Cybersecurity Architect
Ensemble Health Partners Ohio, United States · $164K–$246K/yr
Hospitals and Health Care · 10,001+ employees
About the role
The Cybersecurity Architect designs and reviews security architectures across cloud, infrastructure, and application environments while ensuring alignment with regulatory requirements. This role acts as a technical advisor to engineering teams, developing threat models and promoting secure-by-design principles throughout the technology lifecycle.
What they look for
Requirements
Candidates must possess a bachelor's degree in a relevant field and 5 to 8 years of information security experience, including at least 2 years in a security architecture role. Proficiency in cloud security, regulatory frameworks like HIPAA and NIST, and strong analytical skills are required.
Benefits
Full description
Thank you for considering a career at Ensemble!
Ensemble is a leading provider of technology-enabled revenue cycle management solutions for health systems, including hospitals and affiliated physician groups. They offer end-to-end revenue cycle solutions as well as a comprehensive suite of point solutions to clients across the country.
Ensemble keeps communities healthy by keeping hospitals healthy. We recognize that healthcare requires a human touch, and we believe that every touch should be meaningful. This is why our people are the most important part of who we are. By empowering them to challenge the status quo, we know they will be the difference!
O.N.E Purpose:
- Customer Obsession: Consistently provide exceptional experiences for our clients, patients, and colleagues by understanding their needs and exceeding their expectations.
- Embracing New Ideas: Continuously innovate by embracing emerging technology and fostering a culture of creativity and experimentation.
- Striving for Excellence: Execute at a high level by demonstrating our “Best in KLAS” Ensemble Difference Principles and consistently delivering outstanding results.
The Opportunity:
The Cybersecurity Architect is responsible for designing, reviewing, and advancing security architecture across infrastructure, applications, cloud platforms, identity services, networks, and data environments. This hands-on technical role partners with engineering, infrastructure, product, and business teams to ensure security is integrated throughout the technology lifecycle. The Cybersecurity Architect develops threat models, conducts architecture and design reviews, and applies secure-by-design principles to support the organization's cybersecurity strategy.
This role translates business objectives and regulatory requirements, including HIPAA, HITRUST, and NIST Cybersecurity Framework requirements, into practical architectural solutions and security controls. The Cybersecurity Architect serves as a trusted advisor to technology teams, helping to ensure that solutions are secure, resilient, scalable, and aligned with organizational standards and regulatory obligations. The position reports to the Director of Cybersecurity and functions as an individual contributor.
Essential Job Functions:
- Design and review security architectures for cloud, infrastructure, application, identity, network, and data environments using secure-by-default principles and established security patterns.
- Develop and maintain threat models for assigned systems, identifying attack surfaces, security risks, and recommended mitigations.
- Participate in architecture and design reviews, providing security guidance and recommendations to project and engineering teams.
- Contribute to the cybersecurity architecture roadmap and evaluate emerging technologies to support future-state security initiatives.
- Serve as a subject matter expert on security architecture for engineering, infrastructure, and product teams.
- Promote and support zero-trust security principles, least-privilege access models, and defense-in-depth strategies across enterprise systems.
- Mentor engineers and technical teams on secure design practices and adherence to approved security standards and patterns.
- Translate regulatory and security framework requirements, including HIPAA, HITRUST, and NIST CSF, into technical architecture requirements and control mappings.
- Collaborate with Legal, Privacy, Compliance, and Governance, Risk, and Compliance (GRC) teams to ensure solutions meet internal policies and external regulatory requirements.
- Conduct risk assessments and develop architecture recommendations, remediation strategies, and mitigation plans for leadership review.
- Act as a liaison between cybersecurity, infrastructure, application development, and business stakeholders.
- Provide security architecture consultation for new technology initiatives, projects, and third-party vendor integrations.
- Support customer security reviews and third-party due diligence activities by articulating architecture decisions and validating security controls.
- Partner with cybersecurity analysts, engineers, and architects to ensure effective security controls are implemented across enterprise systems, cloud platforms, and applications.
Employment Qualifications:
- Bachelor's degree in Computer Science, Information Security, Information Technology, or a related field; or equivalent combination of education and relevant experience.
- 5 to 8 years of overall information security experience.
- Minimum of 2 years of experience in a cybersecurity or security architecture role.
- Experience designing and securing cloud, application, infrastructure, and data environments.(Role requirement inferred directly from documented responsibilities.)
- Experience conducting threat modeling, architectural reviews, and security risk assessments.
- Experience working within regulated environments and supporting compliance requirements such as HIPAA, HITRUST, and NIST CSF.
Preferred Certifications:
- One or more of the following certifications is preferred:
- CISSP (Certified Information Systems Security Professional)
- CCSP (Certified Cloud Security Professional)
- AWS Certified Security – Specialty
- Microsoft Azure Security Engineer Associate (AZ-500)
- Equivalent cloud security or architecture certification
Knowledge, Skills and Abilities:
- Security architecture design and review methodologies.
- Threat modeling, attack surface analysis, and risk assessment.
- Cloud security architecture across AWS and Azure environments.
- Secure application, infrastructure, network, identity, and data architecture principles.
- Zero Trust, least privilege, and defense-in-depth security strategies.
- Knowledge of HIPAA, HITRUST, NIST CSF, and healthcare security requirements.
- Strong communication and stakeholder management skills with the ability to translate technical security requirements into business-focused recommendations.
- Ability to influence engineering teams and mentor technical staff on secure design practices.
- Experience collaborating across cybersecurity, engineering, privacy, compliance, legal, and business organizations.
- Strong analytical, problem-solving, and decision-making capabilities.
- Must be inquisitive and demonstrate openness to innovation including AI to explore better processes and ways to alleviate friction and improve patient and client experiences.
- This is a remote position; however, candidates must be willing and able to travel to and work onsite at client, temporary, or corporate office locations as business needs require.
- This position pays between $163,700-$245,500 based on experience
This posting addresses s state specific requirements to provide pay transparency. Compensation decisions consider many job-related factors, including but not limited to geographic location; knowledge; skills; relevant experience; education; licensure; internal equity; time in position. A candidate entry rate of pay does not typically fall at the minimum or maximum of the role’s range.
#LI-LP1
#LI-Remote
Join an award-winning company
Five-time winner of “Best in KLAS” 2020-2022, 2024-2025
Black Book Research's Top Revenue Cycle Management Outsourcing Solution 2021-2024
22 Healthcare Financial Management Association (HFMA) MAP Awards for High Performance in Revenue Cycle 2019-2024
Leader in Everest Group's RCM Operations PEAK Matrix Assessment 2024
Clarivate Healthcare Business Insights (HBI) Revenue Cycle Awards for strong performance 2020, 2022-2023
Energage Top Workplaces USA 2022-2024
Fortune Media Best Workplaces in Healthcare 2024
Monster Top Workplace for Remote Work 2024
Great Place to Work certified 2023-2024
- Innovation
- Work-Life Flexibility
- Leadership
- Purpose + Values
Bottom line, we believe in empowering people and giving them the tools and resources needed to thrive. A few of those include:
- Associate Benefits – We offer a comprehensive benefits package designed to support the physical, emotional, and financial health of you and your family, including healthcare, time off, retirement, and well-being programs.
- Our Culture – Ensemble is a place where associates can do their best work and be their best selves. We put people first, last and always. Our culture is rooted in collaboration, growth, and innovation.
- Growth – We invest in your professional development. Each associate will earn a professional certification relevant to their field and can obtain tuition reimbursement.
- Recognition – We offer quarterly and annual incentive programs for all employees who go beyond and keep raising the bar for themselves and the company.
Ensemble is an equal employment opportunity employer. It is our policy not to discriminate against any applicant or employee based on race, color, sex, sexual orientation, gender, gender identity, religion, national origin, age, disability, military or veteran status, genetic information or any other basis protected by applicable federal, state, or local laws. Ensemble also prohibits harassment of applicants or employees based on any of these protected categories.
Ensemble provides reasonable accommodations to qualified individuals with disabilities in accordance with the Americans with Disabilities Act and applicable state and local law. If you require accommodation in the application process, please contact TA@ensemblehp.com.
This posting addresses state specific requirements to provide pay transparency. Compensation decisions consider many job-related factors, including but not limited to geographic location; knowledge; skills; relevant experience; education; licensure; internal equity; time in position. A candidate entry rate of pay does not typically fall at the minimum or maximum of the role’s range.
Employment Disclaimers – Ensemble
Similar roles
-
Cybersecurity Specialist (Secret Clearance Required)
SOLERITY Scott AFB, Illinois, United States · $90K–$95K/yr
-
ServiceNow IT Cybersecurity Specialist
Astor & Sanders Fort Lee, Virginia, United States · $130K–$160K/yr
-
Cybersecurity SME
Ignite IT Washington, District of Columbia, United States
-
Section Supervisor (Cybersecurity) - China Lake, CA
JT4 Ridgecrest, California, United States · $86K–$120K/yr
-
Cyber Security Engineer
Metova Federal Orlando, Florida, United States
-
Cybersecurity Analyst
USA DeBusk Houston, Texas, United States