
Sr. Staff Security Architect
OpenLoop Health15 days ago
Remote, United States or Toronto, CanadaStaff+
Responsibilities
- Own and continuously evolve security architecture across cloud infrastructure, applications, and corporate systems.
- Lead threat modeling across product, engineering, and infrastructure initiatives, including coaching engineers to threat model their own work.
- Conduct system architecture reviews and provide actionable recommendations based on security principles and regulatory requirements.
- Design and scale the architecture review process using self-service patterns, risk-tiered review paths, and defined review criteria.
- Define application security standards covering secure design, API security, authentication, authorization, and data protection.
- Establish and maintain zero trust architecture across identity, network, endpoint, and data layers.
- Architect and govern key management, secrets management, encryption, and certificate lifecycle practices.
- Own security architecture for third-party integrations and control supply chain risk at the design stage.
- Translate GRC, privacy, audit, and HIPAA Security Rule requirements into concrete architectural controls for PHI systems.
- Maintain architecture decision records, reference designs, control frameworks, risk metrics, and executive reporting.
- Partner with security leadership on the architecture roadmap and mentor the broader security team.
- Research emerging threats and attack techniques targeting healthcare systems.
Requirements
- Bachelor’s degree in Computer Science, Information Security, or a related field, or equivalent professional experience.
- 10+ years of progressive security experience, including at least five years focused on security architecture across enterprise and cloud environments.
- Deep expertise in application security, cloud security, identity and access management, network security, and data protection.
- Hands-on experience architecting cloud security solutions involving network security, IAM, key and secrets management, encryption, and cloud-native security services.
- Experience leading threat modeling with STRIDE, PASTA, or equivalent methodologies across features and complete systems.
- Strong command of secure software development lifecycle practices, OWASP principles, and application security design patterns.
- Proficiency with OAuth 2.0, OIDC, and SAML across multi-tenant and patient-facing applications.
- Experience architecting key management, secrets management, and PKI or certificate lifecycle controls in cloud-native environments.
- Working knowledge of HIPAA Security Rule technical safeguards, HITRUST CSF, NIST CSF, and SOC 2 sufficient to design compliant controls.
- Ability to communicate complex architectural risk to technical and executive audiences.
- Preferred experience in healthcare, digital health, or another highly regulated industry.
- Preferred experience designing zero trust architectures, scaling architecture review processes, using HL7 or FHIR, applying SABSA or TOGAF security extensions, and mentoring senior engineers or establishing architecture practices.
Benefits
- Medical, dental, and vision plans.
- Flexible Spending Accounts and Health Savings Accounts.
- Flexible PTO.
- 401(k) with company match.
- Life insurance, pet insurance, and additional benefits.
- Salaried position in a relatively flat organizational structure emphasizing autonomy, competence, and belonging.