Jobs · Information Technology

Security Architect / Compliance Specialist

Accelerec Ltd. · United States · 1 wk ago
RemoteRemoteInformation TechnologyFull-time

Responsibilities

  • Design Phase
    • Design the complete zero-trust security architecture for the DAP on Microsoft Azure Government, including Microsoft Entra ID integration, conditional access policies, Privileged Identity Management (PIM), private endpoint configuration, network security groups, and Azure Firewall rules
    • Develop the Role-Based Access Control (RBAC) and Attribute-Based Access Control (ABAC) design covering Azure subscription, Fabric workspace, Power BI semantic model (RLS/CLS), and API access layers
    • Design encryption architecture: AES-256 encryption at rest, TLS 1.2+ in transit, Azure Key Vault configuration, and Customer-Managed Key (CMK) approach
    • Design immutable audit logging architecture using Azure Monitor Log Analytics with 90-day hot retention and long-term archival to Azure ADLS Gen2
    • Produce Security Architecture Design Document and System Security Plan (SSP) in accordance with NIST SP 800-53 Rev. 5 and NCDHHS Privacy and Security Office requirements
    • Map all NIST 800-53 and MARS-E controls to DAP solution components and document implementation approach in the SSP
  • Development and Build Phase
    • Implement zero-trust security controls across all DAP environments (Dev, Test, UAT, Production) including Entra ID conditional access, MFA enforcement, PIM just-in-time access, private endpoints, NSGs, and Azure Firewall
    • Configure Microsoft Defender for Cloud with NIST 800-53 regulatory compliance assessment enabled — providing continuous, automated security posture monitoring
    • Integrate Checkov and tfsec security scanning as mandatory gates in Azure DevOps CI/CD pipelines — blocking any deployment with HIGH or CRITICAL misconfigurations
    • Implement Azure Key Vault for all secrets, certificates, and encryption keys with automated rotation policies and minimum-privilege managed identity access
    • Configure Microsoft Purview sensitivity labels for automated PII/PHI classification across all 110–120 TB of DAP data
    • Ensure all infrastructure as code (Terraform) modules comply with security design and pass automated security scanning before deployment
  • Testing and Parallel Run Phase
    • Lead formal NIST 800-53 security assessment in Months 20–24, coordinating with NC DIT-approved independent assessors and NCDHHS Privacy and Security Office
    • Coordinate penetration testing engagement, track all findings, develop Plan of Action and Milestones (POAM), and ensure all Critical and High findings are remediated before go-live
    • Ensure all security test environments mirror production in security configuration, data protection measures, and reporting
    • Prepare Security Assessment Report and all required security documentation packages
  • O&M Responsibilities
    • Maintain continuous NIST 800-53 compliance monitoring through Microsoft Defender for Cloud — review compliance dashboard monthly and report compliance score to NCDHHS
    • Manage vulnerability remediation in accordance with contract SLA timelines: Critical (7 business days), High (30 business days), Medium (60 business days), Low (90 business days)
    • Support annual security/risk assessment and biennial Conditions for Enhanced Funding (CEF) assessment — providing full evidence packages and documentation
    • Respond to all security incidents within required SLA timeframes; maintain and update Privacy and Security Incident Management Plan
    • Conduct annual DR/BCP testing from a security perspective; certify all security controls are functioning in the recovery environment

Requirements

  • Bachelor's degree in Computer Science, Information Security, Information Technology, or a related field; Master's degree preferred
  • Minimum 7 years of experience in information security architecture and implementation, with at least 3 years in cloud security on Microsoft Azure Government or Azure Commercial
  • Demonstrated experience implementing NIST SP 800-53 security controls for government or healthcare information systems
  • Experience with FedRAMP authorization processes and Azure Government compliance frameworks
  • Experience implementing zero-trust security architectures including Microsoft Entra ID, Privileged Identity Management, and Azure network security
  • Experience configuring Microsoft Defender for Cloud regulatory compliance assessments
  • Experience with HIPAA technical safeguard implementation for systems handling Protected Health Information (PHI)
  • Strong knowledge of encryption standards, key management (Azure Key Vault), and data classification automation (Microsoft Purview preferred)

Preferred Qualifications

  • CISSP (Certified Information Systems Security Professional) or equivalent — strongly preferred
  • Microsoft Certified: Azure Security Engineer Associate (AZ-500)
  • Experience with Medicaid Enterprise System (MES) security requirements and CMS MARS-E controls
  • Experience with penetration testing coordination and POAM management
  • Experience with Infrastructure as Code security scanning tools (Checkov, tfsec)
  • CCSP (Certified Cloud Security Professional) or equivalent cloud security certification

Schedule

Remote (US-based required) | Onsite travel to Raleigh, NC as needed.

Similar jobs

Security Architect Specialist

Accenture Federal ServicesArlington, VA· 2 wk ago
Information Technology$79k–$160k/yrapply on boards.greenhouse.io