Cyber Security Enterprise Architect

Houston Methodist Hospital
  • Houston, TX
    19 days ago

    Job Description

    At Houston Methodist, the Cyber Security Enterprise Architect position is responsible for designing, implementing, and maintaining enterprise and system-level cybersecurity architectures that protect organizational systems, data, and infrastructure. This position translates complex business requirements, regulatory standards, and evolving threat landscapes into secure, scalable, and compliant technology solutions across the full system development lifecycle. The Cyber Security Enterprise Architect position partners with stakeholders across clinical, operational, and technology functions to align security strategies with organizational objectives, ensuring the confidentiality, integrity, and availability of critical systems. This position leads the evaluation of system architectures, conducts risk and threat assessments, and establishes security requirements that support resilient, high-performing, and compliant environments. Additionally, the Cyber Security Enterprise Architect position provides expert guidance on emerging technologies, cloud environments, multi-domain architectures, and secure system integrations. This position is accountable for embedding cybersecurity into acquisition, design, and operational processes while driving continuous improvement, innovation, and adherence to regulatory and industry standards.

    FLSA STATUS

    Exempt

    QUALIFICATIONS

    EDUCATION

    • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, Computer Engineering or related field
    • Master's degree preferred

    EXPERIENCE

    • Ten years of progressive experience in information security, cybersecurity architecture, or related IT disciplines, with increasing scope and responsibility

    LICENSES AND CERTIFICATIONS

    Required

    • CISSP - Certified Information Systems Security Professional (IISSCC) - International Information System Security Certification Consortium_PSV

    Preferred

    • CISM - Certified Information Security Manager (ISACA) or
    • CISA - Certified Information Systems Auditor (ISACA)

    KNOWLEDGE AND ABILITIES

    • Demonstrates the skills and competencies necessary to safely perform the assigned job, determined through ongoing skills, competency assessments, and performance evaluations
    • Sufficient proficiency in speaking, reading, and writing the English language necessary to perform the essential functions of this job, especially with regard to activities impacting patient or employee safety or security
    • Ability to effectively communicate with patients, physicians, family members and co-workers in a manner consistent with a customer service focus and application of positive language principles
    • Knowledge of enterprise security architecture principles, frameworks, and design patterns, including the ability to develop and maintain secure architectures aligned with organizational goals
    • Advanced knowledge of cybersecurity principles, including confidentiality, integrity, availability, authentication, and non-repudiation, and their application across enterprise systems
    • Knowledge of cybersecurity risk management processes, regulatory requirements, and compliance frameworks (e.g., Risk Management Framework, HIPAA, PCI), including implications of security failures
    • Knowledge of network architecture, protocols, and system integration concepts, including secure design of distributed and enterprise systems
    • Knowledge of cloud computing service and deployment models (SaaS, IaaS, PaaS; public, private, hybrid) and their security implications across enterprise environments
    • Knowledge of cryptographic principles, encryption standards, and identity and access management concepts, including Public Key Infrastructure and authentication mechanisms
    • Knowledge of systems engineering processes, secure design methodologies, and integration techniques used to build resilient, scalable, and secure systems
    • Skill in applying cybersecurity technologies and controls such as encryption, firewalls, network segmentation, and security models to protect enterprise environments
    • Knowledge of data protection standards and information classification requirements, including protection of sensitive data such as PHI, PII, and PCI-regulated information
    • Skill in applying analytical methods, system modeling, and design techniques to evaluate architectures, assess performance tradeoffs, and develop secure technical solutions

    ESSENTIAL FUNCTIONS

    PEOPLE ESSENTIAL FUNCTIONS

    • Partners with business, clinical, and technology stakeholders to identify critical business functions and translate operational requirements into secure architecture designs and solutions.
    • Provides expert cybersecurity guidance to project teams, leadership, and procurement functions regarding system design, risks, and security requirements.

    SERVICE ESSENTIAL FUNCTIONS

    • Translates cybersecurity, regulatory, and organizational requirements into secure system and application designs that support safe, reliable, and compliant operations.
    • Ensures security architecture aligns with organizational standards and supports system performance, availability, and protection of sensitive data.
    • Designs and integrates cybersecurity architectures for systems handling varying data classifications, ensuring appropriate protection of regulated and sensitive information.
    • Provides consultative support to ensure solutions meet continuity of operations, disaster recovery, and system availability requirements.

    QUALITY/SAFETY ESSENTIAL FUNCTIONS

    • Conducts security architecture reviews to identify risks, vulnerabilities, and gaps, and develop mitigation strategies aligned with enterprise risk management practices.
    • Defines, documents, and maintains system security requirements, controls, and compliance processes across the system lifecycle.
    • Develops threat models and analyzes attack surfaces to proactively identify and mitigate cybersecurity risks.
    • Defines and documents the security impact of new systems, integrations, and interfaces on the organization's current security posture.
    • Ensures systems and architectures comply with cybersecurity frameworks, regulatory requirements, and organizational security policies.

    FINANCE ESSENTIAL FUNCTIONS

    • Evaluates architecture solutions and recommends cost-effective security controls that balance risk, performance, and operational efficiency.
    • Supports procurement and acquisition processes by ensuring security requirements are embedded in contracts and vendor solutions meet architectural standards.

    GROWTH/INNOVATION ESSENTIAL FUNCTIONS

    • Designs and develops enterprise security architectures, including secure configuration management, system integration, and scalable design patterns.
    • Analyzes and implements emerging technologies, cloud architectures, and enterprise frameworks to enhance scalability, innovation, and overall security posture.

    SUPPLEMENTAL REQUIREMENTS

    WORK ATTIRE

    • Uniform: No
    • Scrubs: No
    • Business professional: Yes
    • Other (department approved): No

    ON-CALLNote that employees may be required to be on-call during emergencies (ie. Disaster, Severe Weather Events, etc) regardless of selection below.

    • On Call* Yes

    TRAVELTravel specifications may vary by department

    • May require travel within the Houston Metropolitan area Yes
    • May require travel outside Houston Metropolitan area Yes

    QUALIFICATIONS

    EDUCATION

    • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, Computer Engineering or related field
    • Master's degree preferred

    EXPERIENCE

    • Ten years of progressive experience in information security, cybersecurity architecture, or related IT disciplines, with increasing scope and responsibility

    LICENSES AND CERTIFICATIONS

    Required

    • CISSP - Certified Information Systems Security Professional (IISSCC) - International Information System Security Certification Consortium_PSV

    Preferred

    • CISM - Certified Information Security Manager (ISACA) or
    • CISA - Certified Information Systems Auditor (ISACA)

    Company Profile:

    Houston Methodist is one of the nation's leading health systems and academic medical centers. The health system consists of eight hospitals: Houston Methodist Hospital, its flagship academic hospital in the Texas Medical Center, seven community hospitals and one long-term acute care hospital throughout the Greater Houston metropolitan area. Houston Methodist also includes a research institute; a comprehensive residency program; international patient services; freestanding comprehensive care clinics, emergency care and imaging centers; and outpatient facilities. Come lead with us!

    Houston Methodist is an Equal Opportunity Employer.

    Numbers & Facts

    LocationHouston, TX

    Skills

    • Acute Careunmatched
    • Analysis Skillsunmatched
    • Architectural Analysisunmatched
    • Architectural Servicesunmatched
    • Authenticationunmatched
    • Business Continuity Planning (BCP)unmatched
    • Business Strategyunmatched
    • CISA - Certified Information Systems Auditorunmatched
    • CISM - Certified Information Security Managerunmatched
    • CISSP - Certified Information Systems Security Professionalunmatched
    • Cloud Architectureunmatched
    • Cloud Computingunmatched
    • Communication Skillsunmatched
    • Computer Engineeringunmatched
    • Computer Scienceunmatched
    • Computer Securityunmatched
    • Computer Servicesunmatched
    • Configuration Managementunmatched
    • Continuous Improvementunmatched
    • Cryptographyunmatched
    • Customer Service Softwareunmatched
    • Design Patterns Programming Methodologiesunmatched
    • Disaster Recoveryunmatched
    • Distributed Computingunmatched
    • Documentationunmatched
    • Embedded Systemsunmatched
    • Emergency Careunmatched
    • Emerging Technologyunmatched
    • English Languageunmatched
    • Enterprise Architectureunmatched
    • Enterprise Protectionunmatched
    • Financeunmatched
    • Firewallsunmatched
    • HIPAA (Health Insurance Portability and Accountability Act)unmatched
    • Hospitalunmatched
    • Hospital Systemsunmatched
    • ISACA (Information Systems Audit and Control Association)unmatched
    • Identity Data Managementunmatched
    • Industry Standardsunmatched
    • Information Technology & Information Systemsunmatched
    • Information/Data Security (InfoSec)unmatched
    • Infrastructure as a Service (IaaS)unmatched
    • International Information Systems Security Certification Consortium (ISC)2unmatched
    • Internet Securityunmatched
    • Leadershipunmatched
    • Long-Term Careunmatched
    • Network Architecture/Engineeringunmatched
    • Network Protocolsunmatched
    • Network Securityunmatched
    • Operations Processesunmatched
    • Outpatient Careunmatched
    • PCIunmatched
    • Patient Careunmatched
    • Patient Safetyunmatched
    • Performance Analysisunmatched
    • Performance Reviewsunmatched
    • Platform as a Service (PaaS)unmatched
    • Problem Solving Skillsunmatched
    • Process Improvementunmatched
    • Public Key Infrastructure (PKI)unmatched
    • Purchasing/Procurementunmatched
    • Regulationsunmatched
    • Regulatory Complianceunmatched
    • Regulatory Requirementsunmatched
    • Risk Analysisunmatched
    • Risk Managementunmatched
    • Risk Management Framework (RMF)unmatched
    • Safety/Work Safetyunmatched
    • Scalable System Developmentunmatched
    • Security Architectureunmatched
    • Software Designunmatched
    • Software Development Lifecycle (SDLC)unmatched
    • Software as a Service (SaaS)unmatched
    • Strategic Planningunmatched
    • System Architectureunmatched
    • System Integration (SI)unmatched
    • System Lifecycleunmatched
    • Systems Administration/Managementunmatched
    • Systems Engineeringunmatched
    • Systems Maintenanceunmatched
    • Systems Scalabilityunmatched
    • Threat Modelingunmatched
    • Threat and risk analysis (TRA)unmatched
    • Trade-Off Analysisunmatched
    • Willing to Travelunmatched

    Be found by employers

    5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

    Level up your application

    Professional resume templates

    Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

    Free resume templates

    Free resume builder

    Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

    Free resume builder