BEST Program Security Architect

Volantsoft Inc•Boston, MA
•Hybrid

About The Position

The BEST Program Security Architect will oversee the implementation of three major security components: Infrastructure (hosting) security, Application Security, and User Authentication security. This role involves aligning with the BEST project team, vendors, system integrators (SI), EOTSS security, and the Comptroller Risk Management Team. Key responsibilities include partnering with EOTSS to integrate Workday and Workday Prism with Commonwealth Single Sign-On (SSO), assessing and recommending solutions for managing individuals with limitations on the standard EOTSS SSO solution, and assisting in the remediation of department user data. The architect will also oversee security SLAs with vendors, ensure appropriate security reports are created and monitored, and work with EOTSS on security and compliance testing. They will collaborate with BEST technical leadership to develop strategies and procedures for enforcing security requirements and addressing risks. Recommendations will be provided regarding end-user security roles, data access controls, and provisioning/de-provisioning protocols. The role includes participation in disaster recovery and business continuity planning, overseeing the establishment of Security Incident Event Management (SIEM), and supporting the identification, assessment, and mitigation of program risks. Integration configuration and testing of EOTSS SSO, IAM, MFA, Cloud SaaS vendor user access management, and Workday access controls will be a key focus. The architect will implement agreed-upon mitigations, document technical controls, and assist security administrators in resolving security incidents. They will translate Comptroller, Commonwealth, and EOTSS policies into program implementation actions and operational processes, and assist in identifying security requirements through risk and business impact assessments. The role involves conducting business system analysis, designing future state security solutions, identifying and recommending solutions for business and technology security vulnerabilities, and assessing compliance with various cybersecurity frameworks. Coordination of information security operations documentation, advisory roles in application development, and support for end-user provisioning and testing are also included. The architect will advise on security authorization requests, research and recommend security hardware and software, analyze audit results, and provide ongoing advice for incident response. Maintaining awareness of security-standard-setting groups and relevant legislation, researching new threats, and ensuring security operational actions are properly implemented are crucial. Support for integration data exchange requirements, monitoring compliance throughout the project lifecycle, executing security reviews, and advising on the use of AI tools from a security perspective are also part of the role. The architect will develop strategies and procedures to enforce security requirements and oversee configuration updates related to security controls, providing advice on data conversion and collaborating with various security offices to implement technical controls and processes.

Requirements

  • In-depth exposure to technical configurations, technologies, and processing environments in one or more projects of similar size and complexity to BEST
  • In-depth knowledge and understanding of information risk concepts and principles as a means of relating business needs to security controls
  • Knowledge of and experience in developing and documenting security architecture and plans, including strategic, tactical and project plans
  • Documented experience with common information security management frameworks, such as ISO 2700x, ITIL, SOX, COBIT, and NIST
  • Experience in architecting and implementing cloud-based security solutions
  • Extensive knowledge of security tools and capabilities, such as IDM and SSO
  • Extensive experience in integrating security tools and 3rd party vendor solutions
  • Exceptional planning, organization, communication, prioritization, and business analysis skills
  • In-depth knowledge of risk assessment methods and technologies
  • Proficiency in performing risk, business impact, control, and vulnerability assessments
  • Excellent technical knowledge of mainstream operating systems and a wide range of security technologies, such as network security appliances, IAM systems, anti-malware solutions, privileged access management (PAM), data loss prevention (DLP), encryption at-rest and in-transit, multi-factor authentication (MFA), end-point security, vulnerability scanning and patch management, automated policy compliance tools, and desktop security tools
  • Experience in developing, documenting, and maintaining security policies, processes, procedures, and standards
  • Knowledge of network infrastructure, including routers, switches, firewalls, and the associated network protocols and concepts
  • Strong analytical skills to analyze security requirements and relate them to appropriate security controls
  • Documented written and verbal communication skills
  • Experience working with modern issue tracking systems (JIRA)
  • Ability to interact with personnel at all levels and across all business units and organizations, and to comprehend business imperatives
  • Bachelor's degree in computer science, system analysis or a related study, or equivalent experience in the field of audit compliance and security risk and compliance management
  • Minimum of nine years of design and implementation experience in IT, with deep knowledge in a minimum of two of the following technical disciplines: infrastructure and network design, application development, application programming interfaces (APIs), middleware, servers and storage, database management, data security, and system administration and operations
  • Experience in generation of security materials, including but not limited to compliance adherence, security operational procedures, security implementation plans, and network and security diagrams
  • Minimum of five years of security architecting design and implementation with security certifications, such as Security+

Responsibilities

  • Oversee implementation of Infrastructure (hosting) security, Application Security, and User Authentication security.
  • Align with BEST project team, vendor, SI, EOTSS security, and Comptroller Risk Management Team.
  • Partner with EOTSS to onboard Workday and Workday Prism to work with the Commonwealth Single Sign-On (SSO).
  • Assess options and recommend how individuals with limitations on the standard EOTSS SSO solution will be managed and properly secured.
  • Assist in the remediation of department user data as necessary.
  • Oversee security SLAs with the vendor(s) to ensure appropriate security reports are created and monitored by the Commonwealth.
  • Work with EOTSS on security and compliance testing/documentation and review/remediate results/issues.
  • Work with BEST technical leadership to develop strategies, procedures and recommended roles and responsibilities to enforce security requirements and address identified risks.
  • Provide recommendations regarding end user security roles and groups, data access controls and security role provisioning and de-provisioning protocols.
  • Participate in disaster recovery, business continuity, backup, and operational planning; support DR/business continuity testing and documentation.
  • Oversee establishment of the overall Security Incident Event Management (SIEM) across several security operational domains.
  • Support the identification, assessment, documentation, prioritization, mitigation, monitoring, and escalation of program risks.
  • Support the program risk register and ensure risks have clearly identified owners, mitigation actions, target dates, and escalation paths.
  • Oversee integration configuration and testing of EOTSS Single Sign-On (SSO), EOTSS Identity Access Management (IAM), EOTSS Multi-Factor Authentication (MFA), Cloud SaaS vendor user access management, and Workday access controls and provisioning processes.
  • Implement agreed mitigations and solutions to address business and technology vulnerabilities.
  • Document and implement technical controls, processes and procedures related to data security.
  • Assist security administrators and IT staff in the resolution of reported security incidents; act as liaison between incident response leads and subject matter experts; monitor daily or weekly reports and security logs for unusual events.
  • Translate Comptroller, Commonwealth, and EOTSS policies into BEST program implementation actions, solutions, and processes, as well as on-going operational processes.
  • Assist in identifying security requirements using methods that may include risk and business impact assessments.
  • Conduct additional business system analysis as needed; design future state security solution supporting data, application, and environment security needs across multiple stakeholders.
  • Identify business and technology security vulnerabilities and make recommendations to program leadership and stakeholders.
  • Assess compliance with risk and cybersecurity frameworks and standards such as NIST, ISO, COSO, PCI, FERPA, and GLBA.
  • Assist in the coordination and completion of information security operations documentation.
  • Play an advisory role in application development and implementation to assess security requirements and controls and assure security issues are addressed throughout the project life cycle.
  • Support the Program and the BEST Phase 2 Technical Lead to identify approved end users of the new solution and coordinate provisioning of users for Day One go live; drive end-to-end testing of the go-live security solution.
  • Provide advice to security administrators on normal and exception-based processing of security authorization requests.
  • Research, evaluate and recommend information-security-related hardware and software, including developing business cases for security investments.
  • Analyze results of SI/product vendor audits or third-party audits to produce recommendations on acceptable risks and risk mitigation strategies.
  • Provide ongoing advice and support to Security Operations and IT for incident response, indicators of compromise (IOCs), vendor security vulnerability notifications, law enforcement security alerts, etc.
  • Maintain awareness of existing and proposed security-standard-setting groups, state and federal legislation and regulations pertaining to information security; identify regulatory changes affecting information security policy, standards, and procedures, and recommend changes.
  • Research and assess new threats and security alerts and recommend remedial actions.
  • Work with BEST Operations, Comptroller operations, EOTSS operations, and Agency operations to ensure security operational actions are properly implemented.
  • Assist/support BEST Phase 2 Technical Lead on integration data exchange inbound and outbound requirements identification, definition, and validation.
  • Monitor compliance throughout design, configuration, development, testing, deployment, and transition to operations.
  • Execute "tabletop" security reviews of end-to-end go-live security processes.
  • Oversee and advise BEST program use of AI tools from a security point of view; advise vendor and SI on use of AI tools built into the Workday product natively.
  • Ensure the completion of information security operations documentation.
  • Develop strategies, procedures and recommended roles and responsibilities to enforce security requirements and address identified risks related to the use of the new solution.
  • Oversee configuration updates and execution role in application development and implementation related to security requirements and controls; ensure security controls are implemented as planned and security and access needs are addressed throughout the user life cycle.
  • Provide advice and recommendations on the data conversion of end users from the legacy system to the new system.
  • Work with BEST, CTR's, and EOTSS' CSOs, CIOs, and the Comptroller's Risk Management Office to identify, select and implement technical controls related to data security and implement security processes and procedures.
  • Advise the BEST Team, SI and product vendors regarding end user security roles and groups, data access controls and security role provisioning and de-provisioning protocols.
  • Support the BEST Team and agencies in identifying approved end users of the new solution and coordinating provisioning of users for Day One go live.
  • Advise security administrators on normal and exception-based processing of security authorization requests including the use of SI or product vendor provided tools that monitor system use and data access irregularities.
  • Act as a liaison between incident response leads and subject matter experts.
  • Support the implementation of the new solution's complete security profile, including but not limited to: Azure Active Directory (AD) entry; Single Sign-On (SSO); New Solution User Security Role; New Solution User Workflow Role.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service