Bellese Technologies Logo

Bellese Technologies

Staff Engineer, Security Architect

Posted 8 Days Ago
Remote
Hiring Remotely in United States
150K-182K Annually
Senior level
Remote
Hiring Remotely in United States
150K-182K Annually
Senior level
The Staff Engineer, Security Architect will implement an information security program, manage risks, develop policies, and ensure compliance with regulations.
The summary above was generated by AI
The Staff Engineer, Security Architect will play a critical role in implementing and maintaining an effective information security program for the organization within the context of the Hospital Quality Reporting (HQR) contract, including the maintenance of the HQR Authority to Operate (ATO). The HQR system is a software solution utilized by the Center for Medicare and Medicaid Services (CMS) to assess the quality of care provided by hospitals, catering to both Medicare recipients and the broader U.S. population.

The Staff Engineer, Security Architect may provide support across multiple contracts as well as contribute to business development and growth initiatives at Bellese. This role is responsible for protecting the confidentiality, integrity, and availability of the organization's information assets by identifying and managing risks, developing and implementing policies and procedures, conducting security assessments, and ensuring compliance with relevant laws and regulations.

The Staff Engineer, Security Architect will also support cross-functional development teams across various aspects, including design & architecture, application security, infrastructure & operability, and testing & quality assurance. This position will contribute to the organization's overall security posture while fostering collaboration with diverse teams and stakeholders, and promoting a culture of security consciousness and innovation.

Responsibilities

  • Develop, implement, and maintain the organization's information security strategy and policies to protect sensitive (PII/PHI) data, infrastructure, and intellectual property.
  • Serve as the primary point of contact for all information security matters, including risk assessment, vulnerability management, and incident response.
  • Collaborate with IT and business stakeholders to ensure that security is incorporated in the design, development, and implementation of new and existing systems and applications.
  • Develop and oversee the implementation of security controls, procedures, and guidelines in compliance with CMS Acceptable Risk Safeguards (ARS), Federal Information Security Management Act (FISMA) requirements, and other applicable regulations.
  • Perform regular security audits and assessments to identify vulnerabilities, threats, and risks, and recommend appropriate mitigation strategies.
  • Oversee the Authority to Operate (ATO) process, ensuring that all necessary security documentation, such as System Security Plans (SSPs), Adaptive Capabilities Testing (ACT), and Plans of Action and Milestones (POA&Ms), are developed, maintained, and submitted in a timely manner.
  • Lead incident response efforts, including investigation, containment, and remediation of security incidents and coordinating with relevant stakeholders and external parties.
  • Establish and maintain relationships with external security vendors, partners, and agencies to enhance the security posture and obtain threat intelligence.
  • Provide security awareness training and education to employees, contractors, and partners, promoting a culture of security consciousness within the organization.
  • Evaluate and recommend new security technologies, tools, and best practices to enhance the organization's security capabilities and defenses.
  • Monitor and report on the organization's security posture and the effectiveness of security controls, providing regular updates to senior management and key stakeholders.
  • Develop and maintain documentation of security policies, procedures, standards, and guidelines, ensuring they remain current and relevant.
  • Provide expert guidance and mentorship to junior team members, fostering their professional growth and development.
  • Participate in industry conferences and forums to stay current on the latest trends, technologies, and best practices in information security.
  • Serve as a subject-matter-expert in security with clients, working to build trust in Bellese’s approach and qualifications.

Qualifications

  • A Bachelor's or Master's degree in Computer Science, Information Security, or a related field.
  • CISSP, CISM, or other relevant security certifications.
  • A minimum of 7 years of experience (10+ preferred) in information security, with at least 5 years in a leadership role.
  • In-depth knowledge of CMS security requirements, FISMA, NIST security frameworks, and other applicable regulations.
  • In-depth knowledge and experience using the CMS CFACTS tool.
  • Strong experience delivering AWS-based cloud solutions that leverage EC2, ECS, Lambda, Cloudwatch, SNS, SQS, EventBridge, S3, RDS, DynamoDB, Glue, Elasticsearch, RedShift, ElastiCache, Athena, KMS, Secrets Manager, Security Hub, Inspector, Certificate Manager, and more.
  • Strong experience working with Java, Spring Boot, Python, Go, JS/TS, Angular, and other languages/frameworks.
  • Strong experience working with Terraform, Jenkins, Git/Github, New Relic, Tenable Nessus, SonarQube, Snyk, and other DevSecOps technologies.
  • Strong knowledge of information security principles, technologies, and best practices.
  • Strong knowledge of industry standards and government regulations related to information security.
  • Excellent communication, interpersonal, and leadership skills.
  • Strong analytical, problem-solving, and decision-making abilities.

Top Skills

Angular
Athena
AWS
Certificate Manager
Cloudwatch
DynamoDB
Ec2
Ecs
Elasticache
Elasticsearch
Eventbridge
Git
Git
Glue
Go
Inspector
Java
Jenkins
JavaScript
Kms
Lambda
New Relic
Python
Rds
Redshift
S3
Secrets Manager
Security Hub
Sns
Snyk
Sonarqube
Spring Boot
Sqs
Tenable Nessus
Terraform
Ts

Similar Jobs

35 Minutes Ago
Remote
USA
144K-195K Annually
Senior level
144K-195K Annually
Senior level
Cloud • Greentech • Social Impact • Software • Consulting
The Marketing Director will lead integrated marketing campaigns to drive pipeline growth, aligning with Sales and managing cross-functional efforts for successful execution.
Top Skills: Abm PlatformsLucidchartMarketoPower BISalesforce
59 Minutes Ago
Remote or Hybrid
NC, USA
Mid level
Mid level
Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Develop internal tools and frameworks for product distribution while working with existing codebases and greenfield applications. Focus on software development, primarily in Go, with experience in Kubernetes, virtualization, and CI/CD processes.
Top Skills: ArgocdAWSAzureBambooGCPGoHelmJenkinsKubernetesPostgresPythonSQLVMware
An Hour Ago
Remote or Hybrid
USA
135K-215K Annually
Senior level
135K-215K Annually
Senior level
Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Design and implement security features for a Linux sensor, ensuring performance and reliability while collaborating with cross-functional teams.
Top Skills: AWSCC++DockerEbpfKubernetesLinux

What you need to know about the Boston Tech Scene

Boston is a powerhouse for technology innovation thanks to world-class research universities like MIT and Harvard and a robust pipeline of venture capital investment. Host to the first telephone call and one of the first general-purpose computers ever put into use, Boston is now a hub for biotechnology, robotics and artificial intelligence — though it’s also home to several B2B software giants. So it’s no surprise that the city consistently ranks among the greatest startup ecosystems in the world.

Key Facts About Boston Tech

  • Number of Tech Workers: 269,000; 9.4% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Thermo Fisher Scientific, Toast, Klaviyo, HubSpot, DraftKings
  • Key Industries: Artificial intelligence, biotechnology, robotics, software, aerospace
  • Funding Landscape: $15.7 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Summit Partners, Volition Capital, Bain Capital Ventures, MassVentures, Highland Capital Partners
  • Research Centers and Universities: MIT, Harvard University, Boston College, Tufts University, Boston University, Northeastern University, Smithsonian Astrophysical Observatory, National Bureau of Economic Research, Broad Institute, Lowell Center for Space Science & Technology, National Emerging Infectious Diseases Laboratories

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account