Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
JobTailor Logo

See all jobs on JobTailor

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Brown Medicine

IS Principal Security Architect

Brown Medicine

Principal Security Architect securing Brown University Health’s hybrid and multi-cloud healthcare environments. Governing identity, data, network, AI, and enterprise security architecture.

Posted 8/10/2026full-timeRemote • Rhode Island • 🇺🇸 United StatesLead💰 $127,691 - $210,725 per yearWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates extensive expertise in security architecture for hybrid and multi-cloud environments, with a strong focus on compliance with regulatory standards and best practices. Proficient in defining security requirements, conducting risk assessments, and implementing security controls across various platforms and technologies.

Highest-signal resume keywords
Security Architecture DesignCloud Security GovernanceRisk Assessment and ManagementSecurity Certifications (CISSP, CCSP, GIAC, etc.)Technical Leadership in Information Security

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Security ArchitectureRisk AssessmentCloud SecurityNetwork SecurityIdentity Access ManagementEncryptionPythonPowerShellTerraformCI/CD Integration
Soft Skills
Excellent Communication SkillsMotivated Self-StarterTechnical Documentation
Tools & Technologies
SIEM PlatformsVulnerability Management ToolsCSPM SolutionsMonitoring PlatformsAPI Integrations
Certifications & Qualifications
CISSPCCSPGIACISSAPCKSCCAKOSCPOSCE
Industry Keywords
HIPAANISTISO 27001Security FrameworksRegulatory Compliance

Tech Stack

Tools & technologies
AnsibleAWSAzureCloudDNSFirewallsLinuxPythonSwitchingTerraformVault

About the role

Key responsibilities & impact
  • Establish and govern secure technology architecture across hybrid on-premises and multi-cloud environments
  • Partner with infrastructure, application, data, and cloud platform teams to translate security strategy, regulatory expectations, and industry best practices into reference architectures, security standards, and design requirements
  • Own enterprise security reference architectures, design standards, and security patterns
  • Approve, require modification of, or reject proposed designs that do not meet security requirements; govern deviations through exception management
  • Define security requirements during project intake and early design phases
  • Lead security architecture reviews and assurance activities against standards, reference architectures, threat models, and control requirements
  • Drive remediation of security and control gaps across identity, network segmentation, data protection, monitoring, CI/CD, and third-party integrations
  • Design security architecture for Microsoft Fabric and lakehouse patterns, secure data ingestion pipelines, Microsoft Purview governance, encryption, and customer-managed keys
  • Define secure ingestion and connectivity patterns for on-premises systems and third-party platforms
  • Define and enforce security architecture for AI platforms and agent-based solutions
  • Assess acquired entities and define transition architectures aligned to enterprise standards
  • Define and maintain Microsoft Entra ID security architecture standards
  • Define secure network architecture patterns across on-premises and cloud environments
  • Define enterprise logging, telemetry, monitoring, SIEM integration, retention, and visibility requirements
  • Own and maintain enterprise security configuration standards and baselines across endpoints, infrastructure, cloud platforms, identity services, and AI/agent platforms
  • Ensure alignment with CIS Benchmarks and internal policy requirements and validate adoption
  • Perform detailed security risk assessments and translate findings into risk narratives, compensating controls, and prioritized roadmaps
  • Evaluate new technologies and platforms for architectural fit, integration requirements, and risk implications
  • Provide architectural guidance during major incidents and support post-incident reviews
  • Attend team, project, project management, problem management, cloud migration, and major incident conference calls as required
  • Participate in compliance and audit activities
  • Maintain work effort status within SLAs on Brown University Health’s Service Desk and Task Management Platforms
  • Perform other duties as assigned

Requirements

What you’ll need
  • Minimum 10 years of IS/IT experience, including 5+ years in information security architecture, engineering, or related senior technical security roles
  • Bachelor’s degree in information systems or equivalent experience; MBA or MS in Information Security preferred
  • Minimum of 3 active security certifications required at hire or within 6 months, such as CISSP, CCSP, GIAC, ISSAP, CKS, CCAK, OSCP/OSCE, or equivalent
  • Senior technical leadership across enterprise architecture, cloud security, identity security, AI governance, and data protection
  • Experience designing and governing security architecture for hybrid and multi-cloud environments
  • Experience with segmentation, secure connectivity, VPN, ExpressRoute, Direct Connect equivalents, DNS/routing, egress controls, and cloud governance models
  • Experience securing Azure and AWS environments across multiple subscriptions/accounts
  • Strong technical knowledge of security methodologies, platform hardening, and enterprise security controls across Windows/Linux systems, endpoints, cloud platforms, and enterprise infrastructure
  • Knowledge of IAM, federation, SAML, OAuth2, OpenID Connect, Conditional Access, RBAC, privileged access management, and application identity governance
  • Experience implementing phishing-resistant MFA, including FIDO2/WebAuthn, smart cards, or certificate-based authentication
  • Knowledge of encryption, PKI, secrets management, and KMS/Key Vault
  • Experience with Python, PowerShell, Bash, cloud CLIs/SDKs, and API/webhook integrations
  • Experience integrating security controls into Terraform, Ansible, and CI/CD workflows
  • Experience with SIEM and monitoring platforms; SOAR and automated response familiarity preferred
  • Knowledge of vulnerability management tools such as Qualys, Nessus, and Rapid7
  • Experience with CSPM/CWPP solutions across multi-cloud environments
  • Strong understanding of network security architecture, firewalls, routing, switching, DNS, private networking, and packet analysis
  • Strong understanding of HIPAA/HITECH, NIST, ISO 27001, security frameworks, regulatory requirements, and risk methodologies
  • Ability to perform risk, control, vulnerability, and business impact assessments and create remediation plans
  • Excellent verbal and written communication skills, technical documentation, architectural diagrams, and executive-level reporting
  • Motivated self-starter with a record of owning security challenges through resolution
  • Ability to work Monday–Friday, 8:30am–5:00pm Eastern Time
  • No driving required
  • No supervisory responsibilities

Benefits

Comp & perks
  • Equal employment opportunity and a work environment free from unlawful discrimination and harassment
  • Respectful, inclusive, and equitable environment
  • Holistic well-being support for employees and their families