Jobs and Careers
AV
Principal Cybersecurity Architect
Avera HealthSioux Falls, United Statesfull_timeVerifiedPosted 16 Feb 2026
💰 $180,960/yr($121,160/yr – $180,960/yr)
About the role
Location:
Avera Downtown Building-Sioux FallsWorker Type:
RegularWork Shift:
Day Shift (United States of America)Pay Range:
The pay range for this position is listed below. Actual pay rate dependent upon experience.
$121,160.00 - $180,960.00Position Highlights
You Belong at Avera
Be part of a multidisciplinary team built with compassion and the goal of Moving Health Forward for you and our patients. Work where you matter.
A Brief Overview
The Principal Cybersecurity Architect at Avera is the senior-most technical authority responsible for defining, designing, and guiding the enterprise cybersecurity architecture across the health system, including hospitals, clinics, senior care, home health, and payer operations. This role ensures that cybersecurity architecture principles, frameworks, and reference models support business strategy, safeguard patient safety, comply with regulatory requirements (HIPAA, OCR, CMS), and enable secure digital transformation. The Principal Architect partners closely with IT Infrastructure, Data Analytics, IT Architecture, Network Engineering, Clinical Engineering, DevOps, and Application teams to design secure, resilient, scalable solutions and serve as a key advisor to the CISO and senior leadership.
What you will do
- Enterprise Security Architecture & Strategy: • Develop and maintain the Enterprise Security Architecture Blueprint, including reference architectures for cloud, on-prem, hybrid, and edge environments (clinical devices, IoT). • Establish and champion Zero Trust Architecture across identity, network, endpoint, and application workloads. • Define long-term security technology roadmaps aligned with organizational strategy and cybersecurity maturity goals. • Translate business requirements into security architecture requirements for new systems, acquisitions, and enterprise initiatives.
- Cloud & Infrastructure Architecture: • Lead secure architecture for Azure, AWS, and SaaS platforms, ensuring proper identity segmentation, encryption, workload isolation, and secure configuration baselines. • Partner with Infrastructure/Network teams to design micro-segmentation, firewall policies, SD-WAN security, and secure remote access solutions.
- Clinical & Enterprise Systems Security: • Develop secure design guidelines for EHR (Epic), PACS, VDI, data platforms, IoMT/biomedical devices, and other clinical technologies. • Collaborate with Clinical Engineering to ensure IoMT vulnerabilities, patching constraints, device segmentation, and lifecycle management align with enterprise security controls. • Validate security of vendor integrations, APIs, and interfaces with PHI flows.
- Security Controls, Standards & Governance: • Define enterprise security standards, patterns, and reusable control templates (NIST CSF, NIST 800-53, CIS). • Review and approve all high-risk architecture designs, cloud deployments, and technical exceptions. • Oversee threat modeling and secure design reviews for major projects. • Maintain architecture governance processes and ensure alignment with GRC and compliance requirements.
- Threat Modeling & Risk Reduction: • Conduct threat modeling on new solutions and major system changes using frameworks such as STRIDE, MITRE ATT&CK, and DREAD. • Provide expert-level guidance on attack paths, privilege escalation risks, identity architecture weaknesses, and compensating controls. • Work closely with the SOC and Incident Response teams to design detection and response visibility into new architectures.
- M&A, Vendor Due Diligence, and Third-Party Integrations: • Lead technical due diligence for acquisitions, affiliation partners, and new clinical applications. • Evaluate vendor security architecture, API exposure, access models, and integration risks. • Ensure third-party environments meet enterprise security architecture requirements before connection or data sharing.
- Leadership, Influence & Mentorship: • Serve as the technical advisor to the CISO and a trusted consultant to senior IT and business leaders. • Mentor security engineers and architects, enabling career growth and improving architectural maturity. • Communicate complex architectural decisions and risks to executives in clear business terms.
Essential Qualifications
The individual must be able to work the hours specified. To perform this job successfully, an individual must be able to perform each essential job function satisfactorily including having visual acuity adequate to perform position duties and the ability to communicate effectively with others, hear, understand and distinguish speech and other sounds. T
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s