SCA Health logo
SCA HealthPosted 1 month ago

Principal Architect - Security

RemoteUnited States

Full TimeSenior LevelEnterprise

Job Summary

Develop and maintain an enterprise security architecture blueprint that aligns with business objectives and risk appetite. Serve as the authoritative security reviewer at the Architecture Review Board, evaluating designs for fitness and enforcing Zero Trust, Zscaler-anchored identity controls. Lead threat modeling practices using STRIDE to integrate findings into governance, while performing risk assessments to map mitigations and reduce project exposure. Design patterns for identity governance, data protection for PHI/PII, and secure network segmentation across hybrid and partner-driven environments. Provide strategic consultation to business customers and guide third-party vendor security reviews, ensuring compliance with NIST CSF, HIPAA, and HITRUST frameworks. Articulate analytical findings to executive management and foster IT maturity through mentorship and knowledge transfer.

Required Qualifications

  • Bachelor's degree or equivalent work experience
  • 8-10+ years of experience in security architecture and engineering, with the most recent role in an architect or technical leadership capacity
  • 2-5+ years of experience working in an architect or technical leadership capacity
  • Solid understanding of healthcare provider (ASC) security and compliance obligations (HIPAA, HITRUST), with the ability to provide a trusted voice at the decision-making table
  • Strong command of security frameworks and control catalogs: NIST CSF, NIST 800-53, HITRUST, SOC 2, and PCI DSS
  • Deep identity and access management expertise: directory and identity platforms (Microsoft Entra ID and Active Directory), federation and authentication protocols (SAML, OIDC, OAuth 2.0, SCIM), Conditional Access, MFA and passwordless, and RBAC/ABAC authorization
  • Identity governance and privileged access experience: IGA lifecycle and provisioning, access certification and entitlement management, and PAM with just-in-time elevation (e.g., Entra Privileged Identity Management); experience with workforce/partner identity across separated, non-federated identity stores — including externally issued contractor identities, B2B/guest, and Citrix — is a strong plus
  • Thorough understanding of cloud security and governance, in particular Microsoft Azure (landing zones, guardrails, policy-as-code)
  • Data protection expertise: encryption in transit and at rest, key management, and masking/tokenization for PHI and PII
  • Strong network and boundary security background, including segmentation and zero-trust network access
  • Hands-on Zscaler experience across the SSE platform — Zscaler Private Access (ZPA), Zscaler Internet Access (ZIA), and Zscaler Digital Experience (ZDX) — designing zero-trust access to replace legacy VPN, with an understanding of how Zscaler integrates with identity (Entra ID) and device posture
  • Proficiency with threat modeling (e.g., STRIDE) and risk assessment methodologies as they relate to integration and software engineering
  • Demonstrated experience operationalizing a threat-modeling program — establishing trigger criteria, applying a recognized methodology (e.g., STRIDE, PASTA, or attack-tree analysis), and integrating findings into architecture governance — not just performing individual threat models
  • Experience with security logging, monitoring, and detection, including SIEM and SOC integration
  • Experience with vulnerability management, SBOM, and DevSecOps / secure SDLC practices, including CI/CD security gates
  • Knowledge of TOGAF and a security architecture framework such as SABSA required; certification preferred (CISSP, CISSP-ISSAP, CCSP, SABSA, Microsoft SC-300 Identity and Access Administrator, Azure security certifications, or Zscaler certifications such as ZCCA/ZCCP)
  • Excellent conceptual and security design pattern skills irrespective of technology, and willingness to assume total ownership of security architecture from inception to delivery
  • Experience creating an effective framework and process model for establishing enterprise-wide security architecture
  • Ability and willingness to document security architecture, integrations, and dependencies for existing platforms and systems currently in use at SCA
  • Understanding and experience implementing the strategic alignment of business and security
  • Experience with third-party and vendor security risk management, particularly for Tier 1 PHI SaaS vendors
  • Demonstrated competency in communicating the value of security architecture to stakeholders and senior management
  • Strong interpersonal, verbal, and written communication skills, with the ability to develop and conduct executive-level presentations
  • Ability to collaborate with various levels of individuals – both IT and business
  • Self-directed with the ability to work effectively under tight deadlines

Desired Qualifications

  • Experience with Mergers & Acquisitions, in areas of security diligence and integration, is desirable.

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce