Overview

Security Specialist Jobs in United States at Impelsys

Title: Security Specialist

Company: Impelsys

Location: United States

Role Summary

The Security Specialist will own the security architecture and review process for the vLEI implementation. This includes evaluating cryptographic primitives underpinning the credential chain, reviewing network design for containerized (Kubernetes) deployments, ensuring compliance with healthcare security frameworks, and providing assurance that the integration meets health plan security requirements. The role bridges deep cryptographic expertise with practical healthcare security compliance.

Key Responsibilities

  • Design and review the security architecture for the vLEI credential chain: organization credentials, person credentials, purpose-of-use credentials, and dynamic client registration credentials
  • Evaluate cryptographic implementations including key management, digital signatures, and hash-based data integrity mechanisms used in the credential infrastructure
  • Conduct security assessments of the authorization server reference implementation and its Dockerized/Kubernetes deployment model
  • Review network design for health plan integration points, including both server-side (accepting connections) and client-side (outgoing connections) trust establishment
  • Ensure alignment with healthcare security standards including HIPAA Security Rule, HITRUST CSF, and NIST 800-53 controls relevant to identity and access management
  • Assess FAST Security framework compliance for the credential-based authentication model
  • Support health plan security review processes and provide documentation required for their approval workflows
  • Advise on threat modeling for decentralized identity infrastructure in a multi-payer healthcare network
  • Document security controls, risk mitigations, and residual risk acceptance recommendations.

Required Qualifications

  • 7+ years of experience in information security with at least 3 years focused on healthcare environments
  • Deep understanding of public key infrastructure (PKI), digital signatures, key management lifecycles, and modern cryptographic protocols
  • Experience with network security design for containerized environments (Docker, Kubernetes) in enterprise or regulated settings
  • Familiarity with identity and access management protocols: OAuth 2.0, OpenID Connect, SAML, and client credential flows
  • Working knowledge of HIPAA Security Rule requirements, HITRUST CSF, or NIST 800-53 security controls
  • Experience conducting security architecture reviews and threat modeling for distributed systems
  • Strong documentation skills for security review artifacts, risk registers, and compliance evidence
  • CISSP, CISM, CEH, or equivalent security credential

Preferred Qualifications

  • Experience with decentralized identity technologies, verifiable credentials (W3C VC), or self-sovereign identity architectures
  • Familiarity with vLEI (Verifiable Legal Entity Identifier), KERI (Key Event Receipt Infrastructure), or similar identity ecosystems
  • Knowledge of FAST Security Trust Framework and its application to healthcare credential exchange
  • Experience with TEFCA security requirements or Qualified Health Information Network (QHIN) security assessments
  • Background in zero-trust architecture design for healthcare data exchange networks
  • Experience supporting security reviews for large health plans, PBMs, or pharmacy benefit organizations

Engagement Structure

This is a part-time contract engagement at 24 hours per week for an initial 12-week term. This may expand into a full-time engagement. The Security Specialist operates within the Business Partner delivery team, working closely with the Integration Engineers and Technical PM. The role includes direct participation in health plan security review processes and may extend as the engagement model is replicated for additional payers.

Upload your CV/resume or any other relevant file. Max. file size: 800 MB.