risk Management and Compliance, and EOTSS.
  • Assist security administrators and IT staff in the resolution of reported security incidents; act as liaison between incident response leads and subject matter experts; monitor daily or weekly reports and security logs for unusual events.
  • Translate Comptroller, Commonwealth, and EOTSS policies into BEST program implementation actions, solutions, and processes, as well as on-going operational processes, in cooperation with the Comptroller Risk Management Team and CTR Payroll Teams.
  • Assist in identifying security requirements using methods that may include risk and business impact assessments, including review of SLA requirements, Commonwealth IT policies related to data security, and Commonwealth Risk Management Office policies, assessments, and recommendations.
  • Conduct additional business system analysis as needed; design future state security solution supporting data, application, and environment security needs across multiple stakeholders.
  • Identify business and technology security vulnerabilities and make recommendations to program leadership and stakeholders.
  • Assess compliance with risk and cybersecurity frameworks and standards such as NIST, ISO, COSO, PCI, FERPA, and GLBA, with the BEST Phase 2 Technical Lead and Comptroller Risk Management Team.
  • Assist in the coordination and completion of information security operations documentation.
  • Play an advisory role in application development and implementation to assess security requirements and controls and assure security issues are addressed throughout the project life cycle.
  • Support the Program and the BEST Phase 2 Technical Lead to identify approved end users of the new solution and coordinate provisioning of users for Day One go live; drive end-to-end testing of the go-live security solution.
  • Provide advice to security administrators on normal and exception-based processing of security authorization requests, including the use of SI or product vendor tools that monitor system use and data access irregularities.
  • Research, evaluate and recommend information-security-related hardware and software, including developing business cases for security investments.
  • Analyze results of SI/product vendor audits or third-party audits to produce recommendations on acceptable risks and risk mitigation strategies; provide recommendations on audit finding remediation, feedback on managerial responses, tracking progress and status updates to the BEST Team.
  • Provide ongoing advice and support to Security Operations and IT for incident response, indicators of compromise (IOCs), vendor security vulnerability notifications, law enforcement security alerts, etc.
  • Maintain awareness of existing and proposed security-standard-setting groups, state and federal legislation and regulations pertaining to information security; identify regulatory changes affecting information security policy, standards, and procedures, and recommend changes.
  • Research and assess new threats and security alerts and recommend remedial actions.
  • Work with BEST Operations, Comptroller operations, EOTSS operations, and Agency operations to ensure security operational actions are properly implemented.
  • Assist/support BEST Phase 2 Technical Lead on integration data exchange inbound and outbound requirements identification, definition, and validation.
  • Monitor compliance throughout design, configuration, development, testing, deployment, and transition to operations.
  • Execute "tabletop" security reviews of end-to-end go-live security processes.
  • Oversee and advise BEST program use of AI tools from a security point of view; advise vendor and SI on use of AI tools built into the Workday product natively.
  • Ensure the completion of information security operations documentation.
  • Develop strategies, procedures and recommended roles and responsibilities to enforce security requirements and address identified risks related to the use of the new solution.
  • Oversee configuration updates and execution role in application development and implementation related to security requirements and controls; ensure security controls are implemented as planned and security and access needs are addressed throughout the user life cycle, in collaboration with the Comptroller Risk Management Team.
  • Provide advice and recommendations on the data conversion of end users from the legacy system to the new system.
  • Work with BEST, CTR's, and EOTSS' CSOs, CIOs, and the Comptroller's Risk Management Office to identify, select and implement technical controls related to data security and implement security processes and procedures ensuring controls are managed and maintained both centrally and within agencies where certain security management tasks are decentralized.
  • Advise the BEST Team, SI and product vendors regarding end user security roles and groups, data access controls and security role provisioning and de-provisioning protocols.
  • Support the BEST Team and agencies in identifying approved end users of the new solution and coordinating provisioning of users for Day One go live.
  • Advise security administrators on normal and exception-based processing of security authorization requests including the use of SI or product vendor provided tools that monitor system use and data access irregularities.
  • Act as a liaison between incident response leads and subject matter experts.
  • Support the implementation of the new solution's complete security profile, including but not limited to: Azure Active Directory (AD) entry; Single Sign-On (SSO); New Solution User Security Role; New Solution User Workflow Role.
Required Skills
  • In-depth exposure to technical configurations, technologies, and processing environments in one or more projects of similar size and complexity to BEST
  • In-depth knowledge and understanding of information risk concepts and principles as a means of relating business needs to security controls
  • Knowledge of and experience in developing and documenting security architecture and plans, including strategic, tactical and project plans
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

BEST Program Security Architect
BEST Program Security Architect

Volantsoft Inc • Boston (MA)

Hybrid
USD 140,000 - 210,000
Security Architect
Security Architect

LanceSoft Inc • Boston (MA)

On-site
USD 124,000 - 138,000
Technical Security Analyst / Boston MA / Hybrid
Technical Security Analyst / Boston MA / Hybrid

Volantsoft Inc • Boston (MA)

Remote
USD 130,000 - 170,000
Technical Security Analyst
Technical Security Analyst

Lancesoft • Boston (MA)

Hybrid
USD 120,000 - 160,000
Security Architect
Security Architect

Lancesoft • Boston (MA)

Hybrid
USD 124,000 - 138,000
Hybrid work model
Technical Manager - Security
Technical Manager - Security

Volantsoft Inc • Boston (MA)

Hybrid
USD 110,000 - 150,000
Flexible work from home
Tech Environment Manager
Tech Environment Manager

Tier4 Group • Boston (MA)

On-site
USD 120,000 - 180,000
Senior Security Architect
Senior Security Architect

Acro Service Corp • Quincy (MA)

Hybrid
USD 90,000 - 140,000
Technical Security Analyst
Technical Security Analyst

Talent Groups • Boston (MA)

Hybrid
USD 110,000 - 160,000
Technical Environment Manager
Technical Environment Manager

Talent Groups • Boston (MA)

Hybrid
USD 120,000 - 190,000