Jobs · Art & Creative

Principal Architect - Security

SCA Health · United States · Yesterday
RemoteRemoteArt & Creative$150k/yrFull-time

About the role

We currently have an exciting opportunity for a Principal Architect - Security, responsible for working with stakeholders, both leadership and subject matter experts, to build a holistic view of the organization's security architecture, controls, and risk posture. This individual will utilize knowledge and experience to link the business mission, strategy, and processes of the organization to a secure-by-design IT strategy, and document this utilizing multiple architectural models or views that show how the current and future needs of the organization will be met in an efficient, sustainable, agile, adaptable, and secure manner. A central focus of this role is embedding security into architecture decisions across SCA's hybrid, partner-driven environment and serving as the authoritative security voice at the Architecture Review Board. Because SCA maintains its own identity boundary with no federation to its Optum/UHG parent, this role treats identity as the primary control plane and delivers secure access through a Zero Trust, Zscaler-anchored model.

Responsibilities

  • Develop, maintain, promote, and evangelize an enterprise view of the security architecture blueprint and roadmap for the organization
  • Align the security strategy, controls, and solutions with the Company's business objectives and defined risk appetite
  • Serve as the authoritative security reviewer at the ARB/DRB, evaluating architectures for security fitness and recording the Security domain sign-off
  • Partner with the CISO organization to ensure architecture aligns with the NIST CSF-aligned security remediation framework, coordinating it with the EA-owned Technical Debt Management Framework
  • Establish and lead the threat modeling practice required by Optum for qualifying solution architectures — defining which architectures trigger a threat model, the method applied (e.g., STRIDE), and how threat-model findings are remediated and carried into the ARB security sign-off
  • Perform architecture risk assessments across initiatives, mapping mitigations to the design and reducing project risk
  • Provide strategic security consultation to assigned business customers in designing technology-based solutions, and identify enabling security technologies based on requirements
  • Design and publish security patterns and reference architectures spanning identity and access management, zero-trust, data protection, network segmentation, secrets management, and logging/detection
  • Own the enterprise identity and access management architecture as the primary control plane for Zero Trust — directory and identity services (Microsoft Entra ID and Active Directory), authentication and federation standards (SAML, OIDC, OAuth 2.0, SCIM), Conditional Access, MFA and passwordless, and RBAC/ABAC authorization models
  • Architect identity governance and privileged access — joiner/mover/leaver lifecycle and automated provisioning/deprovisioning, access certification and entitlement reviews, and privileged access management (e.g., Entra Privileged Identity Management) with just-in-time, least-privilege elevation
  • Design cross-boundary, workforce, and partner identity for SCA's separated identity model — Optum-issued contractor identities, B2B/guest access, and Citrix — where SCA and the Optum parent maintain distinct identity stores without federation; define workload and non-human identity patterns (service principals, managed identities, workload federation) and secrets management to eliminate long-lived credentials
  • Architect data protection for PHI and PII in the ASC context, including encryption in transit and at rest, key management, and masking/tokenization
  • Establish the Zero Trust network and secure-access architecture on the Zscaler SSE/SASE platform — Zscaler Private Access (ZPA) for identity- and posture-aware access to private applications, Zscaler Internet Access (ZIA) for secure web/egress and inline inspection, and Zscaler Digital Experience (ZDX) for monitoring — replacing implicit-trust VPN patterns and enforcing segmentation and ingress/egress controls
  • Extend the Zscaler platform into the broader control set where it fits — CASB and DLP for SaaS, posture control, and device-posture signals feeding Conditional Access — with clean integration to Entra ID, endpoint tooling, and logging/detection
  • Provide cloud and SaaS security architecture, in particular for Microsoft Azure, including landing-zone guardrails, policy-as-code, and shared-responsibility clarity
  • Map security controls to applicable frameworks (NIST CSF, HIPAA, HITRUST, SOC 2, PCI) with ownership and an evidence approach
  • Guide vulnerability management and supply-chain security, including SBOM, patching, and security gates in the SDLC/CI-CD pipeline
  • Lead the security architecture review of third-party and vendor solutions, with particular rigor for Tier 1 PHI vendors
  • Monitor and manage security-related technical debt within the environment, coordinating remediation priority with the CISO framework
  • Contribute to the growth and maturity of the IT department through mentorship, knowledge transfer, and thought leadership by example
  • Articulate security architecture concepts, risk, and analytical findings to Executive Management, business leadership, software developers, and end users
  • Additional duties as assigned.

Qualifications

  • Bachelor's degree or equivalent work experience
  • 8-10+ years of experience in security architecture and engineering, with the most recent role in an architect or technical leadership capacity
  • 2-5+ years of experience working in an architect or technical leadership capacity
  • Solid understanding of healthcare provider (ASC) security and compliance obligations (HIPAA, HITRUST), with the ability to provide a trusted voice at the decision-making table
  • Strong command of security frameworks and control catalogs: NIST CSF, NIST 800-53, HITRUST, SOC 2, and PCI DSS
  • Deep identity and access management expertise: directory and identity platforms (Microsoft Entra ID and Active Directory), federation and authentication protocols (SAML, OIDC, OAuth 2.0, SCIM), Conditional Access, MFA and passwordless, and RBAC/ABAC authorization
  • Identity governance and privileged access experience: IGA lifecycle and provisioning, access certification and entitlement management, and PAM with just-in-time elevation (e.g., Entra Privileged Identity Management); experience with workforce/partner identity across separated, non-federated identity stores — including externally issued contractor identities, B2B/guest, and Citrix — is a strong plus
  • Thorough understanding of cloud security and governance, in particular Microsoft Azure (landing zones, guardrails, policy-as-code)
  • Data protection expertise: encryption in transit and at rest, key management, and masking/tokenization for PHI and PII
  • Strong network and boundary security background, including segmentation and zero-trust network access
  • Hands-on Zscaler experience across the SSE platform — Zscaler Private Access (ZPA), Zscaler Internet Access (ZIA), and Zscaler Digital Experience (ZDX) — designing zero-trust access to replace legacy VPN, with an understanding of how Zscaler integrates with identity (Entra ID) and device posture
  • Proficiency with threat modeling (e.g., STRIDE) and risk assessment methodologies as they relate to integration and software engineering
  • Demonstrated experience operationalizing a threat-modeling program — establishing trigger criteria, applying a recognized methodology (e.g., STRIDE, PASTA, or attack-tree analysis), and integrating findings into architecture governance — not just performing individual threat models
  • Experience with security logging, monitoring, and detection, including SIEM and SOC integration
  • Experience with vulnerability management, SBOM, and DevSecOps / secure SDLC practices, including CI/CD security gates
  • Knowledge of TOGAF and a security architecture framework such as SABSA required; certification preferred (CISSP, CISSP-ISSAP, CCSP, SABSA, Microsoft SC-300 Identity and Access Administrator, Azure security certifications, or Zscaler certifications such as ZCCA/ZCCP)
  • Excellent conceptual and security design pattern skills irrespective of technology, and willingness to assume total ownership of security architecture from inception to delivery
  • Experience creating an effective framework and process model for establishing enterprise-wide security architecture
  • Ability and willingness to document security architecture, integrations, and dependencies for existing platforms and systems currently in use at SCA
  • Understanding and experience implementing the strategic alignment of business and security
  • Experience with third-party and vendor security risk management, particularly for Tier 1 PHI SaaS vendors
  • Demonstrated competency in communicating the value of security architecture to stakeholders and senior management
  • Strong interpersonal, verbal, and written communication skills, with the ability to develop and conduct executive-level presentations
  • Ability to collaborate with various levels of individuals - both IT and business
  • Self-directed with the ability to work effectively under tight deadlines
  • Experience with Mergers & Acquisitions, in areas of security diligence and integration, is desirable.

Benefits

We offer a comprehensive benefits package to support your health, well-being, and financial future. Our offerings include medical, dental, and vision coverage, 401k plan with company match, paid time off, life and disability insurance, and more. Please visit https://careers.sca.health/why-sca to learn more about our benefits.

Pay

USD $150,000.00/Yr. - USD $185,000.00/Yr.

This response is AI-generated, for reference only.

Similar jobs

Principal Security Architect

Palo Alto NetworksSanta Clara, CA· 2 wk ago
Engineering$163k–$263k/yrapply on paloaltonetworks.wd5.myworkdayjobs.com

Principal Security Architect

Quest DiagnosticsSecaucus, NJ· 2 mo ago
Information Technology$160k–$225k/yrapply on hdox.fa.us6.oraclecloud.com