US Anesthesia Partners

Information Security Architect

Job ID 2026-19066
Function
Information Technology
Location
US-Remote
Employment Status
Full Time

Overview

USAP Logo

 

US Anesthesia Partners is the highest-quality single-specialty anesthesia practice in the United States, with over 6,000 employees distributed across 10 states. Our clinical and non-clinical staff support each other as they work toward a common vision: Forging a better future by empowering people to advance exceptional care. 

 

POSITION SUMMARY: The Information Security Architect is a functional, hands-on architect whose responsibility is to lead the governance and maturation of secure design, implementation and management for Enterprise applications and systems across all IT domains. This role partners closely with developers, DevOps, cloud infrastructure, networking, solution architects and security teams to embed security throughout the software development lifecycle (SDLC) while enabling rapid delivery of cloud-based solutions. 

 

The ideal candidate has deep expertise in cloud security architecture, application security, DevSecOps, threat modeling, and modern cloud platforms such as AWS and Azure.  This role also requires extensive knowledge and understanding of platform architecture, software development, well architected frameworks, and the ability to solve complex technical challenges. The Information Security Architect will serve as a trusted advisor to development teams, helping design resilient, scalable, and secure applications that meet business and regulatory requirements. 

Job Highlights

ESSENTIAL DUTIES AND RESPONSIBILITIES: (The ideal candidate must be able to complete all physical requirements of the job with or without a reasonable accommodation) Pineapple 

 

  • Establishes and enforces secure software development standards and cloud security best practices. 
  • Leads the security lifecycle by reviewing emerging technologies, threats, and trends as well as maturing end of life governance for applications and technologies. 
  • Participates in and matures the Architectural Review Board by applying a security focused mindset to all IT domains being reviewed. 
  • Reviews application architecture documentation including diagrams and runbooks with a security focused lens. 
  • Partners with engineering and DevOps teams to create security governance and best practice into CI/CD pipelines. 
  • Conducts architecture risk assessments, threat modeling, and secure design reviews for new and existing applications. 
  • Develops security reference architectures, design patterns, and technical standards for cloud-native applications. 
  • Leads application security initiatives including SAST, DAST, software composition analysis (SCA), Infrastructure as Code (IaC) scanning, container security, and API security. 
  • Works directly with the enterprise architect to ensure that overall enterprise security architecture, governance, and guidance is being executed on all IT domain levels. 
  • Evaluates cloud services and third-party technologies for security risks and compliance requirements. 
  • Collaborates with security operations, infrastructure, compliance, and engineering teams to investigate and resolve security findings. 
  • Acts as a trusted advisor to development, infrastructure, network, cloud, data, and security teams. 
  • Ensures cloud applications comply with organizational policies and applicable regulatory frameworks such as PCI DSS, HIPAA, SOC 2, ISO 27001, NIST, and GDPR. 
  • Provides technical leadership and mentorship to development teams on secure coding practices and cloud security. 
  • Performs other duties as assigned by management. 

Qualifications

KNOWLEDGE/SKILLS/ABILITIES (KSAs): 

 

  • Bachelor’s degree in computer science, business, or a related field required (or equivalent work experience). 
  • 7+ years of experience securing enterprise environments across on-premises, hybrid, and cloud infrastructures. 
  • Strong understanding of secure software development lifecycle (SSDLC) and DevSecOps practices. 
  • Strong knowledge of secure coding principles and common application vulnerabilities (OWASP Top 10, API Security Top 10). 
  • Solid knowledge and experience working with Azure Dev Ops technology with focus on CI/CD pipelines and GIT repositories. 
  • Strong knowledge of identity and access management, authentication, authorization, OAuth, OpenID Connect, SAML, risk management, and Zero Trust principles. 
  • Strong familiarity with SIEM, EDR/XDR, IAM, PAM, CASB, DLP, and vulnerability management platforms. 
  • Experience in healthcare is preferred. 
  • CISSP certification is preferred. 
  • Ability to understand and translate business needs, aligning them to proper technical application solutions. 
  • Ability to translate security policy, regulatory requirements, and risk findings into practical architecture guidance. 
  • Excellent communication and collaboration skills with the ability to work with multiple teams simultaneously. 
  • Excellent time management skills and ability to work on multiple business critical projects simultaneously. 
  • Understanding of core security and compliance principles in a healthcare environment. 
  • Strong analytical and problem-solving skills with the ability to solve complex technical problems. 

Options

<p style="margin: 0px;"><span style="font-size: 12pt;">Sorry the Share function is not working properly at this moment. Please refresh the page and try again later.</span></p>
Share on your newsfeed