hireejobsgulf

Architect - Security

1.00 to 10.00 Years   Qatar   23 Aug, 2022
Job LocationQatar
EducationNot Mentioned
SalaryNot Mentioned
IndustryOther Business Support Services
Functional AreaNot Mentioned

Job Description

JOB SUMMARY:The Architect ? Security establishes, monitors and maintains the overall Security Architecture within Sidra, as the roles primary function. The post holder reports into the Manager ? Architecture Services and is responsible for the design, review and ongoing improvement of secure, stable and available solutions to Sidra Medicine and its patients and partner organizations.The Architect sets and maintains the security standards for Sidra and measures compliance and improvement plans against these set standards. The incumbent is seen as a mentor and leader to the wider organization who is directly involved in the assessment, management and troubleshooting of all security related issues and solutions. S/he sets the strategic direction for security in relation to the overall ?IMT Urban Planning? at Sidra Medicine. S/he maintains a significant knowledge base and certification in Security Architecture, Healthcare IT, Risk Management, Governance and Disaster Recovery.The Architect works hand-in-glove with security governance, operational security and infra teams to ensure that Sidra is compliant to technical, legal and licensure requirements. S/he evaluates current and proposed solution architectures and sets the standard for the deployment, adoption and retirement of systems and operational processes. S/he keeps knowledge current and relevant to Sidra Medicine and maintains the security asset inventory within the Sidra Enterprise Architecture framework. The post holder reviews current security measures, recommends enhancements, identifies areas or weaknesses and oversees mediation and improvement plans put in place to address risks and issues identified.The Architect continuously evaluates security systems along with the Infrastructure Architect including (but not limited to) networking, VPN, routers, firewalls, intrusion detection, security appliances, storage, PKI, certificate auth., OS configuration and application design and configuration.The Architect works with the Data & Information Architect in the security and definition of Data, the corporate wide data security identification and classification, Information and Integration standards and patterns to ensure that they are secure, reliable and available. The incumbent, therefore, has a sound understanding of information models in Healthcare and experience in software development.The Architect works with application configuration and development teams, evaluates and responds to security risks and issues identified. The role holder requires sound understanding and experience of Cloud security for solutions that are hosted within the cloud in various different forms, strong emphasis on subjects such as the sovereignty of data and information privacy as Sidra Medicine is moving towards a model where cloud services are a critical part of the IT and Information ecosystem at Sidra Medicine.The Architect participates in the evaluation and subsequent implementation of solutions for their area of specialism. The work requires inputs to be provided from the relevant architectural and functional standard and for the post holder to review, recommend and resolve differences between solutions proposed and what can be accepted at Sidra Medicine. The incumbent facilitates and participates in regular compliance and audit processes to ensure that all solutions are compliant and/or the risks of the solution are known and acknowledged by the Sponsor. The post holder maintains a program to continuously evaluate, provide assurance and report on the effectiveness of the security controls within vendors? and services providers? environments.KEY ROLE ACCOUNTABILITIES:Planning and Design Activities:

  • Develops and maintains a security architecture process that enables the enterprise to develop and implement security solutions and capabilities that are clearly aligned with business, technology and threat drivers
  • Develops security strategy plans and roadmaps based on sound enterprise architecture practices
  • Develops and maintains security architecture artifacts (e.g., models, templates, standards and procedures) that can be used to leverage security capabilities in projects and operations
  • Develops and maintains IT solutions evaluation and validation framework (procedures, questionnaires, forms and templates) to cover IT solutions lifecycle (initial requirements definition and procurement, security accreditation criteria, deployment validation and post implementation review)
  • Determines baseline security configuration standards for operating systems (e.g., OS hardening), network segmentation and identity and access management (IAM)
  • Develops and maintains a program for data security identification, classification and impact assessment.
  • Develops standards and practices for data encryption and tokenization in the organization, based on the organizations data classification criteria
  • Drafts security procedures and standards to be reviewed and approved by executive management
  • Establishes a taxonomy of indicators of compromise (IOCs) and share this detail with other security colleagues, including the security operations center (SOC), information security managers and analysts, as well as counterparts within the network operations center (NOC)
Assurance:
  • Tracks developments and changes in the digital business and threat environments to ensure that theyre adequately addressed in security strategy plans and architecture artifacts
  • Validates IT infrastructure and other reference architectures for security best practices and recommend changes to enhance security and reduce risks, where applicable
  • Validates security configurations and access to security infrastructure tools, including firewalls, IPSs, WAFs and anti-malware/endpoint protection systems
  • Conducts or facilitate threat modeling of services and applications that tie to the risk and data associated with the service or application
  • Ensures a complete, accurate and valid inventory of all systems, infrastructure and applications that should be logged by the security information and event management (SIEM) or log management tool
  • Manages the vulnerability management program: works with specialized security vendors and the different IT teams to regularly perform Vulnerability Assessment and Penetration Testing (VAPT) exercises. Follow-up on timely mitigation as per the vulnerability management policies and procedures and regularly reports on compliance status.
  • Documents data flows of sensitive information in the organization (e.g., PII or ePHI), conducts security identification and classification exercises.
  • Recommends controls to ensure that this data is adequately secured (e.g., encryption and tokenization, data masking, data access controls)
  • Reviews network segmentation to ensure least privilege for network access
  • Supports the testing and validation of internal security controls, as directed by the executive management or the internal audit team
  • Formally regularly reviews and reports on vendors and services providers security controls environments.
  • Reviews security technologies, tools and services, and makes recommendations to the broader security team for their use, based on security, financial and operational metrics
Collaboration:
  • Liaises with the vendor management (VM) team to conduct security assessments of existing and prospective vendors, especially those with which the organization shares intellectual property (IP), as well as regulated or other protected data such as Software as a service (SaaS) providers, Cloud/infrastructure as a service (IaaS) providers, Managed service providers (MSPs) and Payroll providers
  • Evaluates the statements of work (SOWs) for these providers to ensure that adequate security protections are in place. Assesses the providers SSAE 16 SOC 1 and SOC 2 audit reports (or alternative sources) for security-related deficiencies and required user controls and report any findings to the executive management and vendor management teams
  • Coordinates with operational and facility management teams to assess the security of operational technology (OT) and Internet of Things (IoT) systems
  • Liaises with other security architects and security practitioners to share best practices and insights
  • Liaises with the business continuity management (BCM) team to validate security practices for BCM testing and operations when a failover occurs
  • Participates in application and infrastructure projects to provide security-planning advice
  • Liaises with the internal audit (IA) team to review and evaluate the design and operational effectiveness of security-related controls
  • Represent Sidra with regard to IMT Security and design with partner organizations such as HMC/PHCC, MoPH, and Supreme Committee for Delivery & Legacy, MOI.
  • Establishes and maintains strategic partnerships and security related programs of work between Sidra and external parties such as MOI, HMC, MoTC, and Microsoft.
  • Consults with program/project and operational teams to fit security solutions to architecture across all viewpoints
  • Adheres to Sidra?s standards as they appear in the Code of Conduct and Conflict of Interest policies
  • Adheres to and promotes Sidra?s Values
In view of the evolving needs and opportunities within Sidra, this position may be required to perform other duties as assigned and reporting relationships may vary.QUALIFICATIONS, EXPERIENCE AND SKILLS ? SELECTION CRITERIA:Education:ESSENTIALBachelors Degree in computer science, information systems, cybersecurity or a related field.PREFERRED
  • Masters Degree in computer science, information systems, cybersecurity or a related field.
  • In addition to essential criteria, certification in an Advanced IT or Data Science discipline relating to healthcare or medical research.
Experience:ESSENTIAL
  • 7+ years of experience inclusive of
  • Experience in IT, technology, Healthcare IT environment
  • Experience in IT management
  • Experience in IT Security and risk management
PREFERRED
  • 10 years plus experience in IT, technology, Healthcare IT environment
  • 5 years? experience in IT management
  • 10 years in IT Security and risk management
Certification and Licensure: ESSENTIALOne of the following:
  • Professional Cloud Solutions Architect Certification
  • Azure Security Engineer Associate
  • TOGAF 9 Certification
  • CompTIA Security+ certification
  • CISSP Certification
PREFERREDMore of the following:
  • Professional Cloud Solutions Architect Certification
  • Azure Security Engineer Associate
  • TOGAF 9 Certification
  • CompTIA Security+ certification
  • CISSP Certification
or any other equivalentJob Specific Skills and Abilities:
  • Direct, hands-on experience or strong working knowledge of managing security infrastructure ? e.g., firewalls, intrusion prevention systems (IPSs), web application firewalls (WAFs, endpoint protection, SIEM and log management technology.
  • Verifiable experience reviewing application code for security vulnerabilities.
  • Direct, hands-on experience or a strong working knowledge of vulnerability management tools.
  • Documented experience and a strong working knowledge of the methodologies to conduct threat-modeling exercises on new applications and services.
  • Working relationships with IMT business partners, clinical and administrative business teams.
  • Proven experience in Architecture and Innovation with a Healthcare IT environment
  • Experience in Information Security for a Medium to Large Enterprise
  • Excellent communication and interpersonal skills
  • Adaptive and agile thinker with good negotiation and conflict resolution skills.
  • Knowledge of business re-engineering principles and processes coupled with good design thinking to tackle ill-designed and tricky problems.
  • Additional training and certification in Cloud services, TOGAF, Project Management is desirable
  • Proficiency with Microsoft Office suite.
  • Fluency in written and spoken English.

Keyskills :

APPLY NOW

Related Jobs

© 2023 HireeJobsGulf All Rights Reserved