Job Description :
Security Architect – (IDENTITY & ACCESS MANAGEMENT Lead)

The Information Security Architect will report to the Office of Information Assurance and operate as an experienced consultant to SCDHHS leadership, business units, business partners and vendors.


Assist in the design, development, implementation and/or ongoing maturation of SCDHHS
security and compliance solutions
Provide hands-on support of SCDHHS Systems and Software
Participate in audit and assessment of internal agency systems as well as business
partner/service provider information systems.
Utilize Microsoft Office software suite, eGRC system, Bizagi, Atlassian and other
products to document and report on information gathered during Audit and Assessment
activities or other OIA efforts.
Participate in third-party audits and/or assessments of agency and business partner systems
Collaborate with agency leadership, business partners and other parties/stakeholders
to provide recommendations for security and compliance risk mitigation efforts
Security Program Experience:
Experience with CMS MARS-E or other FISMA Risk Management Framework (RMF)
compliant programs is strongly desired and will be given the highest weight.
Experience should include well documented success in the performance of security
focused processes and procedures supportive of a secure, compliant enterprise architecture.
Experience with development and integration of RMF tasks and artifacts into the System
Development Life Cycle (SDLC) is ideal.
Experience in security as related to multi-tenant, cloud services and vendor interface
management would be considered desirable for this position.
IBM System 390/zSeries
Linux and Windows servers
Network Firewalls, Intrusion Prevention Systems (IPS), Switching and Routing Infrastructure
Security Information and Event Management (SIEM) solutions
Identity and Access Management (IAM) solutions

Required Skills

Must have a strong working knowledge of FISMA, NIST, CMS MARS-E and HIPAA Security
and Privacy.
Must have deep technical knowledge of secure systems architecture principles,
security and compliance tools, data protection and access models.
5+ years of experience in I.T. working with and/or auditing IBM System 390/zSeries,
Windows, Linux, networking infrastructure and web-based applications.
ISC(2), ISACA, SANS GIAC and/or other Information Security Certification is
Ability to work independently and as a member of a team.
Ability to collaborate and coordinate with multiple teams and vendors.
Ability to multitask and prioritize tasks effectively in order to meet deadlines.
Experience and training with eGRC solutions.
Ability to engage diverse audiences of varying technical and non-technical skill-levels to
sure effective alignment of technical requirements to business objectives.
Ability to collaborate and coordinate efforts amongst multiple teams and vendors in
fulfillment of SCDHHS OIA initiatives
Ability to multitask and prioritize tasks effectively in order to meet deadlines in a results-
oriented environment.
Must have intermediate to advanced skills in Microsoft Office products (Word, Excel,
PowerPoint, Visio) to include working with templates and style guidelines for branding
Keen attention to detail while maintaining the ability to see the big picture.
Ability to absorb, retain and communicate complex processes.
Ability to accept changes and constructive criticism and remain flexible in dealing with
leadership and teams of varying technical and business knowledge.

Preferred Skills

Prior experience working within a FISMA compliant program.
Prior experience in working with any eGRC systems.
Prior Health Information Technology experience

Required Education/Certifications

ISC(2), ISACA, SANS GIAC and/or other Information Security Certification Or Similar with valid experience

Preferred Education/Certifications

BS degree in computer science or similar discipline