Back to search
VA Boston Healthcare System Linkedin · Posted yesterday

Cyber Security Architect

Boston, Massachusetts, United States

Linkedin
Continue to application Add your email once, then Caio opens the original posting.

Indexed description

Cyber Security Architect


VA Boston Healthcare System

Boston, MA 02130


The role is based within the VA Boston Healthcare System, a leading biomedical research center that operates a high-performance computing (HPC) with petabyte-scale biomedical data on a multi-cloud and on-premises hybrid platform. The organization is seeking a senior Cybersecurity Architect & Engineer who designs, builds, and defends the organization’s hybrid computing infrastructure while structurally anchoring all technical controls within recognized cybersecurity compliance frameworks. This dual-focus role bridges high-level strategic architecture with hands-on engineering. The individual is responsible for adopting, implementing, and maintaining strict alignment with frameworks such as NIST (CSF, SP 800-53), ensuring a consistent, auditable, and hardened security posture across legacy on-premises data centers and multi-cloud environments


You will join a multidisciplinary team of clinicians, researchers, data scientists, and software engineers at a nationally recognized research Center. This role offers a unique opportunity to innovate, define, manage, maintain, and implement strong security measures for high‑impact.


PRIMARY DUTIES:

Framework Adoption, Governance & Compliance Maintenance

  • Lead the evaluation, adoption, and end-to-end implementation of security frameworks, specifically focusing on the NIST Cybersecurity Framework (CSF) and NIST SP 800-53
  • Translate complex compliance framework requirements into actionable, quantifiable technical controls across on-premises hardware and multi-cloud services
  • Establish continuous monitoring programs to maintain a constant state of compliance, producing necessary artifacts, system security plans (SSPs), and evidence for internal and external audits
  • Map technical architectures directly to regulatory requirements and framework controls to identify, track, and remediate compliance gaps via structured Plans of Action and Milestones (POA&Ms).

Hybrid & Multi-Cloud Architecture

  • Define governance, audit, and security strategy
  • Design and maintain secure, resilient blueprint architectures that unify legacy on-premises hardware, virtualized environments, and multi-cloud platforms in compliance with NIST standards
  • Perform comprehensive framework-aligned threat modeling on cross-environment integrations, evaluating risk patterns for data transitioning between on-premises infrastructure and cloud services
  • Establish and govern hybrid identity baselines, ensuring unified directory services, single sign-on (SSO), and privileged access management (PAM) across all environments.


Technical Security Engineering & Control Implementation

  • Define, design, build, and implement security architecture and security systems
  • Configure, optimize, and manage enterprise security tooling—including Next-Generation Firewalls (NGFW), Web Application Firewalls (WAF), and Zero Trust Network Access (ZTNA)—ensuring configurations match NIST baseline hardening guidelines
  • Build and maintain standardized Infrastructure as Code (IaC) templates to automate secure, compliant provisioning across multiple cloud providers and on-premises hypervisors
  • Manage enterprise cryptographic infrastructure, implementing NIST-approved encryption-at-rest, encryption-in-transit, and robust key management systems (KMS)
  • Design and fine-tune security telemetry pipelines to aggregate, correlate, and orchestrate log infrastructure into a centralized SIEM/SOAR platform to satisfy auditing requirements
  • Contribute to defining, designing, and implementing security policies and principles including system security, platform and infrastructure security, application security, user security, data security, data privacy, and data governance.


Vulnerability & Risk Management

  • Orchestrate unified vulnerability scanning and configuration assessment programs spanning on-premises bare-metal, virtual machines, and cloud-native assets
  • Serve as the tier-3 technical escalation point for security incidents, conducting advanced forensic log analysis across diverse cloud and on-premises infrastructure silos
  • Lead automated remediation initiatives to dynamically isolate compromised assets or adjust firewall rules during active security events based on incident response playbooks


MINIMUM QUALIFICATIONS:

  1. MUST be a US Citizen and MUST clear a US government background check
  2. Resume must indicate full-time or part-time and include hours for each position listed under work experience.

3. DEGREE: Bachelor's degree in computer science or higher, or bachelor's degree with 30 semester hours in a combination of mathematics, statistics, and computer science. At least 15 of the 30 semester hours must have included any combination of statistics and mathematics that included differential and integral calculus. All academic degrees and coursework must be from accredited or pre-accredited institutions.

4. EXPERIENCE: Experience must demonstrate progressively more complex computer scient work (systems design, architecture, research, etc.)


NOTE: Reference OPM website for more information on Qualification Standards: https://www.opm.gov/policy-data-oversight/classification-qualifications/general-schedule-qualification-standards/1500/computer-science-series-1550/


PREFERRED QUALIFICATIONS:

  • Framework Mastery: Deep, practical knowledge of adopting and scaling the NIST Cybersecurity Framework (CSF), NIST SP 800-53, or ISO 27001 within high-scale enterprise environments
  • Multi-Cloud Expertise: Proven experience architecting and securing native services across major cloud platforms (AWS, Azure)
  • On-Premises Infrastructure: Deep technical knowledge of enterprise data center technologies, including VMware/Hyper-V virtualization, Active Directory, and physical networking hardware.
  • Network & Automation Engineering: Expert-level understanding of core protocols (TCP/IP, BGP, DNS, TLS) and experience utilizing modern IaC tools to enforce automated security compliance policies
  • Exceptional ability to scale security policies consistently across modern cloud-native architectures and legacy on-premises systems while maintaining strict compliance
  • Strong systemic thinking to analyze, map, and secure complex distributed data flows against regulatory baselines
  • Excellent technical communication skills to translate abstract compliance mandates into concrete technical directives for engineering teams
  • Practical working knowledge of cybersecurity tools (Okta, Ping Identity, and other industry-leading tools)


NOTE: This posting is for candidate identification only. Resumes will be reviewed, and a shortlist may be interviewed. Any final recommendations for hire will be submitted to VA Human Resources for qualification review.

POINT OF CONTACT FOR POSITION:

Applicants should submit a cover letter, CV/resumes (must indicate full-time or part-time for each position listed under work experience and # of hours), and unofficial transcripts, including “CyberSecurity Architect” in the e-mail subject line, by Monday, August 31, 2026, to: [email protected]


Please confirm US citizenship in your cover letter.

EEO/Equal Opportunity Employer

Free. 20 seconds. No password. See every match in this search.

Create a free Caio profile to unlock more results and save your role and location preferences.

Unlock free search
Want help applying to roles like this? Search Caio for free. If repetitive applications get heavy, Managed Job Search adds supervised execution for $99/month.
View Managed Job Search