Program Security Architect

Marchon Partners
  • Boston, MA
  • Instant Apply
2 days ago

Job Description

Duration: 18 months contract
Hours per week:  37.5-40 hours per week
Location:  Hybrid onsite one day per week in Downtown Boston, MA

Marchon's client is hiring a Security Architect to support the adoption of the future state end user security solution and protocols.  As a key member of the project’s Security Team, the Risk and Compliance Lead will work closely with other team members to develop and implement a comprehensive information security program. This includes:
  • Design and recommend protocols and procedures for monitoring the product vendor’s performance against Service Level Agreement standards regarding data security, annual security audits, and disaster recovery testing.
  • Collect documentation and other artifacts as the project develops to support comprehensive IT and other statewide audits, which will require documentation of conversion between systems, validation of data, operations and other content and support data reliability.
  • Propose security policies, processes and standards related to end- user roles, data access for application users, and how users will be provisioned and de-provisioned.
  • Provide input on selection, deployment, and oversight of security technologies and other compliance and risk management/mitigation strategies.


The Risk and Compliance Lead will participate in recommending strategies for:
  • Monitoring compliance with vendor and Commonwealth IT security policies and applicable laws.
  • Defining procedures for investigating and reporting security incidents.
  • Contribute in developing, testing, and documenting security procedures, including disaster recovery, business continuity, backups, and incident response.
  • Monitoring and assessing business continuity and disaster recovery programs, network penetration, and other tests to assess application vulnerability; and
  • Participate in risk and compliance assessment reviews of the new Human Resource and Payroll solution and supporting services and infrastructure.
  • Support of coordinated operational change management strategy to ensure a successful implementation of training materials, training resources and training opportunities to support compliance with HR Payroll policies and guidance and successful system change management for users.


This role involves collaborating with program functional teams to identify end-user roles and permissions for implementing the new Human Resource and Payroll solution across all agencies and user types, ensuring appropriate data access. User security procedures will be developed in conjunction with theTechnical Lead, Comptroller Risk Management Team, the system integration and product vendor, and agency staff responsible for user provisioning and deprovisioning.

Required Skills
  • Bachelor's degree in computer science, system analysis or a related study, or equivalent experience in the field of audit compliance and security risk and compliance management.
  • Minimum of nine years of design and implementation experience in IT, with a deep knowledge in a minimum of two of the following technical disciplines: infrastructure and network design, application development, application programming interfaces (APIs), middleware, servers and storage, database management, data security, and system administration and operations
  • Experience in generation of Security materials, including but not limited to compliance adherence, security operational procedures, security implementation plans, and network and security diagrams.
  • Minimum of five years of security architecting design and implementation with security certifications, such as: SIA Security +
  • In-depth knowledge and understanding of information risk concepts and principles as a means of relating business needs to security controls.
  • Knowledge of and experience in developing and documenting security architecture and plans, including strategic, tactical and project plans.
  • Documented experience with common information security management frameworks, such as International Organization for Standardization (ISO) 2700x and the ITIL, SOX, COBIT and National Institute of Standards and Technology (NIST) frameworks.
  • Experience in architecting and implementing cloud-based security solutions.
  • Extensive knowledge of security tools and capabilities, such as: IDM and SSO.
  • Extensive experience in integrating security tools and 3rd party vendor solutions.
  • Exceptional planning, organization, communication, prioritization, and business analysis skills.
  • In-depth knowledge of risk assessment methods and technologies.
  • Proficiency in performing risk, business impact, control, and vulnerability assessments.
  • Excellent technical knowledge of mainstream operating systems and a wide range of security technologies, such as network security appliances, identity, and access management (IAM) systems, anti-malware solutions, privilege access management (PAM), data loss prevention (DLP), encryption at-rest and in-transit, multi-factor authentication (MFA), end-point-security, vulnerability scanning and patch management, automated policy compliance tools, and desktop security tools.
  • Experience in developing, documenting, and maintaining security policies, processes, procedures, and standards.
  • Knowledge of network infrastructure, including routers, switches, firewalls, and the associated network protocols and concepts.
  • Strong analytical skills to analyze security requirements and relate them to appropriate security controls.
  • Documented written and verbal communication skills.
  • Experience working with modern issue tracking systems (JIRA)
  • Ability to interact with personnel at all levels and across all business units and organizations, and to comprehend business imperatives.


Preferred Qualifications
  • Extensive experience with Human Resource and Payroll systems security requirements.
  • Experience with AI security
  • Experience with implementation of AI tools within a government agency
  • Experience with WorkDay Human Resource and Payroll solution, with an additional preference of implementation within a government agency.
  • Experience with WorkDay Prism data and reporting solution.
  • Experience with WorkDay user security management as a member of a business (non-IT) team.
  • Experience in transitioning traditional IT security functions to business teams.
  • Extensive experience with Software-as-a-Service cloud implementations particularly those in which legacy on premise applications have been migrated to cloud delivery options.
  • Experience operating end user security protocols, policies in an enterprise environment.
  • Experience at implementing technical configurations, technologies, and processing environments in an enterprise environment.
  • Experience with Audit, compliance, or governance actions.
  • Experience with Microsoft security tools and functions
  • Experience with Snowflake security functions

Numbers & Facts

LocationBoston, MA

Skills

  • Analysis Skillsunmatched
  • Application Programming Interface (API)unmatched
  • Applications Securityunmatched
  • Artificial Intelligence (AI)unmatched
  • Atlassian JIRAunmatched
  • Authenticationunmatched
  • Business Analysisunmatched
  • Change Managementunmatched
  • Cloud Architectureunmatched
  • Cloud Computingunmatched
  • Communication Skillsunmatched
  • CompTIA Security+unmatched
  • Computer Scienceunmatched
  • Computer Securityunmatched
  • Control Objectives for Information and related Technology (COBIT)unmatched
  • Cryptographyunmatched
  • Data Qualityunmatched
  • Database Administrationunmatched
  • Desktop PCunmatched
  • Disaster Recoveryunmatched
  • Documentationunmatched
  • Endpoint Securityunmatched
  • Establish Prioritiesunmatched
  • Firewallsunmatched
  • Functional Programming Languagesunmatched
  • Governmentunmatched
  • Human Resourcesunmatched
  • ISO (International Organization for Standardization)unmatched
  • ITIL (IT Infrastructure Library)unmatched
  • Identity Data Managementunmatched
  • Incident Responseunmatched
  • Information/Data Security (InfoSec)unmatched
  • Loss Preventionunmatched
  • Maintain Complianceunmatched
  • Malwareunmatched
  • Management Strategyunmatched
  • Microsoft Product Familyunmatched
  • Middlewareunmatched
  • Network Administration/Managementunmatched
  • Network Designunmatched
  • Network Programmingunmatched
  • Network Protocolsunmatched
  • Network Routersunmatched
  • Network Securityunmatched
  • Network Switchingunmatched
  • Operating Systemsunmatched
  • Operational Strategyunmatched
  • Operational Supportunmatched
  • Operations Managementunmatched
  • Operations Processesunmatched
  • Operations Security (OPSEC)unmatched
  • Payroll Software/Servicesunmatched
  • Penetration Testingunmatched
  • Presentation/Verbal Skillsunmatched
  • Prismunmatched
  • Project Planningunmatched
  • Protocol Designunmatched
  • Requirements Managementunmatched
  • Riskunmatched
  • Risk Analysisunmatched
  • Risk Managementunmatched
  • Sarbanes-Oxley Act (SOX)unmatched
  • Security Analysisunmatched
  • Security Architectureunmatched
  • Security Auditingunmatched
  • Security Complianceunmatched
  • Security Designunmatched
  • Security Information and Event Management (SIEM)unmatched
  • Security Monitoringunmatched
  • Security Protocolsunmatched
  • Service Level Agreement (SLA)unmatched
  • Single Sign-On (SSO)unmatched
  • Software Developmentunmatched
  • Software Patchesunmatched
  • Software as a Service (SaaS)unmatched
  • Strategic Planningunmatched
  • System Integration (SI)unmatched
  • System Operationsunmatched
  • System Validationunmatched
  • Systems Administration/Managementunmatched
  • Systems Analysisunmatched
  • Team Playerunmatched
  • Technical Supportunmatched
  • Test Plan/Scheduleunmatched
  • U.S. National Institute of Standards and Technology (NIST)unmatched
  • Vendor/Supplier Evaluationunmatched
  • Vulnerability Scannersunmatched
  • Writing Skillsunmatched

Be found by employers

5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

Level up your application

Professional resume templates

Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

Free resume templates

Free resume builder

Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

Free resume builder