Cyber Security Enterprise Architect
Indexed description
At Houston Methodist, the Cyber Security Enterprise Architect position is responsible for designing, implementing, and maintaining enterprise and system-level cybersecurity architectures that protect organizational systems, data, and infrastructure. This position translates complex business requirements, regulatory standards, and evolving threat landscapes into secure, scalable, and compliant technology solutions across the full system development lifecycle. The Cyber Security Enterprise Architect position partners with stakeholders across clinical, operational, and technology functions to align security strategies with organizational objectives, ensuring the confidentiality, integrity, and availability of critical systems. This position leads the evaluation of system architectures, conducts risk and threat assessments, and establishes security requirements that support resilient, high-performing, and compliant environments. Additionally, the Cyber Security Enterprise Architect position provides expert guidance on emerging technologies, cloud environments, multi-domain architectures, and secure system integrations. This position is accountable for embedding cybersecurity into acquisition, design, and operational processes while driving continuous improvement, innovation, and adherence to regulatory and industry standards.
FLSA STATUS
Exempt
QUALIFICATIONS
EDUCATION
- Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, Computer Engineering or related field
- Master's degree preferred
- Ten years of progressive experience in information security, cybersecurity architecture, or related IT disciplines, with increasing scope and responsibility
- CISSP - Certified Information Systems Security Professional (IISSCC) - International Information System Security Certification Consortium_PSV
- CISM - Certified Information Security Manager (ISACA) or
- CISA - Certified Information Systems Auditor (ISACA)
- Demonstrates the skills and competencies necessary to safely perform the assigned job, determined through ongoing skills, competency assessments, and performance evaluations
- Sufficient proficiency in speaking, reading, and writing the English language necessary to perform the essential functions of this job, especially with regard to activities impacting patient or employee safety or security
- Ability to effectively communicate with patients, physicians, family members and co-workers in a manner consistent with a customer service focus and application of positive language principles
- Knowledge of enterprise security architecture principles, frameworks, and design patterns, including the ability to develop and maintain secure architectures aligned with organizational goals
- Advanced knowledge of cybersecurity principles, including confidentiality, integrity, availability, authentication, and non-repudiation, and their application across enterprise systems
- Knowledge of cybersecurity risk management processes, regulatory requirements, and compliance frameworks (e.g., Risk Management Framework, HIPAA, PCI), including implications of security failures
- Knowledge of network architecture, protocols, and system integration concepts, including secure design of distributed and enterprise systems
- Knowledge of cloud computing service and deployment models (SaaS, IaaS, PaaS; public, private, hybrid) and their security implications across enterprise environments
- Knowledge of cryptographic principles, encryption standards, and identity and access management concepts, including Public Key Infrastructure and authentication mechanisms
- Knowledge of systems engineering processes, secure design methodologies, and integration techniques used to build resilient, scalable, and secure systems
- Skill in applying cybersecurity technologies and controls such as encryption, firewalls, network segmentation, and security models to protect enterprise environments
- Knowledge of data protection standards and information classification requirements, including protection of sensitive data such as PHI, PII, and PCI-regulated information
- Skill in applying analytical methods, system modeling, and design techniques to evaluate architectures, assess performance tradeoffs, and develop secure technical solutions
- Partners with business, clinical, and technology stakeholders to identify critical business functions and translate operational requirements into secure architecture designs and solutions.
- Provides expert cybersecurity guidance to project teams, leadership, and procurement functions regarding system design, risks, and security requirements.
- Translates cybersecurity, regulatory, and organizational requirements into secure system and application designs that support safe, reliable, and compliant operations.
- Ensures security architecture aligns with organizational standards and supports system performance, availability, and protection of sensitive data.
- Designs and integrates cybersecurity architectures for systems handling varying data classifications, ensuring appropriate protection of regulated and sensitive information.
- Provides consultative support to ensure solutions meet continuity of operations, disaster recovery, and system availability requirements.
- Conducts security architecture reviews to identify risks, vulnerabilities, and gaps, and develop mitigation strategies aligned with enterprise risk management practices.
- Defines, documents, and maintains system security requirements, controls, and compliance processes across the system lifecycle.
- Develops threat models and analyzes attack surfaces to proactively identify and mitigate cybersecurity risks.
- Defines and documents the security impact of new systems, integrations, and interfaces on the organization’s current security posture.
- Ensures systems and architectures comply with cybersecurity frameworks, regulatory requirements, and organizational security policies.
- Evaluates architecture solutions and recommends cost-effective security controls that balance risk, performance, and operational efficiency.
- Supports procurement and acquisition processes by ensuring security requirements are embedded in contracts and vendor solutions meet architectural standards.
- Designs and develops enterprise security architectures, including secure configuration management, system integration, and scalable design patterns.
- Analyzes and implements emerging technologies, cloud architectures, and enterprise frameworks to enhance scalability, innovation, and overall security posture.
- Uniform: No
- Scrubs: No
- Business professional: Yes
- Other (department approved): No
- Note that employees may be required to be on-call during emergencies (ie. Disaster, Severe Weather Events, etc) regardless of selection below.
- On Call* Yes
- Travel specifications may vary by department**
- May require travel within the Houston Metropolitan area Yes
- May require travel outside Houston Metropolitan area Yes
- Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, Computer Engineering or related field
- Master's degree preferred
- CISSP - Certified Information Systems Security Professional (IISSCC) - International Information System Security Certification Consortium_PSV
- CISM - Certified Information Security Manager (ISACA) or
- CISA - Certified Information Systems Auditor (ISACA)
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search