OpenLoop Health

Sr. Staff Security Architect

OpenLoop Health
Apply
15 days ago
Remote, United States or Toronto, CanadaStaff+

Responsibilities

  • Own and continuously evolve security architecture across cloud infrastructure, applications, and corporate systems.
  • Lead threat modeling across product, engineering, and infrastructure initiatives, including coaching engineers to threat model their own work.
  • Conduct system architecture reviews and provide actionable recommendations based on security principles and regulatory requirements.
  • Design and scale the architecture review process using self-service patterns, risk-tiered review paths, and defined review criteria.
  • Define application security standards covering secure design, API security, authentication, authorization, and data protection.
  • Establish and maintain zero trust architecture across identity, network, endpoint, and data layers.
  • Architect and govern key management, secrets management, encryption, and certificate lifecycle practices.
  • Own security architecture for third-party integrations and control supply chain risk at the design stage.
  • Translate GRC, privacy, audit, and HIPAA Security Rule requirements into concrete architectural controls for PHI systems.
  • Maintain architecture decision records, reference designs, control frameworks, risk metrics, and executive reporting.
  • Partner with security leadership on the architecture roadmap and mentor the broader security team.
  • Research emerging threats and attack techniques targeting healthcare systems.

Requirements

  • Bachelor’s degree in Computer Science, Information Security, or a related field, or equivalent professional experience.
  • 10+ years of progressive security experience, including at least five years focused on security architecture across enterprise and cloud environments.
  • Deep expertise in application security, cloud security, identity and access management, network security, and data protection.
  • Hands-on experience architecting cloud security solutions involving network security, IAM, key and secrets management, encryption, and cloud-native security services.
  • Experience leading threat modeling with STRIDE, PASTA, or equivalent methodologies across features and complete systems.
  • Strong command of secure software development lifecycle practices, OWASP principles, and application security design patterns.
  • Proficiency with OAuth 2.0, OIDC, and SAML across multi-tenant and patient-facing applications.
  • Experience architecting key management, secrets management, and PKI or certificate lifecycle controls in cloud-native environments.
  • Working knowledge of HIPAA Security Rule technical safeguards, HITRUST CSF, NIST CSF, and SOC 2 sufficient to design compliant controls.
  • Ability to communicate complex architectural risk to technical and executive audiences.
  • Preferred experience in healthcare, digital health, or another highly regulated industry.
  • Preferred experience designing zero trust architectures, scaling architecture review processes, using HL7 or FHIR, applying SABSA or TOGAF security extensions, and mentoring senior engineers or establishing architecture practices.

Benefits

  • Medical, dental, and vision plans.
  • Flexible Spending Accounts and Health Savings Accounts.
  • Flexible PTO.
  • 401(k) with company match.
  • Life insurance, pet insurance, and additional benefits.
  • Salaried position in a relatively flat organizational structure emphasizing autonomy, competence, and belonging.

Categories

OpenLoop Health

About OpenLoop Health

501-1,000 employees
Contact me