Cyber Security Architect

Aviva plc

Markham

Hybrid

CAD 140,000 - 190,000

Full time

3 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Hybrid work model
Bonus eligibility
Retirement savings plan
Health benefits
Career development

Job summary

Aviva Canada is seeking a Cyber Security Architect to define and assure security across on-premises, cloud, and hybrid infrastructure. You will collaborate with Infrastructure, Cyber Security, Engineering, Risk, and delivery teams to embed security by design.

You will provide leadership on data centres, networks, AD, SIEM, AI security, and resilience, guiding teams through design reviews and incident response planning in a large, regulated environment.

Qualifications

  • 5+ years in Cyber Security Architecture.
  • Strong cloud and hybrid security experience (AWS) including IAM, KMS, and GuardDuty.
  • Knowledge of AI security for LLMs, RAG, and AI tooling.
  • Familiarity with OWASP/ATLAS/NIST AI risk guidance.

Responsibilities

  • Define and maintain security architecture across on-prem, cloud, and hybrid infra.
  • Embed security by design and guide engineering teams.
  • Lead security reviews, threat modeling, and incident response planning.
  • Oversee AI security governance and risk management.
  • Collaborate with risk, cyber operations, and governance teams.

Skills

Security architecture
Hybrid infrastructure
Cloud security (AWS)
Zero Trust
AI security

Tools

SIEM
SOAR
XDR
EDR
NDR
IAM / KMS

Job description

Individually we are people, but together we are Aviva. Individually these are just words, but together they are our Values – Care, Commitment, Community, and Confidence. At Aviva Canada, we put people first, our employees, our customers, and our communities. We’re proud of a culture built on care, inclusion, and collaboration, where your voice matters and your growth is supported. We’re not just about insurance; we’re about making a real difference by protecting what matters most.

The Cyber Security Architect is responsible for defining, designing, and assuring security architecture across the organization’s on-premises and hybrid technology estate. The role will work closely with Infrastructure, Cyber Security, Engineering, Risk, and delivery teams to ensure security is embedded by design and that solutions meet enterprise security, resilience, privacy, and regulatory requirements.

What you’ll do

Work with the Cybersecurity team to define and maintain security architecture, standards, reference patterns, and roadmaps for on-premise, cloud, and hybrid infrastructure. Embed cybersecurity requirements (‘security by design’) early in initiatives during the early design phases and subsequently assist the Security Advisory team on later stage cybersecurity assessments of initiatives. Provide security architecture leadership for data centres, cloud, networks, servers, storage, virtualization platforms, databases, middleware, end-user computing, and infrastructure management services. Design and assure security controls across core infrastructure, including network services, servers, Active Directory, virtualization, storage, backup and recovery, cyber vault, endpoint protection, encryption, key management and third-party connectivity. Perform security design reviews, and technical guidance to engineering, data science, and platform teams. Partner with Cyber Operations to ensure infrastructure designs support effective monitoring, logging, detection, incident response, and recovery using SIEM, SOAR, XDR, EDR, NDR, IDS/IPS, and related security capabilities. Support cyber resilience initiatives, including immutable backup, privileged recovery, infrastructure recovery, ransomware containment, and recovery testing. Assess and guide the security of the organization’s growing AI footprint, including AI platforms, AI-assisted development tools, and their integrations with enterprise infrastructure. Define appropriate AI security guardrails covering identity and access, data protection, prompt and context security, model and tool integration, logging, monitoring, human oversight, and incident response. Evaluate AI-related threats such as prompt injection, sensitive-data leakage, model or knowledge-source poisoning, excessive agent privileges, insecure tool use, rogue agent behaviour, and unsafe AI-generated code. Stay on the forefront of cyber – keep up-to-date with the latest trends and technologies to evaluate how they would address the evolving threat landscape. Provide technical leadership, coaching, and guidance to architects, engineers, project teams, and external delivery partners. Monitor emerging infrastructure and AI security threats, assess their relevance to the organization, and recommend pragmatic changes to security architecture and controls.

What you’ll bring

Extensive experience (5+ years) in Cyber Security Architecture with strong and demonstrable focus on hybrid infrastructure ecosystem in a large/complex enterprise. Work experience (2+ years) in cloud and hybrid security, particularly AWS, including IAM, KMS, GuardDuty, Security Hub, Private Link, WAF, CloudTrail, and network security controls. Strong hands‑on knowledge of on-premises infrastructure security across enterprise networking, identity and access services, Windows/Linux servers, virtualization platforms, storage, backup, cyber recovery, endpoint security, vulnerability management, patching, certificates, encryption, and key management. Solid understanding of Zero Trust, Defense-in-Depth, network isolation, least privilege, secure administration, and privileged‑access controls. Exposure to security operations technologies and processes, including SIEM, SOAR, XDR, EDR, NDR, logging, detection engineering, threat hunting, and incident-response playbooks. Good understanding of cyber resilience and recovery architecture, including ransomware containment, backup integrity, clean‑room recovery, identity recovery, and recovery validation. Knowledge of AI and Generative AI security, including LLMs, RAG, vector databases, embeddings, AI agents, tool use, AI‑assisted code generation, prompt injection, data leakage, model and RAG poisoning, agent privilege escalation, insecure tool integration, AI supply‑chain risk, and security controls for prompts, context, embeddings, memory, outputs, knowledge sources, models, plugins, tools, and supporting infrastructure. Familiarity with AI security guidance such as the OWASP Top 10 for LLM Applications, OWASP Agentic AI guidance, MITRE ATLAS, and the NIST AI Risk Management Framework. Ability to assess AI solutions from an enterprise infrastructure perspective, including hosting, network connectivity, identity, data flows, isolation, monitoring, resilience, and integration dependencies. Ability to balance strategic target‑state architecture with practical short‑term delivery needs and infrastructure constraints. Strong analytical and problem‑solving skills, with the ability to translate complex cyber risks into clear design decisions and actionable recommendations. Excellent written and verbal communication skills, with the ability to influence engineers, architects, delivery leaders, risk partners, and executive stakeholders.

What makes you stand out

Experience working within financial services, insurance, or another highly regulated industry is preferred. Relevant certifications an asset: CISSP (or CISSP‑ISSAP), SABSA, AWS Certified Security – Specialty, CCSP, and emerging AI/GenAI security certifications. Proven ability to design and govern enterprise security architectures, champion security‑by‑design, and collaborate across business and technology teams to deliver secure solutions aligned with cybersecurity strategy, governance, and Aviva security standards.

What you’ll get
  • The salary band for this position ranges from $140,000 to $190,000. Please note that individual salary is determined by factors such as job‑related knowledge, skills and experience, as well as internal equity.
  • Compelling rewards package including base compensation, eligibility for annual bonus, retirement savings, share plan, health benefits, personal wellness, and volunteer opportunities.
  • Outstanding Career Development opportunities. We’ll support your professional development education.
  • Competitive vacation package with the option to purchase 5 extra days off per year.
  • Employee driven programs focused on gender, LGBTQ+, origins, diversity, and inclusion.
  • Corporate wellness programs to support our employees’ physical and mental health.
  • Employee discount on home and auto insurance (where applicable).
  • Hybrid flexible work model.

This job advertisement is for a new vacancy which has been posted both internally & externally. Aviva Canada may use AI (Artificial Intelligence) tools to assist us throughout the recruitment process to screen, assess or select applicants for a position. Aviva Canada welcomes applications from all qualified individuals and has a process in place to provide accommodations for persons with disabilities at all stages of the hiring process and during employment. If you require an accommodation during the interview or hiring process, please contact your Aviva Talent Acquisition Partner so that an appropriate accommodation can be arranged.

#LI-PS1 #LI-Hybrid We help our 19.5 million customers to save for the future and manage the risks of everyday life. To give these customers the best possible products and service we know we must make Aviva the most attractive choice for talented, entrepreneurial people with diverse backgrounds and an evolving range of expertise and insight. So, we’re passionate about helping our 23,000 people to do the best work of their lives, to enable them to make a positive difference to the lives of our customers.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cybersecurity Advisor
Cybersecurity Advisor

Aviva Canada • Markham

Hybrid
CAD 80,000 - 105,000
Annual bonus
Health benefits
Career development
+5
Cybersecurity Advisor
Cybersecurity Advisor

Aviva plc • Markham

On-site
CAD 80,000 - 105,000
Annual bonus
Retirement savings plan
Health benefits
+2
AVP, Technology and Transformation Risk
AVP, Technology and Transformation Risk

Aviva plc • Markham

Hybrid
CAD 180,000 - 240,000
Hybrid flexible work model
Bonus eligibility & retirement savings
Health benefits & wellness programs
+3
Vice President, Technology and Transformation Risk
Vice President, Technology and Transformation Risk

Aviva plc • Markham

Hybrid
CAD 180,000 - 280,000
Executive compensation
Pension plan
Hybrid work model
+3
Data Engineer - AWS, Snowflake, DBT
Data Engineer - AWS, Snowflake, DBT

Aviva plc • Markham

On-site
CAD 115,000 - 135,000
Base salary 115k–135k CAD
Annual bonus eligibility
Retirement savings
+8
Frontend Technologies Architect
Frontend Technologies Architect

Aviva Canada • Markham

On-site
CAD 140,000 - 190,000
Base salary
Annual bonus
Retirement plan
+7
Vice President, Technology and Transformation Risk
Vice President, Technology and Transformation Risk

Aviva • Markham

Hybrid
CAD 180,000 - 270,000
Competitive compensation
Pension & retirement savings
Flexible hybrid work
+5
Frontend Technologies Architect
Frontend Technologies Architect

Aviva Canada • Toronto

On-site
CAD 140,000 - 190,000
Hybrid work model
Annual bonus
Retirement plan
+4
Finance and Data Solution Architect
Finance and Data Solution Architect

Aviva • Markham

Hybrid
CAD 140,000 - 190,000
Base salary
Annual bonus
Retirement plan
+5
AVP, Insurance Risk
AVP, Insurance Risk

Aviva plc • Markham

Hybrid
CAD 150,000 - 230,000
Executive compensation
Pension and retirement savings
Hybrid work model
+5