Talent.com
compu vision northeast
BEST Program Security Architect - 26-13420compu vision northeast • Worcester, Massachusetts, United States
Search for other jobs
BEST Program Security Architect - 26-13420

BEST Program Security Architect - 26-13420

compu vision northeast • Worcester, Massachusetts, United States
8 hours ago
Job type
  • Full-time
Job description

BEST Program Security Architect

Location: Boston, MA
Duration: 6 Months

Position Summary

The BEST Program Security Architect will work with the BEST Solution Technical Lead and Deputy Program Manager to support the adoption and implementation of the future-state end-user security solution and protocols.

The Security Architect will collaborate with program leadership, the BEST PMO, BEST Phase 2 Technical Lead, Risk Management Team, product vendor, Systems Integrator (SI), security teams, and other stakeholders to deploy technical controls that meet end-user security requirements and establish processes and standards for maintaining secure configurations within the new Human Resource Management and Payroll solution.

As a key member of the project Security Team, this role will provide security architecture, risk management, compliance, technical guidance, and oversight throughout design, development, testing, implementation, and transition to operations.

Key Responsibilities Security Architecture & Solution Design

  • Translate complex security requirements and risks into sound technical solutions and architectural recommendations.
  • Provide technical security and architectural direction to technology and business teams.
  • Develop and document future-state security architecture supporting application, data, infrastructure, and environment security.
  • Ensure security controls and access requirements are incorporated throughout the solution lifecycle.
  • Design and implement security protocols, processes, standards, and procedures.
  • Oversee implementation of the three major security components:
    • Infrastructure/hosting security
    • Application security
    • User authentication security
  • Support implementation of the complete solution security profile, including:
    • Azure Active Directory (AD) integration
    • Single Sign-On (SSO)
    • Solution user security roles
    • Solution workflow roles

Identity, Access & End-User Security

  • Partner with security teams to integrate Workday and Workday Prism with enterprise SSO for employees, vendors, departments, and contractors.
  • Assess alternative authentication and access-management options for users who cannot utilize standard SSO solutions.
  • Define and recommend end-user security roles, groups, permissions, and data-access controls.
  • Develop user provisioning and de-provisioning procedures for onboarding and offboarding.
  • Oversee integration and testing of:
    • SSO
    • Identity and Access Management (IAM)
    • Multi-Factor Authentication (MFA)
    • Cloud SaaS vendor user-access management
    • Workday access controls and provisioning processes
  • Support identification and approval of end users and coordinate Day One go-live provisioning.
  • Drive end-to-end testing of the go-live security solution.
  • Advise security administrators on standard and exception-based security authorization requests.

Risk, Compliance & Governance

  • Support identification, assessment, documentation, prioritization, mitigation, monitoring, and escalation of program risks.
  • Maintain and support the program risk register, ensuring risks have:
    • Clearly identified owners
    • Mitigation actions
    • Target dates
    • Escalation paths
  • Conduct risk, business impact, control, and vulnerability assessments.
  • Assess compliance with applicable security frameworks and standards, including NIST, ISO, COSO, PCI, FERPA, and GLBA.
  • Translate applicable security policies and standards into implementation actions, controls, solutions, and operational processes.
  • Monitor compliance throughout design, configuration, development, testing, deployment, and transition to operations.
  • Identify regulatory and legislative changes that may affect security policies, standards, and procedures.
  • Recommend appropriate policy and process changes based on regulatory developments.

Vendor, SLA & Audit Oversight

  • Develop and recommend protocols for monitoring vendor performance against security-related Service Level Agreements (SLAs).
  • Review vendor security reports, annual security audits, disaster recovery testing, and related documentation.
  • Establish processes for reviewing and monitoring vendor security SLA compliance.
  • Review requirements agreed upon between the organization, Systems Integrator, and product vendors.
  • Analyze vendor, SI, and third-party audit results and recommend acceptable risk and remediation strategies.
  • Track audit finding remediation and provide status updates to program leadership.
  • Collect and maintain documentation and artifacts required to support IT, security, compliance, and statewide audits.
  • Support documentation related to system conversion, data validation, operations, and data reliability.

Incident Response & Security Operations

  • Assist security administrators and IT personnel with resolution of security incidents.
  • Act as a liaison between incident response leads and subject matter experts.
  • Monitor security reports and logs for unusual or potentially malicious activity.
  • Provide guidance related to indicators of compromise (IOCs), vendor security vulnerability notifications, security alerts, and incident response.
  • Develop, test, and document security incident response procedures.
  • Research emerging threats and security alerts and recommend appropriate remediation.
  • Support security operations teams throughout implementation and ongoing operations.

Disaster Recovery & Business Continuity

  • Contribute to disaster recovery, business continuity, backup, and operational planning.
  • Support development, testing, and documentation of disaster recovery and business continuity procedures.
  • Monitor and assess business continuity and disaster recovery programs.
  • Participate in disaster recovery/business continuity testing and tabletop security reviews.
  • Execute end-to-end tabletop security reviews of go-live processes.

Security Testing & Vulnerability Management

  • Oversee security and compliance testing and documentation.
  • Review testing results, identify issues, and coordinate remediation.
  • Monitor application vulnerability assessments, penetration testing, and related security testing.
  • Identify business and technology vulnerabilities and provide recommendations to program leadership.
  • Implement agreed-upon mitigations and solutions to address identified vulnerabilities.
  • Ensure security requirements and controls are properly addressed throughout application development and implementation.

AI Security

  • Oversee and advise on the secure use of AI tools within the program.
  • Advise vendors and Systems Integrators on security considerations associated with AI capabilities built into the Workday solution.
  • Evaluate AI-related security risks and recommend appropriate controls and mitigation strategies.

Documentation & Process Development

  • Develop and maintain security architecture documentation, security plans, operational procedures, technical controls, and security diagrams.
  • Develop strategies, procedures, roles, and responsibilities to enforce security requirements.
  • Ensure completion of information security operations documentation.
  • Develop and maintain security policies, processes, procedures, and standards.
  • Provide recommendations related to end-user data conversion from legacy systems to the new solution.
  • Support identification, definition, and validation of inbound and outbound integration data-exchange security requirements.
  • Maintain documentation supporting compliance, audit, security operations, and risk management.

Collaboration & Stakeholder Support

  • Work closely with technical leadership, security teams, business teams, vendors, Systems Integrators, and agency stakeholders.
  • Collaborate with security leadership and risk management teams to identify and implement technical controls.
  • Support decentralized security-management activities across participating agencies.
  • Provide security guidance throughout the project lifecycle.
  • Participate in design sessions, business system analysis, security reviews, and implementation planning.
  • Support training, operational change management, and security awareness activities.
  • Coordinate with Independent Verification and Validation (IV&V) vendors to support proper security adoption.

Required Skills & Experience

  • In-depth experience with technical configurations, technologies, and processing environments in projects of similar size and complexity.
  • Strong knowledge of information risk concepts and principles and their relationship to business requirements and security controls.
  • Experience developing and documenting security architectures and plans, including strategic, tactical, and project-level plans.
  • Experience with information security frameworks and methodologies, including:
    • ISO 2700x
    • ITIL
    • SOX
    • COBIT
    • NIST
  • Experience architecting and implementing cloud-based security solutions.
  • Extensive knowledge of security technologies and capabilities, including:
    • Identity and Access Management (IAM/IDM)
    • SSO
    • MFA
    • Privileged Access Management (PAM)
    • Data Loss Prevention (DLP)
    • Encryption
    • Endpoint security
    • Vulnerability scanning
    • Patch management
    • Anti-malware
    • Automated policy compliance tools
    • Desktop security tools
  • Extensive experience integrating security tools and third-party vendor solutions.
  • Strong understanding of network infrastructure, including routers, switches, firewalls, network protocols, and related concepts.
  • Strong risk assessment and vulnerability assessment experience.
  • Proficiency in risk, business impact, control, and vulnerability assessments.
  • Experience developing, documenting, and maintaining security policies, processes, procedures, and standards.
  • Strong analytical and business analysis skills with the ability to translate security requirements into appropriate controls.
  • Excellent planning, organization, communication, prioritization, and stakeholder-management skills.
  • Experience working with modern issue-tracking systems such as JIRA.
  • Strong written and verbal communication skills.
  • Ability to interact effectively with personnel at all organizational levels and across multiple business units.
  • Ability to understand and align security requirements with business objectives.

Preferred Qualifications

  • Extensive experience with Human Resources and Payroll systems security requirements.
  • Experience defining and implementing end-user security protocols within a large public- or private-sector organization.
  • Experience with AI security.
  • Experience implementing AI tools within government agencies.
  • Experience with Workday Human Resource and Payroll solutions.
  • Workday implementation experience within a government environment.
  • Experience with Workday Prism data and reporting solutions.
  • Experience managing Workday user security as part of a business/non-IT team.
  • Experience transitioning traditional IT security functions to business teams.
  • Extensive experience with SaaS cloud implementations, particularly migrations from legacy on-premises applications to cloud platforms.
  • Experience operating end-user security protocols and policies within large organizations.
  • Experience with audit, compliance, and governance activities.
  • Experience with Microsoft security tools and functions.
  • Experience with Snowflake security functions.
  • Experience implementing technical configurations and security environments for projects of similar size and complexity.

Minimum Entrance Requirements

  • Bachelor's degree in Computer Science, Systems Analysis, or a related field, or equivalent experience in audit, compliance, security risk, and compliance management.
  • Minimum of 9 years of IT design and implementation experience.
  • Deep knowledge in at least two of the following technical disciplines:
    • Infrastructure and network design
    • Application development
    • Application Programming Interfaces (APIs)
    • Middleware
    • Servers and storage
    • Database management
    • Data security
    • Systems administration and operations
  • Experience generating security-related materials, including:
    • Compliance documentation
    • Security operational procedures
    • Security implementation plans
    • Network diagrams
    • Security architecture diagrams
  • Minimum of 5 years of security architecture, design, and implementation experience.
  • Security certifications such as Security+ or equivalent are preferred/required as applicable.
Create a job alert for this search

BEST Program Security Architect - 26-13420 • Worcester, Massachusetts, United States