Sr. Security Architect, Identity and Application Security

  • Boise
  • Idaho State Job Bank

Sr. Security Architect, Identity and Application Security at Cardinal Health in Boise, Idaho, United States Job Description This role is for a Sr. Security Architect in our Information Security group focused on driving security strategy and improving the security posture of the organization. The ideal candidate will possess a strong information security and project execution background. Accountabilities include : + Drives development of enterprise security strategy aligned with NIST CSF1.1 with focus on People, Processes, and Technology + Contributes to the creation of information security technology strategies and roadmaps based on business strategy, cybersecurity assessments, IT trends and the overall threat landscape. + Contributes to the development of information security architectures that align with assessment remediation requirements, reference architectures, design patterns and technology standards + Collaborates with Principal Architects to develop and document reference architectures and architectural patterns + Collaborates with IT and Business partners to deliver security technology roadmaps + Learns and masters innovative security technologies with focus on 1-3 year transformation of Cardinal Health + Developes secure architectures that incorporate components from Identity and Access Management, DevSecOps, Networking, and Secrets ManagementProvides security architecture guidance on large-scale, complex projects + Ensures project adherence to information security remediation efforts during solution build and implementation + Participates in cybersecurity control assessments providing risk-based gap analysis and prioritized remediation recommendations + Communicates the impact of cybersecurity gaps to diverse audiences + Designs secure environments for cloud native services such as: Compute, Kubernetes, Container Registries, Databases, Pub/Sub, Infrastructure as Code, DevSecOps, CI/CD Pipelines, Cloud Consoles, Serverless Computing, APIs, and other applicable applications or services. + Mentors and educates less experienced employees in the organization + Designs security controls for emerging technologies (IoT, cloud technologies, automation, AI, etc.) Qualifications + Industry-specific certifications preferred, such as Security+, CISSP, AWS certifications, etc. + Undergraduate degree in a technical field + 7+ years of experience in Information Technology, with a preferred concentration on Information Security + Advanced experience with information security principles, practices, technologies, programs and procedures, accompanied by an To view full details and how to apply, please login or create a Job Seeker account