‹ Back
WWAYPOINT

IS Principal Security Architect

Support StaffFull timeDays
iPosting details
ScheduleDays · Full time
EducationBachelor's degree · Master's degree preferred
Experience10+ years
SourceBrown University Health · posted Aug 10, 2026
✓Requirements
Certifications
✓A minimum of 3 active security certifications are required at the time of hire or must be obtained within 6 months of employment, with emphasis on architecture, cloud, and security engineering disciplines, including certifications such as CISSP, CCSP, GIAC (e.g., GCSA, GCLD, GCAD, GCPN, GPCS, GCTD),
✓Experience implementing and supporting phishing-resistant MFA (e.g., FIDO2/WebAuthn, smart cards, certificate-based authentication).
Education
✓A bachelor’s degree in information systems (or equivalent experience)
MBA or MS in Information Security preferred.
Qualifications
✓A minimum of 10 years of IS/IT experience, including 5+ years in information security architecture, engineering, or related senior technical security roles.
✓Demonstrated ability to operate as a senior technical leader across multiple security domains, balancing enterprise architecture, cloud security, identity security, AI governance, and data protection requirements.
✓Demonstrated experience designing and governing security architecture for hybrid (on-premises and cloud) and multi-cloud environments, including segmentation, secure connectivity (VPN, ExpressRoute, Direct Connect equivalents), DNS/routing, egress controls, and cloud governance models (landing zones
✓Demonstrated experience securing Azure and AWS environments across multiple subscriptions/accounts, including identity, networking, storage, monitoring, and secure landing zone architecture.
✓Strong technical knowledge of security methodologies, platform hardening, and enterprise security controls across Windows/Linux systems, endpoints, cloud platforms, and enterprise infrastructure.
✓Strong knowledge of identity and access management, including federation and authentication protocols (SAML, OAuth2, OpenID Connect), Conditional Access, RBAC, privileged access management, and application identity governance.
✓Strong knowledge of encryption and key management, including PKI concepts, secrets management, and KMS/Key Vault.
✓Experience with automation and integration concepts, including scripting (Python, PowerShell, Bash), cloud CLIs/SDKs, and API/webhook integrations supporting security workflows, telemetry, orchestration, and validation activities.
✓Experience integrating security controls and governance requirements into infrastructure-as-code (e.g., Terraform, Ansible) and CI/CD workflows.
✓Experience with SIEM and monitoring platforms supporting enterprise logging, telemetry, alerting, and security visibility requirements; familiarity with SOAR and automated response capabilities is preferred.
✓Knowledge of vulnerability management processes and tools (e.g., Qualys, Nessus, Rapid7), ensuring architecture and control design support effective risk-based prioritization and remediation governance.
✓Experience with CSPM/CWPP solutions to identify misconfigurations, vulnerabilities, and risks across multi-cloud environments.
✓Strong understanding of network security architecture, including segmentation, firewalls, routing, switching, DNS, private networking, and packet analysis concepts.
✓Strong understanding of regulatory requirements, security frameworks, and risk methodologies (e.g., HIPAA/HITECH, NIST, ISO 27001), including the ability to translate requirements into technical controls, governance standards, and audit evidence.
✓Proven ability to perform risk, control, vulnerability, and business impact assessments, and translate findings into actionable remediation plans.
✓Excellent interpersonal, verbal, and written communication skills with the ability to develop standards, architectural diagrams, technical documentation, and executive-level reporting, and communicate security decisions to both technical and non-technical stakeholders.
✓Motivated self-starter with a track record of taking ownership of security challenges and driving them to resolution.
+Brown University Health
10support roles open
Pay for this position
Employer-posted
$128k – $211k/yr
Apply to Brown University HealthContact Recruiter about this role
✓You’ll need
Certifications
✓A minimum of 3 active security certifications are required at the time of hire or must be obtained within 6 months of employment, with emphasis on architecture, cloud, and security engineering disciplines, including certifications such as CISSP, CCSP, GIAC (e.g., GCSA, GCLD, GCAD, GCPN, GPCS, GCTD),
✓Experience implementing and supporting phishing-resistant MFA (e.g., FIDO2/WebAuthn, smart cards, certificate-based authentication).
Education
✓A bachelor’s degree in information systems (or equivalent experience)
MBA or MS in Information Security preferred.
Qualifications
✓A minimum of 10 years of IS/IT experience, including 5+ years in information security architecture, engineering, or related senior technical security roles.
✓Demonstrated ability to operate as a senior technical leader across multiple security domains, balancing enterprise architecture, cloud security, identity security, AI governance, and data protection requirements.
✓Demonstrated experience designing and governing security architecture for hybrid (on-premises and cloud) and multi-cloud environments, including segmentation, secure connectivity (VPN, ExpressRoute, Direct Connect equivalents), DNS/routing, egress controls, and cloud governance models (landing zones
✓Demonstrated experience securing Azure and AWS environments across multiple subscriptions/accounts, including identity, networking, storage, monitoring, and secure landing zone architecture.
✓Strong technical knowledge of security methodologies, platform hardening, and enterprise security controls across Windows/Linux systems, endpoints, cloud platforms, and enterprise infrastructure.
✓Strong knowledge of identity and access management, including federation and authentication protocols (SAML, OAuth2, OpenID Connect), Conditional Access, RBAC, privileged access management, and application identity governance.
✓Strong knowledge of encryption and key management, including PKI concepts, secrets management, and KMS/Key Vault.
✓Experience with automation and integration concepts, including scripting (Python, PowerShell, Bash), cloud CLIs/SDKs, and API/webhook integrations supporting security workflows, telemetry, orchestration, and validation activities.
✓Experience integrating security controls and governance requirements into infrastructure-as-code (e.g., Terraform, Ansible) and CI/CD workflows.
✓Experience with SIEM and monitoring platforms supporting enterprise logging, telemetry, alerting, and security visibility requirements; familiarity with SOAR and automated response capabilities is preferred.
✓Knowledge of vulnerability management processes and tools (e.g., Qualys, Nessus, Rapid7), ensuring architecture and control design support effective risk-based prioritization and remediation governance.
✓Experience with CSPM/CWPP solutions to identify misconfigurations, vulnerabilities, and risks across multi-cloud environments.
✓Strong understanding of network security architecture, including segmentation, firewalls, routing, switching, DNS, private networking, and packet analysis concepts.
✓Strong understanding of regulatory requirements, security frameworks, and risk methodologies (e.g., HIPAA/HITECH, NIST, ISO 27001), including the ability to translate requirements into technical controls, governance standards, and audit evidence.
✓Proven ability to perform risk, control, vulnerability, and business impact assessments, and translate findings into actionable remediation plans.
✓Excellent interpersonal, verbal, and written communication skills with the ability to develop standards, architectural diagrams, technical documentation, and executive-level reporting, and communicate security decisions to both technical and non-technical stakeholders.
✓Motivated self-starter with a track record of taking ownership of security challenges and driving them to resolution.

More support jobs in Rhode IslandMore support jobs nearby

All 151 in Rhode Island →All 151 →

Highest-paying support roles in Rhode Island

Employer-posted ranges only
All RI support jobs →
Want the next support job in Rhode Island by email?
Weekly, free, unsubscribe with one click.

About the role