Solution Architect
Job Summary
We are seeking a Security Architect to support a comprehensive modernization assessment of a multi-state Medicaid Provider platform built on .NET and C#. This role is responsible for evaluating the security posture of the current platform, defining security requirements and controls for the target-state architecture, and ensuring that compliance obligations — including HIPAA and CMS MITA 3.0 — are fully addressed in all architectural recommendations.
The ideal candidate brings deep experience in application and cloud security architecture within regulated environments, with hands-on knowledge of identity and access management, data protection, tenant boundary enforcement, and DevSecOps pipeline security. This person will work closely with solution, data, and infrastructure architects to ensure security is embedded across every layer of the target-state design.
Key Responsibilities
• Assess the current security posture of the Legacy Provider and Provider Plus platforms, including authentication, authorization, encryption, audit logging, and vulnerability management practices • Evaluate HIPAA and data privacy controls for data handling, access management, PII boundary enforcement, and audit traceability across current-state implementations • Define security architecture requirements for the target-state multi-tenant platform, including per-tenant role-based access enforced through PingOne OIDC, encryption standards (TLS 1.2+, AES-256 at rest, FIPS 140-3 validated modules), and database-per-tenant data isolation on Aurora PostgreSQL • Assess cross-tenant data isolation requirements and PII boundary risks, including data separation in the Aurora PostgreSQL database-per-tenant model and tenant connection routing • Contribute to the DevSecOps security pipeline assessment, including SAST/DAST integration, dependency and software composition scanning, serverless artifact scanning, and secrets management tooling • Evaluate identity and access management patterns built on PingOne OIDC federated to TennCare IAM, including tenant resolution from token claims and claim-based authorization across the .NET on AWS Lambda request pipeline • Assess the security implications of event-driven integration on Amazon MSK Serverless, external system integrations over REST APIs and file-based exchange (Amazon S3 and MOVEit), and API exposure • Contribute security findings and remediation recommendations to the Gap Analysis, Critical Remediation Roadmap, Operations and Stability Improvement Plan, and Executive Decision Pack • Participate in stakeholder interviews and SME sessions to validate current-state security practices and identify operational riskRequired Qualifications
• 10+ years of security architecture experience in enterprise or regulated environments • Deep knowledge of HIPAA and data privacy requirements, including handling of PII and other sensitive data, access controls, audit logging, and breach notification obligations • Strong experience defining and assessing security architecture for multi-tenant cloud-native platforms • Hands-on experience with DevSecOps pipeline security including SAST/DAST tools, dependency and software composition scanning, and secrets management • Strong understanding of identity and access management patterns including RBAC, OAuth 2.0, OpenID Connect (including federated identity providers such as PingOne), and claims-based authorization • Experience with encryption standards and data protection controls for regulated data at rest and in transit • Experience conducting security gap assessments and producing prioritized remediation roadmaps • Strong communication skills with the ability to present security risks and recommendations to both technical teams and executive stakeholdersPreferred Qualifications
• Experience in healthcare, Medicaid, or other CMS-regulated environments • Familiarity with CMS MITA 3.0 standards and federal Medicaid IT security requirements • Experience assessing .NET or ASP.NET Core application security, including middleware pipeline security patterns • Exposure to multi-tenant PII boundary analysis and tenant isolation risk modeling • Experience with AWS security tooling, including IAM and SigV4, security groups, and cloud-native security posture management (such as AWS Security Hub and GuardDuty) • Relevant certifications such as CISSP, CISM, CCSP, or equivalentWhat Success Looks Like
• Current-state security posture is clearly documented with HIPAA and data privacy compliance gaps, PII boundary risks, and access control deficiencies identified and prioritized • Security requirements for the target-state multi-tenant architecture are defined with sufficient detail to guide implementation planning • DevSecOps pipeline security recommendations are actionable, prioritized, and integrated into a Operations and Stability Improvement Plan • Security findings are accurately reflected across the Gap Analysis, Remediation Roadmap, and Executive Decision Pack with clear risk ratings and mitigation paths • Tenant isolation and PII boundary controls in the target architecture meet or exceed HIPAA, CMS, and applicable data privacy requirements