
IT Security Architect
Vail Health has become the world’s most advanced mountain healthcare system. Vail Health consists of an updated 520,000-square-foot, 56-bed hospital. This state-of-the-art facility provides exceptional care to all of our patients, with the most beautiful views in the area, located centrally in Vail. Learn more about Vail Health here.
- Owns the enterprise security architecture and multi year roadmap, defining target state designs, security standards, and investment priorities; acts as a trusted advisor to executive leadership and drives cross functional delivery across IT, cloud, and product teams.
- Establishes and governs enterprise identity, access, and data protection strategy, including SSO/MFA, federation (SAML, OIDC, OAuth), RBAC/ABAC, IGA lifecycle automation, privileged access management (PAM), and secrets and certificate management—enforcing least privilege and zero standing access at scale.
- Defines and executes cloud security strategy across Azure and AWS by designing secure landing zones and zero trust guardrails; implements and operationalizes CSPM, CWPP, and CIEM capabilities to continuously reduce cloud risk and misconfiguration exposure.
- Leads network and Zero Trust architecture modernization, including micro segmentation, NAC, next generation firewalls, secure remote access, and policy enforcement; delivers measurable isolation of critical systems and reduction of lateral movement risk.
- Elevates security operations architecture and detection strategy, shaping SIEM and XDR correlation across endpoint, identity, email, cloud, and network telemetry; optimizes signal to noise, detection fidelity, and mean time to detect and respond (MTTD/MTTR).
- Owns incident response architecture and organizational readiness, developing playbooks for containment, eradication, and recovery; ensures forensic readiness; leads post incident executive reviews and drives durable control improvements aligned to root cause analysis.
- Scales security automation and orchestration through SOAR and API driven integrations, automating high impact detections, incident response workflows, access reviews, and vulnerability and patch pipelines; maintains policy as code and audit ready evidence collection.
- Hardens enterprise email and social engineering defenses, enforcing DMARC, DKIM, and SPF, advanced BEC protections, and SEG/SASE integrations; analyzing attack trends to inform preventative controls and security awareness initiatives.
- Owns enterprise vulnerability and patch governance, implementing risk based prioritization, remediation SLAs, executive dashboards, and validation of fixes; partners with Infrastructure and Cloud teams to continuously improve hardening baselines and exposure metrics.
- Embed governance, risk, and compliance requirements into security architecture, aligning designs to HIPAA, HITECH, HITRUST, NIST CSF and 800 series controls, CIS Controls, and ISO 27001; delivering defensible metrics and board level reporting.
- Applies healthcare specific security patterns for PHI, EMR/EHR platforms, and connected clinical devices, ensuring secure data flows, strong segmentation, and protection of patient care networks where applicable.
- Leads security platform and vendor strategy, including evaluation and proof of value, selection, enterprise rollout, and optimization of EDR/XDR, SIEM, IAM/IGA/PAM, and cloud security platforms; demonstrate measurable risk reduction and return on security investment.
- Five years of experience in Information Technology required (multiple areas preferred).
- Three years of experience in healthcare information security preferred.
- Demonstrated knowledge of Network Hardware Configuration, Network Protocols, Information Security requirements for healthcare, and policy creation required.
- Demonstrated knowledge of EMR products preferred.
License(s) & Certification(s):
- Certified Information Systems Security Professional (CISSP) required
- Other IT Security Certifications Desired: CISM, CISA, Microsoft, Cisco
- Bachelor’s degree in computer science or information systems preferred.
Benefits at Vail Health (Full Time) Include:
- Competitive Wages & Family Benefits:
- Competitive wages
- Parental leave (4 weeks paid)
- Housing programs
- Childcare reimbursement
- Comprehensive Health Benefits:
- Medical
- Dental
- Vision
- Educational Programs:
- Tuition Assistance
- Existing Student Loan Repayment
- Specialty Certification Reimbursement
- Annual Supplemental Educational Funds
- Paid Time Off:
- Up to five weeks in your first year of employment and continues to grow each year.
- Retirement & Supplemental Insurance:
- 403(b) Retirement plan with immediate matching
- Life insurance
- Short and long-term disability
- Recreation Benefits, Wellness & More:
- Up to $1,000 annual wellbeing reimbursement
- Recreation discounts
- Pet insurance
The posted salary range for this position is the anticipated hiring range in Colorado and will be adjusted based on geographic location. Vail Health considers a variety of factors in making compensation decisions which influence the offer a candidate receives.
Yearly pay:
$104,208 - $143,852.80 USD
Create a Job Alert
Interested in building your career at Vail Health Hospital? Get future opportunities sent straight to your email.
Apply for this job
*
indicates a required field