Jobs and Careers
ED

Senior Architect, Information Security

Edwards Lifesciences
USA-California-Remote, United StatesRemotefull_timeVerifiedPosted 24 Jul 2024
💰 $196,000/yr($138,000/yr$196,000/yr)

About the role

Innovation starts from the heart. Making a meaningful difference to patients around the world. At Edwards Lifesciences, we’re dedicated to developing ground-breaking technologies with a genuine impact on patients’ lives. At the core of this commitment is our investment in cutting-edge information technology. This supports our innovation and collaboration on a global scale, enabling our diverse teams to optimize both efficiency and success. As part of our IT team, your expertise and commitment will help facilitate our patient-focused mission by developing and enhancing technological solutions.

This Sr. Security Architecture position will support cybersecurity risk management by designing, developing or recommending secure solutions, including policy, standards, processes, applications, systems, architectures, and infrastructure that are operationally viable and efficient. Ensure appropriate application of security products and technologies to protect Edwards’ systems and information and enable achievement of Edwards’ business objectives. Perform analysis of emerging cybersecurity frameworks and best practices, architectures and solutions to enforce secure policy/standards conformance.

Position Accountability / Scope - Reports to Sr. Manager of Governance, Risk & Compliance. The scope of this position is Edwards wide and considers the information security implications unique to all Edwards divisions when developing governance and risk management strategies.

You will make an impact by…

  • Developing a cyber security risk management service which meets regulatory requirements and aligns with industry leading information security practices.

  • Planning and executing  Tier 2 and Tier 3 risk assessment by using threat modelling techniques and recommend mitigating activities using industry leading security controls and tool sets.

  • Developing risk taxonomy, methodology and framework that can used to assess, communicate and manage cyber risks across IT and non-IT business units.

  • Reporting top security risk to security and IT leadership team monthly.

  • Initiating the lead for crown jewel assessments to identify critical business processes and application

  • Performing controls monitoring activities for critical controls identified during Tier 2 (Enterprise wide) and Tier 3 (application specific) risk assessments

  • Collaborating with business units, application development teams, and third-party vendors to achieve program requirements while enabling the business.

  • Defining  and executing creation of KRI’s that align with top cyber risks

  • Defining and executing service KPI’s for the risk management service to demonstrate risk identification and mitigation

  • Developing strategies, policy and standards to protect company information and technology assets.

  • Applying technical knowledge to protect the company against cyber threats (e.g., knowledge of firewalls, intrusion detection and prevention systems, data loss prevention solutions, endpoint protections, log aggregation technology and other leading-edge security technologies).

  • Facilitating cross team coordination to achieve defined security goals and meet technical requirements in support of detailed implementation plans for security projects.

What you’ll need (Required):

  • Bachelor's Degree in information security, Computer Science, Computer Engineering or related field; or equivalent experience

  • Plus 10 years of previous professional IT experience Required

What else we look for (preferred):

  • Technical knowledge on how to identify and implement security requirements during architecture reviews

  • Possess expertise in valuing and implementing industry standards such as the ISO 27001/2, SOC 2, NIST CSF, HITRUST and FedRAMP Information Security standard.

  • Experience with implementation and operational use of GRC toolsets (Governance Risk and Compliance)

  • Experience in assess and managing risk in manufacturing and IT environments

  • Possess CISSP certification (or similar) and knowledge of national and international regulatory compliances and frameworks such as ISO, SOX, BASEL II, EU DPD, HIPAA, and PCI DSS.

  • Excellent organization and time management skills

  • Excellent verbal and written communication skills and customer focused skills

  • Ability to manage competing priorities in a fast paced environment

  • Adhere to all company rules and requirements (e.g., pandemic protocols, Environmental Health & Safety rules) and take adequate control measures in preventing i

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Edwards Lifesciences

View company profile →