ForgeApply · Job listing
IS Principal Security Architect
Brown University Health
Tailor your resume to this posting in about a minute.
ForgeApply tailors your resume and cover letter to this exact posting, then hands you a ready-to-submit application for Brown University Health's site. Free trial, no card required.
About this role
SUMMARY:
The Principal Security Architect is a key member of the CISO organization responsible for establishing and governing secure technology architecture across hybrid on-premises and multi-cloud environments. This role serves as a trusted subject matter expert partnering with infrastructure, application, data, and cloud platform teams to translate security strategy, regulatory expectations, and industry best practices into practical reference architectures, security standards, and design requirements. The Principal Security Architect leads architecture review and assurance activities to ensure solutions are implemented in alignment with approved designs and enterprise standards, and drives remediation of identified security and control gaps across identity, network segmentation, data protection, monitoring, CI/CD, and third-party integrations.
Owns enterprise security reference architectures, design standards, and security patterns across the organization. Has authority to approve, require modification of, or reject proposed designs that do not meet established security requirements, and ensures deviations are formally governed through the enterprise exception management process.
RESPONSIBILITIES:
Engage in project intake and early design phases to define security requirements prior to implementation. Partner with infrastructure, application, and cloud teams to embed security-by-design into initial architecture decisions and reduce downstream rework and exception volume.
Serve as a subject matter expert for the evaluation, design, and secure adoption of infrastructure, cloud platforms, applications, and enterprise technologies, ensuring security requirements are incorporated throughout the solution lifecycle. Lead security architecture review and assurance activities by assessing proposed and existing designs, network and application architecture diagrams, and technology implementations against enterprise standards, reference architectures, threat models, and control requirements; defining security requirements and guardrails; and validating implemented solutions align with approved designs and enterprise standards.
Identify and drive remediation of security and control gaps across identity, network segmentation, data protection, logging/monitoring, key management, CI/CD, and third-party integrations in partnership with Infrastructure, Application, Data, and Cloud Platform teams.
Design security architecture for Microsoft Fabric and lakehouse patterns (Bronze/Silver/Gold), including secure data ingestion pipelines (e.g., Data Factory), least-privilege access using service principals and managed identities, strong data governance controls such as classification, labeling, lineage, and policy enforcement via Microsoft Purview, and secure storage and access boundaries through encryption and customer-managed keys (where applicable). Define secure ingestion and connectivity patterns for on-premises systems (e.g., EMR/Epic, relational databases) and third-party platforms (e.g., Snowflake), including segmentation, traceability, and segregation of duties between data engineering and data consumers.
Define and enforce security architecture for AI platforms and agent-based solutions (e.g., Copilot Studio, Azure AI services), including identity and access controls for service principals and managed identities, least-privilege connector design, data protection and prompt handling safeguards, logging and traceability of agent actions, and integration with enterprise data governance controls (e.g., Microsoft Purview).
Assess and integrate acquired entities into the enterprise security architecture by evaluating inherited environments, identifying control gaps, and defining transition architectures that align to enterprise standards while accounting for operational constraints.
Define and maintain Microsoft Entra ID security architecture standards, including Conditional Access, phishing-resistant MFA, PIM, RBAC design, privileged access workflows, and application identity governance.
Define secure network architecture patterns including segmentation, private networking, egress controls, firewall policy, and DNS security considerations across on-premises and cloud environments.
Define enterprise logging, telemetry, and monitoring architecture requirements, including SIEM integration, retention standards, and visibility requirements across on-premises, cloud, research, and AI environments.
Own and maintain enterprise security configuration standards and baselines across endpoints, infrastructure, cloud platforms (Azure and AWS), identity services, AI/agent platforms, and controlled environments including research and AI enclaves. This includes Windows, Linux and macOS systems, network devices, cloud-native services, Microsoft Entra ID, and AI agent frameworks. Ensure alignment with CIS Benchmarks and internal policy requirements and validate adoption through architecture governance and coordination with engineering and control validation teams, with particular focus on protecting sensitive data within research and AI workloads.
Perform detailed security risk assessments across infrastructure, endpoints, identity, networks, applications, and data platforms; translate findings into actionable risk narratives, compensating controls, and prioritized roadmaps.
Evaluate new technologies and platforms for architectural fit, integration requirements, and risk implications, providing recommendations aligned to enterprise security strategy and standards.
Provide architectural guidance during major incidents and support post-incident reviews to identify control gaps and improve future-state design.
Attend and actively contribute to team, project, project management, problem management, cloud migration and major incident conference calls as required.
Participate in compliance and audit activities in support of internal and external audit requirements.
Maintains work effort status within SLA’s
Ready to apply to Brown University Health?
Tailor my resume for this roleSimilar jobs
- Principal Architect - Security — 3cloud · Remote
- Principal Security Engineer — Candidhealth · San Francisco (CA), Denver (CO), New York (NY)
- Principal Security Engineer — Seesaw · Remote
- Principal Security Engineer — Intersystems · Boston, MA
- Principal Product Manager, Security — Clickhouse · Remote
- Principal Software Security Architect — Beyondtrust · Remote United States
- Lead Security Architect — 2k · Austin, Texas, United States
- AI Security - Principal Security Research Engineer I — Elastic · United States
More like this: More jobs at Brown University Health · Browse all jobs