BEST Program Security Architect
Volantsoft Inc
Full-time, Monday–Friday, 7.5-hour days
Location: Boston, MA — Hybrid (minimum 4 business days/month on-site; must be able to report on-site with little or no notice; reasonable proximity required; no travel reimbursement)
SPECIFIC DUTIES
- Oversee implementation of the three major security components: Infrastructure (hosting) security, Application Security, and User Authentication security.
- Align with BEST project team, vendor, SI, EOTSS security, and Comptroller Risk Management Team, including:
- Partner with EOTSS to onboard Workday and Workday Prism to work with the Commonwealth Single Sign-On (SSO) for employees and vendors as appropriate; for departments, employees, and contractors with limitations on the standard EOTSS SSO solution, assess options and recommend how these individuals will be managed and properly secured.
- Assist in the remediation of department user data as necessary in support of the CTR Risk and Compliance Unit.
- Oversee security SLAs with the vendor(s) to ensure appropriate security reports are created, and create a process for review to ensure SLAs are monitored by the Commonwealth.
- Work with EOTSS on security and compliance testing/documentation and review/remediate results/issues as necessary, in collaboration with the Comptroller Risk Management team.
- Work with BEST technical leadership to develop strategies, procedures and recommended roles and responsibilities to enforce security requirements and address identified risks related to the use of the new solution and suitability of underlying internal controls and technologies.
- Provide recommendations regarding end user security roles and groups, data access controls and security role provisioning (onboarding) and de-provisioning (offboarding) protocols, in cooperation with the Comptroller Risk Management Team.
- Participate in disaster recovery, business continuity, backup, and operational planning; support DR/business continuity testing and documentation.
- Oversee establishment of the overall Security Incident Event Management (SIEM) across several security operational domains including Cloud SaaS vendor, Comptroller's office, and EOTSS.
- Support the identification, assessment, documentation, prioritization, mitigation, monitoring, and escalation of program risks.
- Support the program risk register and ensure risks have clearly identified owners, mitigation actions, target dates, and escalation paths.
- Oversee integration configuration and testing of EOTSS Single Sign-On (SSO), EOTSS Identity Access Management (IAM), EOTSS Multi-Factor Authentication (MFA), Cloud SaaS vendor user access management, and Workday access controls and provisioning processes, in cooperation with Comptroller Risk Management Team.
- Implement agreed mitigations and solutions to address business and technology vulnerabilities.
- Document and implement technical controls, processes and procedures related to data security in conjunction with the BEST Phase 2 Technical Lead, Assistant Comptroller for Statewide Risk Management and Compliance, and EOTSS.
- Assist security administrators and IT staff in the resolution of reported security incidents; act as liaison between incident response leads and subject matter experts; monitor daily or weekly reports and security logs for unusual events.
- Translate Comptroller, Commonwealth, and EOTSS policies into BEST program implementation actions, solutions, and processes, as well as on-going operational processes, in cooperation with the Comptroller Risk Management Team and CTR Payroll Teams.
- Assist in identifying security requirements using methods that may include risk and business impact assessments, including review of SLA requirements, Commonwealth IT policies related to data security, and Commonwealth Risk Management Office policies, assessments, and recommendations.
- Conduct additional business system analysis as needed; design future state security solution supporting data, application, and environment security needs across multiple stakeholders.
- Identify business and technology security vulnerabilities and make recommendations to program leadership and stakeholders.
- Assess compliance with risk and cybersecurity frameworks and standards such as NIST, ISO, COSO, PCI, FERPA, and GLBA, with the BEST Phase 2 Technical Lead and Comptroller Risk Management Team.
- Assist in the coordination and completion of information security operations documentation.
- Play an advisory role in application development and implementation to assess security requirements and controls and assure security issues are addressed throughout the project life cycle.
- Support the Program and the BEST Phase 2 Technical Lead to identify approved end users of the new solution and coordinate provisioning of users for Day One go live; drive end-to-end testing of the go-live security solution.
- Provide advice to security administrators on normal and exception-based processing of security authorization requests, including the use of SI or product vendor tools that monitor system use and data access irregularities.
- Research, evaluate and recommend information-security-related hardware and software, including developing business cases for security investments.
- Analyze results of SI/product vendor audits or third-party audits to produce recommendations on acceptable risks and risk mitigation strategies; provide recommendations on audit finding remediation, feedback on managerial responses, tracking progress and status updates to the BEST Team.
- Provide ongoing advice and support to Security Operations and IT for incident response, indicators of compromise (IOCs), vendor security vulnerability notifications, law enforcement security alerts, etc.
- Maintain awareness of existing and proposed security-standard-setting groups, state and federal legislation and regulations pertaining to information security; identify regulatory changes affecting information security policy, standards, and procedures, and recommend changes.
- Research and assess new threats and security alerts and recommend remedial actions.
- Work with BEST Operations, Comptroller operations, EOTSS operations, and Agency operations to ensure security operational actions are properly implemented.
- Assist/support BEST Phase 2 Technical Lead on integration data exchange inbound and outbound requirements identification, definition, and validation.
- Monitor compliance throughout design, configuration, development, testing, deployment, and transition to operations.
- Execute "tabletop" security reviews of end-to-end go-live security processes.
- Oversee and advise BEST program use of AI tools from a security point of view; advise vendor and SI on use of AI tools built into the Workday product natively.
- Ensure the completion of information security operations documentation.
- Develop strategies, procedures and recommended roles and responsibilities to enforce security requirements and address identified risks related to the use of the new solution.
- Oversee configuration updates and execution role in application development and implementation related to security requirements and controls; ensure security controls are implemented as planned and security and access needs are addressed throughout the user life cycle, in collaboration with the Comptroller Risk Management Team.
- Provide advice and recommendations on the data conversion of end users from the legacy system to the new system.
- Work with BEST, CTR's, and EOTSS' CSOs, CIOs, and the Comptroller's Risk Management Office to identify, select and implement technical controls related to data security and implement security processes and procedures ensuring controls are managed and maintained both centrally and within agencies where certain security management tasks are decentralized.
- Advise the BEST Team, SI and product vendors regarding end user security roles and groups, data access controls and security role provisioning and de-provisioning protocols.
- Support the BEST Team and agencies in identifying approved end users of the new solution and coordinating provisioning of users for Day One go live.
- Advise security administrators on normal and exception-based processing of security authorization requests including the use of SI or product vendor provided tools that monitor system use and data access irregularities.
- Act as a liaison between incident response leads and subject matter experts.
- Support the implementation of the new solution's complete security profile, including but not limited to: Azure Active Directory (AD) entry; Single Sign-On (SSO); New Solution User Security Role; New Solution User Workflow Role.
- In-depth exposure to technical configurations, technologies, and processing environments in one or more projects of similar size and complexity to BEST
- In-depth knowledge and understanding of information risk concepts and principles as a means of relating business needs to security controls
- Knowledge of and experience in developing and documenting security architecture and plans, including strategic, tactical and project plans
- Documented experience with common information security management frameworks, such as ISO 2700x, ITIL, SOX, COBIT, and NIST
- Experience in architecting and implementing cloud-based security solutions
- Extensive knowledge of security tools and capabilities, such as IDM and SSO
- Extensive experience in integrating security tools and 3rd party vendor solutions
- Exceptional planning, organization, communication, prioritization, and business analysis skills
- In-depth knowledge of risk assessment methods and technologies
- Proficiency in performing risk, business impact, control, and vulnerability assessments
- Excellent technical knowledge of mainstream operating systems and a wide range of security technologies, such as network security appliances, IAM systems, anti-malware solutions, privileged access management (PAM), data loss prevention (DLP), encryption at-rest and in-transit, multi-factor authentication (MFA), end-point security, vulnerability scanning and patch management, automated policy compliance tools, and desktop security tools
- Experience in developing, documenting, and maintaining security policies, processes, procedures, and standards
- Knowledge of network infrastructure, including routers, switches, firewalls, and the associated network protocols and concepts
- Strong analytical skills to analyze security requirements and relate them to appropriate security controls
- Documented written and verbal communication skills
- Experience working with modern issue tracking systems (JIRA)
- Ability to interact with personnel at all levels and across all business units and organizations, and to comprehend business imperatives MINIMUM ENTRANCE REQUIREMENTS
- Bachelor's degree in computer science, system analysis or a related study, or equivalent experience in the field of audit compliance and security risk and compliance management
- Minimum of nine years of design and implementation experience in IT, with deep knowledge in a minimum of two of the following technical disciplines: infrastructure and network design, application development, application programming interfaces (APIs), middleware, servers and storage, database management, data security, and system administration and operations
- Experience in generation of security materials, including but not limited to compliance adherence, security operational procedures, security implementation plans, and network and security diagrams
- Minimum of five years of security architecting design and implementation with security certifications, such as Security+
Flexible work from home options available.
- ...Job Description Job Description BEST Program Security Architect Location: Boston, MA Duration: 6 Months Position Summary The BEST Program Security Architect will work with the BEST Solution Technical Lead and Deputy Program Manager to support the adoption...SuggestedFor contractors
$175k - $200k
...office. We are seeking a strategic Security Architect to define and drive our cloud and enterprise... ..., and development teams on security best practices Partner strategically with... ...work, with global awards and kudos programs As an international company, the chance...SuggestedWork at officeLocal areaRemote workWork from homeShift work3 days per week$120k - $202.5k
...ForWe are looking for a Senior Application Security Architect. You will be responsible for designing,... ...Zero Trust, DevSecOps, and AI security best practices across the enterprise.... ...State Street’s comprehensive benefits program, which includes: our retirement savings...SuggestedFull timeTemporary workFlexible hoursShift work$90k - $157.5k
...Looking ForWe are looking for a Cloud Security Architect. You will be responsible for defining,... ...requirements, enterprise standards, and industry best practices.What You Will Be Responsible... ...State Street’s comprehensive benefits program, which includes: our retirement savings...SuggestedFull timeTemporary workFlexible hoursShift work$120k - $202.5k
...Looking ForWe are looking for a Senior Cloud Security Architect. You will be responsible for defining,... ..., enterprise standards, and industry best practices.What You Will Be Responsible... ...State Street’s comprehensive benefits program, which includes: our retirement savings...SuggestedFull timeTemporary workFlexible hoursShift work$155k - $195k
...about training, recovery, and lifestyle.WHOOP is seeking a Security Architect to help build and scale the Security Architecture function within... ...with healthcare, regulated environments, or security programs supporting HIPAA, PCI DSS, ISO 27001, SOC 2, NIST 800-53, or...Full timeWork at officeRelocation$120k - $175k
Technology Cyber Security ArchitectCooley is seeking a Cyber Security Architect to join the technology team.Position summary: Cooley Technology embraces a culture... ...disciplineFamiliarity with security frameworks and best practices (NIST CSF, Mitre ATT&CK, Zero Trust, OWASP...Full timeTemporary workWork at officeFlexible hoursWeekend work- ...Manager Edge Security Architect Type of Job: New Contracting Role Req # to submit to: 2026-149848 Client: UHG Openings... ...• Implements and maintains network and application security best practices including change controls configuration standards documentation...For contractorsWork at office
$120k - $202.5k
Who We Are Looking ForWe are looking for a Senior Data Security Architect. You will be responsible for designing, reviewing, and governing... ...eligible to participate in State Street’s comprehensive benefits program, which includes: our retirement savings plan (401K) with...Full timeTemporary workFlexible hoursShift work$120k - $202.5k
Who we are looking for We are seeking a Product Security Engineer / Architect - Email Security reporting into the Defensive Engineering leadership... ...eligible to participate in State Street’s comprehensive benefits program, which includes: our retirement savings plan (401K) with...Full timeTemporary workWork at officeFlexible hours$95.92k - $177.63k
...apply now. We are currently seeking a Security Risk Assessment Architect to join our team in Boston,... ...developing plans to meet or exceed security best practices Ensure the... ...problem-solving abilities Project and program management planning and organizational...Temporary workWork at officeRemote workFlexible hours- Enterprise Architect -Presales Retail & ManufacturingThis role has been... ...and resources and sharing best practices with peers and partners... ...request by completing our secure form linked here.Note: This... ...we all are. We have specific programs catered to helping you reach...Full timeWork experience placementLocal areaImmediate startRemote workWork from home
$87.4k - $253k
...beyond multi-year planning to architect solutions that learn, adapt,... ...technology, data and analytics, security, cloud, and platform... ...perspectives and bring out the best in the teams around you. You... ...scale technology transformation programs that deliver measurable business...Full timeWork experience placementInternshipLive inWork at officeLocal area$156k - $253k
...military in months, not years.ABOUT THE TEAMWe're seeking a product security engineer to own security for assigned products in your... ...and processesREQUIRED QUALIFICATIONSExperience with one or more programming languages (e.g. C/C++, Golang, Rust, Python)Experience assessing...Full timeWork experience placementImmediate start- ...KPMG is currently seeking a Director, Cyber Defense Agentic Security Architect, to join our Advisory Services practice. Responsibilities... ...enterprise cyber defense architectures and security automation programs Strong understanding of AI, machine learning, and agentic...H1b
- ...Wittij Inc. is seeking a seasoned Solution Architect to lead end-to-end designs for large, complex programs. The role blends hands-on architecture with strategic oversight, ensuring security, data integrity, and scalable integration across enterprise domains. You will...Remote job
$130.7k - $205.2k
Senior Security Software Developer (R&D)Description -We are looking for a Senior Security Software... ...policies and practices to determine best method for accomplishing work and... ...perspective to cross-organization projects, programs, and activities.Drives innovation and integration...Full timeTemporary workLocal areaRelocationFlexible hoursShift work$165k - $185k
We are seeking a highly motivated and experienced Security Architect, Cloud & Emerging Technology. Reporting to the Associate Director of Information... ...of Massachusetts’ Top Places to Work by the Boston Globe, a Best Place to Work in Greater Cincinnati by the Cincinnati...Work at officeLocal areaFlexible hoursShift work3 days per week$120k - $202.5k
...Who we are looking for We are seeking a Product Security Engineer / Architect – Email Security reporting into the Defensive Engineering leadership... ...to participate in State Street’s comprehensive benefits program, which includes: our retirement savings plan (401K)...Temporary workFlexible hours$120k - $175k
Technology Cloud Security ArchitectCooley is seeking a Technology Cloud Security Architect to join the Security team.About Cooley: Cooley is a global law firm with an expansive... ...training and guidance on cloud security best practices to Technology staff and other...Full timeTemporary workWork at officeRemote workWork from homeWorldwideFlexible hoursWeekend work$154k - $208k
...OVERVIEWWe are seeking an Enterprise Solutions Architect with deep expertise in life science R&D... ...solution architecture, and establishing best practices and data architecture standards... ...employees enjoy a comprehensive benefits program including equity, health, dental, vision,...Work at officeLocal areaFlexible hours3 days per week$140k - $200k
...a hands on (in the code) Solutions Architect at Formlabs, you will be a strategic... ...applications, infrastructure, data, and security to do their best work. This is a high-impact role... ...Our Perks & Benefits: Robust equity program to build future wealth through RSUs...Full timeWork at officeFlexible hours3 days per week$117.6k - $176.4k
As a Senior Security Engineer at EnergySage, you will play a pivotal role in fortifying our... ...implementations and templates to streamline best practices across the team.Monitoring and... ..., paid family leaves, well-being programs, 12 holidays per year, and 15 days of paid...Full timeTemporary workFlexible hours$88k - $126k
...culture that supports you in doing what you do best. Our employees work together to reach... ...who rely on us to help them build more secure and prosperous futures. THE ROLEA technical... ...and may participate one or more program(s), project(s), scope of work, or processes...Full timeWork experience placementWork at officeLocal areaRemote workFlexible hoursShift workNight shiftWeekend work$145.9k - $234.2k
...functional partners to help keep Moderna secure. Here’s What You’ll DoIncident Response &... ...Moderna, we believe that when you feel your best, you can do your best work. That’s why... ...Competitive healthcare, plus voluntary benefit programs to support your unique needsA holistic...Permanent employmentFull timeWork at officeWork from home$141.6k - $212.4k
...destiny.Klaviyo is looking for a Senior Security Engineer to add to our growing Detection... ...data engineering techniques Proficient in programming languages to automate / build (e.g.,... ...our customers. If you’re ready to do the best work of your career, where you’ll be welcomed...$145.9k - $234.2k
...implement, and mature Moderna’s approach to API security across modern applications, platform... ..., we believe that when you feel your best, you can do your best work. That’s why our... ...Competitive healthcare, plus voluntary benefit programs to support your unique needsA holistic...Permanent employmentFull timeWork at officeWork from home$159.3k - $202.4k
...for a diverse range of customers?The AWS Security Hub team is looking for a highly... ...environments.Basic qualifications- 3+ years of programming in Python, Ruby, Go, Swift, Java, .Net,... ...culture empowers Amazonians to deliver the best results for our customers. If you have a...InternshipFlexible hours$121k - $226k
...continue to grow, we’re looking for a Sr. AI Security Engineer. Hi Marley is building an AI-... ...findings into our practices. AI Security Program Execution Run the risk assessment process... ...an environment where people can do their best work, feel supported, and grow alongside...Work at officeFlexible hours3 days per week$140k - $190k
...your professional and personal goals is the best way to help our clients and advance our... ...we are seeking a Senior Vulnerability & Security Engineer to lead the advancement of the organization... ...management and security configuration programs.This is a technical cybersecurity role...Full timeLocal areaImmediate start
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to BEST Program Security Architect. Be the first to apply!


