HPC Security Architect
Listed on 2026-07-14
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Required Qualification
- Bachelor's degree. In lieu of a degree, a combination of directly related full‑time experience in cybersecurity, with experience in research computing or large‑scale distributed systems totaling nine (9) years may be considered.
- Five (5) years of experience in cybersecurity, with experience in research computing or large‑scale distributed systems.
- Experience in NIST 800‑171, HIPAA, and regulated data environments.
- Experience with Identity and Access Management architectures.
- Experience with Network and system security design.
- Experience with Linux systems, high‑performance networking, and storage architectures.
- Experience with translating complex regulatory requirements into technical implementations.
- Advanced degree (foreign equivalent or higher).
- Experience supporting HPC environments or research infrastructure.
- Experience in AI/ML security, model governance, and data provenance.
- Experience with federated identity (InCommon, SAML, OIDC) and research collaboration frameworks.
- Certified in CISSP, CISM, CCSP, or similar.
The HPC Security Architect leads the design, implementation, and governance of security architecture across Stony Brook University's advanced research computing ecosystem, including AMA
27, Sea Wulf, NVWulf, and Clin Wulf. This role establishes a comprehensive, risk‑based security framework ensuring compliance with HIPAA, NIST 800‑171, NIH GDS, and emerging AI governance standards. The incumbent operates at the intersection of research enablement and enterprise security, partnering with the Division of Information Technology (DoIT), Stony Brook Medicine IT (SBMIT), Research Security, IRB, and faculty to embed secure‑by‑design principles across compute, storage, data workflows, and collaborative research environments.
The HPC Security Architect must effectively communicate with others.
- Design and maintain a multi‑tier security architecture for research computing environments spanning Sea Wulf, NVWulf, Clin Wulf, and AMA
27 (NSF Tier‑1 HPC). - Define reference architectures for secure compute, storage (GPFS/Arcastream), and high‑speed networking (Infini Band).
- Establish segmentation strategies (network, identity, workload isolation) across research tiers.
- Lead adoption of zero trust principles in HPC and research environments.
- Align HPC security strategy with institutional and SUNY‑wide initiatives (e.g., Empire AI).
- Lead implementation of security controls aligned to HIPAA Security Rule, NIST 800‑171/CMMC, NIH Genomic Data Sharing (GDS) Policy, and federal export control requirements.
- Partner with Research Security, Privacy, IRB, and Legal to define compliant research computing patterns and support Data Use Agreements (DUAs).
- Enable secure data acquisition, storage, and sharing workflows.
- Develop and maintain System Security Plans (SSPs) and supporting documentation for regulated environments.
- Architect and enforce identity and access management (IAM) integration (e.g., SailPoint, federated access, MFA).
- Implement role‑based and attribute‑based access controls for HPC and research datasets.
- Define secure onboarding workflows for faculty, research staff, external collaborators, and federated/national computing environments (e.g., NSF ACCESS, Empire AI).
- Oversee data protection strategies, including encryption, key management, and secure data lifecycle controls.
- Design and operationalize tiered secure research environments (open, restricted, regulated).
- Collaborate with Data Brokerage and Honest Broker services to ensure privacy‑preserving data access.
- Define secure data pipelines for clinical data (EMR integrations, TriNetX, OnCore/Cerner RPE), genomic and imaging data, and large‑scale AI/ML datasets.
- Establish controls for secure collaboration and data sharing, including external access frameworks.
- Conduct threat modeling for HPC and AI workloads, including supply chain and model security risks.
- Lead risk assessments for new research initiatives and infrastructure deployments.
- Partner with…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).