DescriptionAt ScionHealth, we empower our caregivers to do what they do best. We value every voice by caring deeply for every patient and each other. We show courage by running toward the challenge and we lean into new ideas by embracing curiosity and question asking. Together, we create our culture by living our values in our day-to-day interactions with our patients and teammates.
Job Summary
Serves as the enterprise technical authority for the security architecture, governance, and continuous improvement of ScionHealth's Microsoft 365 and related Microsoft cloud security environment. Designs and maintains security architecture across Microsoft Entra ID, Microsoft Intune, Microsoft Defender, Microsoft Purview, Microsoft Sentinel, and Azure security services. Partners with Cybersecurity Operations, Infrastructure Services, Identity and Access Management, Enterprise Architecture, Clinical Informatics, Compliance, Legal, and Internal Audit to reduce cyber risk, protect sensitive information, and enable secure clinical and business operations.
Essential Functions
- Develops and maintains the enterprise Microsoft 365 security architecture, roadmap, standards, reference designs, and technical governance.
- Leads implementation of Zero Trust principles and evaluates emerging Microsoft security capabilities for enterprise adoption.
- Conducts architecture reviews and security assessments and develops risk-based remediation recommendations.
- Ensures Microsoft cloud security architecture aligns with enterprise cybersecurity strategy, policies, risk tolerance, and regulatory obligations.
- Architects security controls for Microsoft Entra ID, conditional access, multifactor and passwordless authentication, privileged identity management, identity governance, lifecycle workflows, federation, and single sign-on.
- Designs secure access patterns for employees, clinicians, contractors, vendors, remote users, third-party applications, and external collaboration.
- Architects endpoint security using Microsoft Intune, Microsoft Defender for Endpoint, Endpoint Privilege Management, device compliance, Windows security baselines, BitLocker, Autopilot, mobile device management, mobile application management, and bring-your-own-device controls.
- Partners with operational teams to secure clinical workstations, shared devices, executive devices, mobile devices, and virtual desktop environments.
- Leads architecture and deployment of Microsoft Defender XDR, Defender for Endpoint, Defender for Office 365, Defender for Identity, Defender for Cloud Apps, and related exposure management capabilities.
- Designs security monitoring and analytics using Microsoft Sentinel, Azure Monitor, security dashboards, SIEM integrations, and SOAR automation.
- Partners with the Security Operations Center to improve visibility, threat detection, automated investigation, threat hunting, incident response, and reduction of false positives.
- Defines security telemetry, alerting, integration, and escalation requirements for Microsoft cloud services.
- Architects Microsoft Purview capabilities, including data loss prevention, information protection, sensitivity labels, data classification, insider risk management, records management, eDiscovery, communication compliance, and information barriers.
- Evaluates Microsoft Secure Score, identity and endpoint posture, vulnerabilities, configuration risk, and control effectiveness; leads development of remediation priorities.
- Ensures security architecture supports HIPAA, HITECH, applicable CMS and Joint Commission requirements, state privacy requirements, PCI-DSS where applicable, and internal governance standards.
- Creates and maintains security architecture diagrams, standards, control requirements, operating procedures, and technical documentation.
- Provides architectural leadership for major Microsoft security implementations, cloud adoption, acquisitions, integrations, and modernization initiatives.
- Advises technical and business leaders on security risks, control options, tradeoffs, and implementation priorities.
- Mentors security engineers and analysts and provides escalation support for complex Microsoft cloud security issues.
- Collaborates with Microsoft, implementation partners, and strategic vendors to validate designs, resolve issues, and improve security maturity.
Knowledge/Skills/Abilities/Expectations
- Demonstrated ability to translate business and clinical needs into practical, secure, and scalable technology solutions.
- Strong analytical, problem-solving, and decision-making skills, including the ability to evaluate risk, alternatives, and downstream impacts.
- Excellent written and verbal communication skills, including the ability to explain complex technical concepts to technical and nontechnical audiences.
- Ability to build effective relationships and influence outcomes across Information Technology, Cybersecurity, clinical, operational, compliance, and business teams.
- Strong planning and project leadership skills with the ability to manage multiple priorities in a complex, fast-paced environment.
- High degree of accountability, judgment, customer focus, and commitment to continuous improvement.
QualificationsEducation
Licenses/Certifications
- Microsoft Certified: Cybersecurity Architect Expert (SC-100) or comparable Microsoft security certification (Preferred)
- CISSP, CCSP, CISM, or other relevant cybersecurity certification (Preferred)
- Advanced knowledge of Microsoft 365 E5 Security and Compliance, Microsoft Entra ID, Microsoft Intune, Microsoft Defender XDR, Microsoft Sentinel, Microsoft Purview, Microsoft Azure security services, and Microsoft cloud administration Preferred
- Advanced knowledge of Zero Trust, identity security, conditional access, privileged access, endpoint security, data protection, SIEM/SOAR, cloud security posture, threat detection, and incident response integration Preferred
- Knowledge of PowerShell, Microsoft Graph API, Azure Policy, Azure Monitor, security automation, federation, hybrid Active Directory, and enterprise application integration Preferred
- Working knowledge of healthcare cybersecurity, protected health information, clinical workstation security, electronic health record security, third-party risk, business continuity, and regulated environments Preferred
Experience
- 7-9 years progressive cybersecurity, infrastructure security, identity, or cloud security experience (Required) With
- 5+ years designing Microsoft 365 security solutions in a large, complex environment (Required)
- Prior Experience implementing Zero Trust architecture, Microsoft Entra ID security, Microsoft Defender, Microsoft Intune, Microsoft Purview, and Microsoft Sentinel capabilities (Required)
- Prior Experience developing enterprise security standards, reference architectures, risk assessments, and remediation roadmaps (Required)
- Prior Experience leading major cloud security initiatives involving multiple technical, compliance, and business stakeholders (Required)
- Prior Experience in healthcare or another highly regulated, multi-site environment (Preferred)
Additional Qualifications Clarification
- Advanced knowledge of Microsoft 365 E5 Security and Compliance, Microsoft Entra ID, Microsoft Intune, Microsoft Defender XDR, Microsoft Sentinel, Microsoft Purview, Microsoft Azure security services, and Microsoft cloud administration (Preferred proficiency)
- Advanced knowledge of Zero Trust, identity security, conditional access, privileged access, endpoint security, data protection, SIEM/SOAR, cloud security posture, threat detection, and incident response integration (Preferred proficiency)
- Knowledge of PowerShell, Microsoft Graph API, Azure Policy, Azure Monitor, security automation, federation, hybrid Active Directory, and enterprise application integration (Preferred proficiency)
- Working knowledge of healthcare cybersecurity, protected health information, clinical workstation security, electronic health record security, third-party risk, business continuity, and regulated environments (Preferred proficiency)