CybersecurityJobs.io
← Back to all jobs

Job Description

The Enterprise Cybersecurity Architect will design and maintain PAM Health’s enterprise security architecture for a multi-state post-acute health system. This role develops security standards and reference architectures, conducts threat modeling and architecture reviews, and provides senior security subject matter expertise across IT, clinical, and business teams.

Security Architecture & Governance

  • Develop, maintain, and govern PAM Health’s enterprise security architecture, technical security standards, design patterns, and reference architectures.
  • Establish secure architecture standards for cloud, identity, network, endpoint, application security, data protection, logging, monitoring, and incident response.

Architecture Reviews & Security Requirements

  • Review enterprise, cloud, clinical, network, application, data, artificial intelligence, and medical device initiatives to ensure security requirements are incorporated prior to implementation.
  • Conduct threat modeling and security design reviews for new systems, major changes, integrations, and third-party solutions.
  • Define security requirements and architecture guardrails aligned with the NIST Cybersecurity Framework, HIPAA Security Rule, MITRE ATT&CK, OWASP guidance, and applicable regulatory requirements.

Risk, Controls, and Stakeholder Communication

  • Identify architectural risks, document required controls, recommend remediation, and communicate business and clinical impact to technical and executive stakeholders.

Security Leadership Across Teams & Third Parties

  • Partner with Information Technology, Network Operations, Clinical Informatics, Compliance, Privacy, Legal, and business leaders to integrate security into technology strategy and project delivery.
  • Provide technical direction and oversight to managed security service providers, technology vendors, consultants, and other third parties.

Application, AI/ML, and Medical Device Security

  • Support application security through secure development requirements, architecture reviews, vulnerability management, penetration testing, and remediation guidance.
  • Evaluate the security of artificial intelligence and machine learning systems, including data protection, access control, model risk, third-party dependencies, and misuse scenarios.
  • Assess medical devices and connected clinical technologies for cybersecurity risk and recommend compensating controls when remediation is limited.

Incident Support and Continuous Improvement

  • Support security incidents by providing architecture analysis, containment guidance, root-cause review, and recommendations to prevent recurrence.
  • Maintain current knowledge of emerging threats, security technologies, healthcare cybersecurity requirements, and industry practices.
  • Mentor security and information technology staff and promote consistent application of PAM Health security standards across the enterprise.

Required Qualifications

  • Bachelor’s degree in Computer Science, Cybersecurity, Engineering, Information Systems, or a related technical field, or an equivalent combination of education and experience.
  • Certified Information Systems Security Professional (CISSP) must be obtained within six (6) months of hire and maintained in good standing.
  • Ten (10) years of progressive experience in cybersecurity.
  • Seven (7) years of cybersecurity experience in healthcare, including provider, health system, or comparably regulated clinical environments.
  • Five (5) years in a security architecture or senior technical role.
  • Three (3) years of application security experience.
  • Experience providing technical direction to third-party security providers and managed security service providers.

Preferred Qualifications

  • Medical device and connected clinical device security experience.
  • Offensive security experience, including penetration testing, red team operations, or adversarial design review.
  • Applied experience securing artificial intelligence and machine learning systems.
  • Experience supporting HITRUST certification, SOC 2 Type II examination, ISO 27001 certification, or a comparable third-party assessment.
  • Experience with 42 CFR Part 2, PCI DSS, and United States Food and Drug Administration software-as-a-medical-device requirements.
  • Experience in geographically distributed, multi-facility clinical environments.

Education and Training

  • Preferred: Master’s degree in Computer Science, Cybersecurity, or a related technical field.
  • Preferred certifications: GIAC Defensible Security Architecture (GDSA), SABSA, Certified Cloud Security Professional (CCSP), Offensive Security Certified Professional (OSCP), GIAC Penetration Tester (GPEN), or HealthCare Information Security and Privacy Practitioner (HCISPP).

Relevant Frameworks, Guidance, and Tools

  • NIST Cybersecurity Framework
  • HIPAA Security Rule
  • MITRE ATT&CK
  • OWASP guidance, OWASP Top 10, OWASP Top 10 for Large Language Model Applications
  • NIST Artificial Intelligence Risk Management Framework
  • MITRE ATLAS
  • NIST
  • CISSP
  • GIAC Defensible Security Architecture (GDSA), SABSA, CCSP, OSCP, GPEN
  • HCISPP

Location, Travel, and Work Conditions

  • Location: Plano, TX (remote).
  • Remote position with travel up to 15 percent to facilities across the enterprise.
  • Facility visits occur in operating clinical environments and may require compliance with facility access, screening, and health requirements.
  • Work is generally performed indoors in well-lighted, well-ventilated areas, with potential exposure to hospital clinical surroundings during visits.
  • The position may be required to support significant security incidents outside standard business hours.

Leadership, Customer Service, and Health & Safety

  • Promotes cooperation, fairness, and equity; demonstrates respect, empathy, and understanding of others’ perspectives.
  • Coaches, evaluates, develops, and inspires staff; sets expectations and recognizes achievements.
  • Demonstrates accountability and sound judgment in managing company resources and adheres to company policies, procedures, and safety guidelines.
  • Provides the highest level of customer service through courtesy, compassion, and positive communication, while respecting dignity and confidentiality.
  • Works in a manner that promotes safety; participates in OSHA required training; follows universal precautions as appropriate; complies with Employee Health requirements.

Knowledge, Skills, and Abilities

  • Demonstrated expertise with the OWASP Top 10 and secure development practices.
  • Working knowledge of MITRE ATT&CK, the NIST Cybersecurity Framework, and the HIPAA Security Rule.
  • Ability to translate technical risk into business and clinical impact for executive and clinical audiences.
  • Strong written and verbal communication skills, including the ability to produce highly technical architectural documentation and present complex concepts to non-technical executive leadership.
  • Familiarity with OWASP Top 10 for Large Language Model Applications, NIST Artificial Intelligence Risk Management Framework, and MITRE ATLAS (preferred).
  • Cloud security architecture experience across multiple cloud service providers (preferred).

Similar Jobs