Jobs and Careers
HE

Enterprise Security Architect

Hearst
United Statesfull_timeVerifiedPosted 25 Feb 2026

About the role

The Opportunity: 

Homecare Homebase is seeking a hands-on, engineering-first Enterprise Security Architect to help secure and accelerate our modernization of our EHR platform into a cloud-native future. This role is ideal for a senior security-minded software architect who thrives at the intersection of secure-by-design architecture and real implementation. Someone who can define security patterns and also write code to make them real in our platform.

 

This role will partner closely with Architecture, Engineering, Platform, Product, and Compliance to embed security into how we build—not as a gate at the end, but as a repeatable set of guardrails, paved roads, and automation. This role will ensure security scales with modernization and delivery velocity using both traditional techniques and leading-edge AI technology.

 

What You Will Do:

  • Enterprise Security Architecture & Secure-by-Design Patterns

    • Define and maintain security reference architectures, standards, and reusable patterns for modern distributed systems and SaaS platforms.

    • Lead security design reviews for major platform changes, modernization initiatives, and new service development.

    • Create “secure defaults” that reduce risk while improving engineering throughput and consistency.

  • Secure Software Development Lifecycle (SSDLC) Enablement

    • Embed secure development practices into how teams plan, build, test, and ship software (AI & automation-first). 

    • Partner with engineering teams to implement scalable guardrails in CI/CD (policy, validation, prevention) without slowing delivery.

    • Improve secure delivery practices including dependency risk management, secrets hygiene, and build/release integrity.

  • Threat Modeling & Risk Reduction

    • Drive threat modeling as a standard engineering practice for meaningful architecture changes and new feature development. 

    • Ensure threats are translated into real mitigations (architecture decisions, code changes, and automated validation).

    • Help teams proactively reduce risk by identifying trust boundaries, data flows, and attack paths early.

  • Cloud-Native & Platform Security (Azure + Kubernetes)

    • Establish secure patterns for containerized systems: image standards, runtime protections, network segmentation, and least-privileged service access.

    • Partner with platform engineering on Kubernetes and Azure security posture, including identity boundaries and secure workload patterns.

    • Build scalable guardrails that work across environments and teams—security that grows with the platform.

  • Security Engineering (You Will Write Code)

    • Build shared libraries, templates, SDKs, and platform components that make secure development the easiest path.

    • Contribute directly to production services and platform capabilities when needed to deliver secure patterns quickly.

    • Automate security controls and reduce repetitive work through tools and developer experience improvements.

  • Cross-Functional Leadership & Audit Closure

    • Drive alignment across Architecture, Engineering, Compliance, and Product to close open audit issues and prevent recurrence.

    • Communicate clearly: write actionable guidance, design docs, and decision records that engineers actually use.

    • Serve as a trusted security partner—supporting teams with speed, clarity, and pragmatism.

 

What You Will Bring:

  • 8+ years of experience in software engineering, including designing and building large-scale systems.
  • 4+ years leading application security, product security, or enterprise security architecture in modern software environments.

  • Strong development experience in C# /

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Hearst

View company profile →