The BEST Program Security Architect will oversee the implementation of three major security components: Infrastructure (hosting) security, Application Security, and User Authentication security. This role involves aligning with the BEST project team, vendors, system integrators (SI), EOTSS security, and the Comptroller Risk Management Team. Key responsibilities include partnering with EOTSS to integrate Workday and Workday Prism with Commonwealth Single Sign-On (SSO), assessing and recommending solutions for managing individuals with limitations on the standard EOTSS SSO solution, and assisting in the remediation of department user data. The architect will also oversee security SLAs with vendors, ensure appropriate security reports are created and monitored, and work with EOTSS on security and compliance testing. They will collaborate with BEST technical leadership to develop strategies and procedures for enforcing security requirements and addressing risks. Recommendations will be provided regarding end-user security roles, data access controls, and provisioning/de-provisioning protocols. The role includes participation in disaster recovery and business continuity planning, overseeing the establishment of Security Incident Event Management (SIEM), and supporting the identification, assessment, and mitigation of program risks. Integration configuration and testing of EOTSS SSO, IAM, MFA, Cloud SaaS vendor user access management, and Workday access controls will be a key focus. The architect will implement agreed-upon mitigations, document technical controls, and assist security administrators in resolving security incidents. They will translate Comptroller, Commonwealth, and EOTSS policies into program implementation actions and operational processes, and assist in identifying security requirements through risk and business impact assessments. The role involves conducting business system analysis, designing future state security solutions, identifying and recommending solutions for business and technology security vulnerabilities, and assessing compliance with various cybersecurity frameworks. Coordination of information security operations documentation, advisory roles in application development, and support for end-user provisioning and testing are also included. The architect will advise on security authorization requests, research and recommend security hardware and software, analyze audit results, and provide ongoing advice for incident response. Maintaining awareness of security-standard-setting groups and relevant legislation, researching new threats, and ensuring security operational actions are properly implemented are crucial. Support for integration data exchange requirements, monitoring compliance throughout the project lifecycle, executing security reviews, and advising on the use of AI tools from a security perspective are also part of the role. The architect will develop strategies and procedures to enforce security requirements and oversee configuration updates related to security controls, providing advice on data conversion and collaborating with various security offices to implement technical controls and processes.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Senior