Lead security architecture initiatives across: AWS; Microsoft Azure; Google Cloud Platform (GCP)
Partner with engineering and DevOps teams to integrate security into CI/CD pipelines and Infrastructure as Code (IaC) workflows
Guide implementation of: Zero Trust principles; Container and Kubernetes security; Secrets management; Workload protection; Encryption and key management; Cloud-native monitoring and logging
Support secure migration and modernization initiatives
Ensure architecture and security controls align with applicable frameworks and regulations, including
NIST Cybersecurity Framework (CSF)
NIST SP 800-171
ISO 27001
SOC 2
HIPAA/HITECH
GDPR and international privacy regulations
OWASP ASVS
Participate in enterprise risk assessments and audit activities
Develop and maintain security standards, policies, technical baselines, and architectural documentation
Support protection of Genomic data; Biomedical research platforms; Clinical and laboratory systems; Scientific intellectual property; Sensitive patient and operational data
Collaborate with research and scientific teams to balance security, compliance, and scientific innovation
Advise on secure handling of regulated and sensitive healthcare or research information
Serve as a trusted advisor to executive leadership, engineering teams, and business stakeholders
Mentor security engineers and architects across the organization
Support strategic cybersecurity planning and long-term roadmap development
Lead cross-functional initiatives involving infrastructure, applications, cloud, compliance, and third-party vendors
Present technical and strategic security recommendations to leadership and governance committees
Candidates may have experience with tools and platforms such as
Burp Suite
Checkmarx
Veracode
Snyk
Semgrep
Trivy
Nessus
Qualys
Prisma Cloud
Wiz
Metasploit
OWASP ZAP