waypointjobs

US Anesthesia Partners

Information Security Architect

Remote — United States (see country and timezone requirements)

Check who can apply and the requirements below before continuing.

Job description

Overview

US Anesthesia Partners is the highest-quality single-specialty anesthesia practice in the United States, with over 6,000 employees distributed across 10 states. Our clinical and non-clinical staff support each other as they work toward a common vision: Forging a better future by empowering people to advance exceptional care.

POSITION SUMMARY: The Information Security Architect is a functional, hands-on architect whose responsibility is to lead the governance and maturation of secure design, implementation and management for Enterprise applications and systems across all IT domains. This role partners closely with developers, DevOps, cloud infrastructure, networking, solution architects and security teams to embed security throughout the software development lifecycle (SDLC) while enabling rapid delivery of cloud-based solutions.

The ideal candidate has deep expertise in cloud security architecture, application security, DevSecOps, threat modeling, and modern cloud platforms such as AWS and Azure. This role also requires extensive knowledge and understanding of platform architecture, software development, well architected frameworks, and the ability to solve complex technical challenges. The Information Security Architect will serve as a trusted advisor to development teams, helping design resilient, scalable, and secure applications that meet business and regulatory requirements.

Job Highlights

ESSENTIAL DUTIES AND RESPONSIBILITIES: (The ideal candidate must be able to complete all physical requirements of the job with or without a reasonable accommodation) Pineapple

Establishes and enforces secure software development standards and cloud security best practices.

Leads the security lifecycle by reviewing emerging technologies, threats, and trends as well as maturing end of life governance for applications and technologies.

Participates in and matures the Architectural Review Board by applying a security focused mindset to all IT domains being reviewed.

Reviews application architecture documentation including diagrams and runbooks with a security focused lens.

Partners with engineering and DevOps teams to create security governance and best practice into CI/CD pipelines.

Conducts architecture risk assessments, threat modeling, and secure design reviews for new and existing applications.

Develops security reference architectures, design patterns, and technical standards for cloud-native applications.

Leads application security initiatives including SAST, DAST, software composition analysis (SCA), Infrastructure as Code (IaC) scanning, container security, and API security.

Works directly with the enterprise architect to ensure that overall enterprise security architecture, governance, and guidance is being executed on all IT domain levels.

Evaluates cloud services and third-party technologies for security risks and compliance requirements.

Collaborates with security operations, infrastructure, compliance, and engineering teams to investigate and resolve security findings.

Acts as a trusted advisor to development, infrastructure, network, cloud, data, and security teams.

Ensures cloud applications comply with organizational policies and applicable regulatory frameworks such as PCI DSS, HIPAA, SOC 2, ISO 27001, NIST, and GDPR.

Provides technical leadership and mentorship to development teams on secure coding practices and cloud security.

Performs other duties as assigned by management.

Qualifications

KNOWLEDGE/SKILLS/ABILITIES (KSAs):

Bachelor’s degree in computer science, business, or a related field required (or equivalent work experience).

7+ years of experience securing enterprise environments across on-premises, hybrid, and cloud infrastructures.

Strong understanding of secure software development lifecycle (SSDLC) and DevSecOps practices.

Strong knowledge of secure coding principles and common application vulnerabilities (OWASP Top 10, API Security Top 10).

Solid knowledge and experience working with Azure Dev Ops technology with focus on CI/CD pipelines and GIT repositories.

Strong knowledge of identity and access management, authentication, authorization, OAuth, OpenID Connect, SAML, risk management, and Zero Trust principles.

Strong familiarity with SIEM, EDR/XDR, IAM, PAM, CASB, DLP, and vulnerability management platforms.

Experience in healthcare is preferred.

CISSP certification is preferred.

Ability to understand and translate business needs, aligning them to proper technical application solutions.

Ability to translate security policy, regulatory requirements, and risk findings into practical architecture guidance.

Excellent communication and collaboration skills with the ability to work with multiple teams simultaneously.

Excellent time management skills and ability to work on multiple business critical projects simultaneously.

Understanding of core security and compliance principles in a healthcare environment.

Strong analytical and problem-solving skills with the ability to solve complex technical problems.

Originally posted on Himalayas

Who can apply

Eligible countries: United States. Accepted UTC offsets: UTC-10, UTC-9, UTC-8, UTC-7, UTC-6, UTC-5, UTC+14. Review the full description for employer-specific work authorization, residency and schedule requirements.

Ready for your next step?Apply on the official website
Apply on Himalayas ↗

Explore related searches

Current related jobs

infisical

Jobicy

Senior Full Stack Engineer

Remote — Brazil, Canada, Europe, USA

Salary not specifiedRemote

Infisical is the open source security infrastructure platform that engineers use for secrets management, certificates, and privileged access mana…

Listing review due 2026-10-07View job

Spotify

Jobicy

Data Scientist - Music Mission

Remote — USA

Salary not specifiedRemote

The Music Mission enables music creators to grow, engage, and monetize their fan bases on Spotify. Central to the Music Mission's vision is the d…

Listing review due 2026-10-07View job

Spotify

Jobicy

Data Scientist - Music Promotion

Remote — USA

Salary not specifiedRemote

The Music Mission enables Music creators to grow, engage & monetize their fan bases on Spotify. Central to the Music Mission's vision is the deve…

Listing review due 2026-10-07View job

infisical

Jobicy

Strategic Finance

Remote — Canada, USA

Salary not specifiedRemote

Infisical is the open source security infrastructure platform that engineers use for secrets management, certificates, and privileged access mana…

Listing review due 2026-10-07View job