Remote Staff Engineer, Security Architect

at Bellese

Posted 2 days ago 1 applied

Description:

  • The Staff Engineer, Security Architect will implement and maintain an effective information security program for the organization within the context of the Hospital Quality Reporting (HQR) contract.
  • This role includes maintaining the HQR Authority to Operate (ATO) and ensuring the security of the HQR system, which is utilized by the Center for Medicare and Medicaid Services (CMS).
  • The position may provide support across multiple contracts and contribute to business development and growth initiatives at Bellese.
  • Responsibilities include protecting the confidentiality, integrity, and availability of the organization's information assets by identifying and managing risks, developing and implementing policies and procedures, conducting security assessments, and ensuring compliance with relevant laws and regulations.
  • The Staff Engineer, Security Architect will support cross-functional development teams in design & architecture, application security, infrastructure & operability, and testing & quality assurance.
  • This position aims to enhance the organization's overall security posture while fostering collaboration with diverse teams and stakeholders.

Requirements:

  • A Bachelor's or Master's degree in Computer Science, Information Security, or a related field is required.
  • Candidates must possess CISSP, CISM, or other relevant security certifications.
  • A minimum of 7 years of experience in information security is required, with at least 5 years in a leadership role preferred.
  • In-depth knowledge of CMS security requirements, FISMA, NIST security frameworks, and other applicable regulations is essential.
  • Candidates should have in-depth knowledge and experience using the CMS CFACTS tool.
  • Strong experience delivering AWS-based cloud solutions is required, including familiarity with various AWS services such as EC2, ECS, Lambda, and more.
  • Proficiency in programming languages and frameworks such as Java, Spring Boot, Python, Go, JS/TS, and Angular is necessary.
  • Experience with DevSecOps technologies like Terraform, Jenkins, Git/Github, and others is required.
  • Strong knowledge of information security principles, technologies, and best practices is essential.
  • Excellent communication, interpersonal, and leadership skills are required, along with strong analytical, problem-solving, and decision-making abilities.

Benefits:

  • The compensation range for this role is $150,000 to $182,400 USD per year.
  • The position offers opportunities for professional growth and development through mentorship and guidance.
  • Employees will have the chance to participate in industry conferences and forums to stay current on the latest trends and technologies in information security.
  • The role promotes a culture of security consciousness and innovation within the organization.