You Belong at Greenway
Bring your best and truest self. We celebrate what makes us different and what brings us all together. At Greenway Health, we are committed to an inclusive environment and a culture of belonging as we pursue our purpose of healthier communities, successful providers, and empowered patients. We are united in our goal to build the future of healthcare technology. Join us
The Cloud Security Architect will report directly to the Director, Cloud Security and is responsible for designing, implementing, and maintaining Greenway Health’s cloud security, application security, and Identity and Access Management Architectures. This will include working closely with the Product and Technology organization to identify and implement the needed security controls for our public and private cloud infrastructure. They will also be responsible for creating an enterprise Identity and access management architecture for Greenway associates, products, and services. Deep technical knowledge of DevSecOps and a good understanding of software development lifecycles are a must. In addition, deep technical knowledge of Identity management, which includes zero trust, FIDO 2, and other identity concepts, is required. The ideal candidate will have experience deploying solutions in a public cloud environment, a working knowledge of multiple programming languages, and a deep understanding of information security concepts. Experience with the HiTrust framework is a definite plus.
Essential Duties & Responsibilities
- Conduct cloud security planning to determine and describe security necessities
- Maintain knowledge of diverse cloud platforms
- Conduct infrastructure security planning, including firewalls, AppSec, IDS/IPS, SIEM, and scanners for detecting vulnerability
- Develop security criteria, procedures, and policies
- Establish and manage data access controls and provide identity, authentication, and access management design and oversight (IAM)
- Integrate cloud-aware authentication mechanisms
- Perform application vulnerability assessments and evaluations
- Provide guidance and oversight for the correction of discovered vulnerabilities
- Provide DevOps with security oversight and design guidance and oversee DevSecOps initiatives
- Perform security operations (SecOps) responsibilities
- Integrate security into the development lifecycle of software (SDLC)
- Monitor system activities, logs, and alerts
- Install and service security equipment
- Participate in the software development procedure
- Provide infrastructure support
- Provide guidance on systems hardening for cyber resilience
- Evaluate new security solutions and products
- Explore new threats, attack methods, and techniques
- Utilize security orchestration and response automation (SOAR)