Information Security Architect

Health Management Associates,

About The Position

The Information Security Architect is responsible for designing, implementing, and managing the organization's security infrastructure. This role involves developing and enforcing security policies, ensuring the protection of sensitive data, and mitigating security risks across the enterprise.

Requirements

  • In-depth knowledge of security architecture, frameworks, standards, risk management, and threat assessment.
  • Demonstrated hands-on experience designing and securing Azure and/or AWS environments.
  • Knowledge of identity, network, workload, data, application, and endpoint security controls.
  • Experience with EDR platforms, malware investigation, threat hunting, and incident response.
  • Experience with firewalls, IDS/IPS, encryption, FortiGate/Fortinet, FortiManager, or comparable security platforms.
  • Application security knowledge, including secure design, code and configuration review, scripting, and automation.
  • Knowledge of HIPAA, SOC 2, HITRUST, penetration testing, disaster recovery, and business continuity practices.
  • Knowledge of security considerations for AI-enabled and agentic AI systems, including generative AI, AI application stacks, secure development, data protection, model and vendor risk, identity and access controls, monitoring, and governance frameworks for responsible AI use.
  • Strong analytical, problem-solving, organizational, and project-management skills.
  • Excellent verbal and written communication skills, with the ability to mentor others and explain technical risk to varied audiences.
  • Ability to produce clear technical and user-facing documentation, procedures, and architecture diagrams.

Responsibilities

  • Design, implement, and govern security architecture for on-premises and cloud environments, including Azure and AWS identity, network, workload, and data-protection controls.
  • Develop, maintain, and enforce security policies, standards, guidelines, and architecture principles aligned with applicable regulatory and security frameworks.
  • Lead security assessments, audits, penetration-testing activities, vulnerability reviews, and configuration assessments. Develop risk-based mitigation strategies addressing least privilege, RBAC, hardening, encryption, TLS, network security, and SaaS controls.
  • Conduct threat monitoring and proactive threat hunting; independently investigate, triage, and run down malware and EDR alerts (e.g., SentinelOne) through containment and resolution.
  • Develop and manage incident response plans, and lead incident response efforts, malware analysis, and forensic investigations through resolution.
  • Evaluate, recommend, and maintain security technologies, including firewalls, IDS/IPS, encryption solutions, endpoint security platforms, and related network controls. Leverage centralized management through FortiManager to maintain consistent Fortinet policy, configuration, and governance across the environment.
  • Secure in-house and cloud-hosted application development through secure design review, code and configuration review, and scripting and automation across the full stack.
  • Provide security architecture guidance for AI-enabled and agentic AI systems, including review of technology stacks, data flows, tool and API access, identity and permission boundaries, prompt and output controls, logging, monitoring, vendor/model risk, and governance requirements to support responsible and compliant AI use.
  • Ensure compliance with applicable laws, regulations, and standards (HIPAA, SOC 2, HITRUST, GDPR, etc.), and develop and enforce security governance frameworks.
  • Support SOC 2 audits, penetration testing engagements, and disaster recovery and business continuity planning, documentation, and testing.
  • Partner with IT, development, and business teams to integrate security into organizational processes.
  • Mentor staff and produce clear technical documentation, procedures, and architecture diagrams.
  • All other duties as assigned.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service