Director, Product Security Architect

Spectrum Equity

Toronto

Hybrid

CAD 138,000 - 181,000

Full time

19 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Health & Wellness
PTO & Holidays
Volunteer days
Tuition assistance
Flexible work options

Job summary

Varicent Software in Toronto, ON seeks a highly technical Director, Product Security Architect to embed secure-by-design across our SaaS and AI products. You will lead product security architecture, threat modeling, and security reviews while partnering with Engineering, Cloud Operations, AI, and Security teams to build scalable, secure solutions.

This leadership role reports to the VP/CISO and requires 10+ years of InfoSec, plus cloud security and DevSecOps expertise.

Qualifications

  • 10+ years in Information Security, with hands-on Product/AppSec leadership.
  • 3+ years in Application Security Architecture and Threat Modeling.
  • 3–5 years of Software Development or Software Engineering experience.
  • Strong understanding of secure design, cloud security, and modern software architectures.
  • Experience with DevSecOps, secure SDLC practices, and AI-enabled development environments.
  • Expertise in threat modeling methodologies such as STRIDE, CAPEC, and MITRE ATT&CK.
  • Experience securing web, API, mobile, cloud-native, and AI-enabled applications.
  • Knowledge of AWS, Azure, or IBM Cloud security architectures.
  • Strong communication skills with ability to influence stakeholders.
  • Certifications such as ISC2 ISSAP, CISSP, CSSLP, OSCP are assets.

Responsibilities

  • Define and execute the Product Security Architecture and Secure-by-Design strategy.
  • Establish secure reference architectures, design standards, and secure patterns for cloud-native and AI-enabled solutions.
  • Partner with Engineering and Product teams to embed security into development workflows and system design decisions.
  • Drive adoption of secure-by-design best practices by embedding security requirements in epics, user stories, and the AI SDLC.
  • Produce threat modeling artifacts and remediation guidance across critical applications and AI systems.
  • Lead threat modeling activities and translate threats into actionable security requirements.

Skills

InfoSec leadership
AppSec & threat modeling
Software development
Cloud security
DevSecOps
Threat modeling (STRIDE/CAPEC)
Web/API/Mobile security
AWS/Azure/IBM Cloud
Security communication
Security certifications (assets)

Tools

AWS security
Azure security

Job description

Varicent Software

Product, IT

Toronto, ON, Canada

CAD 138,200-181,400 / year

Posted on Aug 20, 2026

At Varicent, We’re Not Just Transforming The Sales Performance Management (SPM) Market—we’re Redefining How Organizations Achieve Revenue Success. Our Cutting-edge SaaS Solutions Empower Revenue Leaders Globally To Design Smarter Go-to-market Strategies, Maximize Seller Performance, And Unlock Untapped Potential. Varicent Stands At The Forefront Of Innovation, Celebrated As a Market Leader In The 2025 Forrester Wave Report For SPM, 2023 Ventana Research Revenue Performance Management (RPM) Value Index, Gartner Peer Insights, 2024 Gartner SPM Market Guide, And G2. Our Solutions Are Trusted By a Diverse Range Of Global Industry Leaders Like T-Mobile, ServiceNow, Wawanesa Bank, Shaw Industries, Moody's, Stryker And Hundreds More. Here’s Why You’ll Thrive At Varicent

  • Innovate with Purpose: Build impactful solutions for customers worldwide.
  • Join Excellence: Work in a diverse, collaborative, and innovative team.
  • Shape the Future: Lead in redefining revenue optimization.
  • Grow Together: Unlock your potential in a supportive environment.

Join us at Varicent—where your talent and ambition meet limitless opportunities for success!

About The Role

We're looking for a highly technical and hands-on Director, Product Security Architect to help shape secure-by-design principles across our SaaS products, cloud platforms, and AI-enabled products. This role is deeply embedded in Product and Engineering, with a focus on identifying and eliminating architectural risk before it reaches production.

In this role, you'll partner closely with Engineering, Product, Cloud Operations, Architecture, AI, and Security teams to embed security early in the software development lifecycle. You'll lead product and application security architecture, threat modeling, secure design reviews, and AI security initiatives while helping teams build scalable, resilient, and secure solutions.

This is a highly technical product security role requiring deep hands‑on experience with software architecture, threat modeling, and secure design, as well as the ability to translate security risks into practical engineering solutions.

This is a highly visible leadership role reporting directly to the VP & Chief Information Security Officer.

What You'll Do
Lead Product Security Architecture & Secure-by-Design
  • Define and execute the Product Security Architecture and Secure-by-Design strategy and roadmap.
  • Establish secure reference architectures, design standards, and secure patterns for cloud-native and AI-enabled solutions.
  • Partner with Engineering and Product teams to embed security into development workflows and system design decisions.
  • Drive adoption of secure-by-design best practices by embedding security requirements in epics, user stories, and the AI SDLC.
Drive Threat Modeling & Risk Analysis
  • Produce actionable threat modeling artifacts including data flow diagrams, trust boundary analysis, abuse cases, attack paths, security requirements, technical specifications, design risks, remediation actions, and residual risk documentation.
  • Analyze recurring vulnerabilities, penetration test results, incident learnings, and security assessment findings to identify systemic design flaws and improve secure architecture standards.
  • Lead threat modeling activities across critical applications, platforms, and AI-enabled systems.
  • Identify architectural risks, attack paths, abuse cases, and trust boundary concerns.
  • Translate threats into actionable security requirements, architectural recommendations, and remediation guidance, partnering directly with engineering teams to implement and validate design changes.
  • Build reusable threat models, security patterns, and design libraries that scale across engineering teams.
Partner with Engineering Teams
  • Guide teams on secure design principles, risk-based decision making, and security tradeoffs.
  • Review distributed systems, microservices, cloud-native architectures, APIs, mobile applications, and identity solutions.
  • Support remediation efforts and validate architectural fixes for security findings and design flaws.
Secure Cloud & AI Platforms
  • Conduct architecture reviews across AWS, Azure, and IBM Cloud environments.
  • Assess containerized, Kubernetes, serverless, and AI-enabled architectures.
  • Define cloud security and AI guardrails, governance models, and secure deployment patterns.
  • Partner with AI teams to evaluate security risks within LLM-enabled products and agentic workflows.
Influence Across the Organization
  • Represent Security while collaborating with Product, Engineering, Software Architecture, Cloud, and Legal stakeholders.
  • Develop security standards, training, and architecture guidance.
  • Communicate architectural risk and security recommendations to technical and executive audiences.
What You'll Bring
  • 10+ years of Information Security experience, with significant hands‑on experience in Product Security, Application Security, Security Architecture, or Software Security Engineering.
  • 3+ years of hands‑on Application Security Architecture and Threat Modeling experience.
  • 3–5 years of Software Development or Software Engineering experience.
  • Strong understanding of secure application design, cloud security, and modern software architectures.
  • Experience with DevSecOps, secure SDLC practices, and AI-enabled development environments.
  • Expertise in threat modeling methodologies such as STRIDE, CAPEC, and MITRE ATT&CK.
  • Experience securing web, API, mobile, cloud-native, and AI-enabled applications.
  • Knowledge of AWS, Azure, or IBM Cloud security architectures.
  • Strong communication skills with the ability to influence stakeholders at all levels.
  • Certifications such as ISC2 ISSAP (Information Systems Security Architecture Professional), CISSP, CSSLP, OSCP, or relevant cloud security certifications are considered an asset.
What Success Looks Like
First 90 Days
  • Assess current architecture, development processes, and secure design maturity.
  • Build relationships across Product, Engineering, Architecture, Cloud, and Security stakeholder teams.
  • Identify high-priority risks and opportunities to improve secure-by-design adoption.
  • Establish a roadmap for threat modeling and to embed secure design requirements in the AI SDLC workflow.
6+ Months
  • Standardize and embed threat modeling and architecture review processes within the AI SDLC.
  • Embed security requirements into engineering and AI development workflows.
  • Expand automated security architecture and design validation capabilities.
Long-Term
  • Scale secure-by-design practices across all products and platforms.
  • Mature security architecture risk management and AI security governance.
  • Enable measurable reductions in security risk through proactive secure design and engineering practices.

For this role, the estimated annual base salary range is between $138,200.00 - $181,400.00 CAD. In addition to base salary, our compensation package may include bonuses, commissions for eligible sales roles, and a comprehensive benefits package. The actual base salary will vary based on factors including individual qualifications and market data, as objectively assessed during the interview process.

This posting is for a new vacancy.

This hiring process utilizes artificial intelligence tools to assist in candidate screening and assessment. Our AI tools are designed to complement — not replace — human decision-making.

Overview Of Benefits
  • Health & Wellness — Comprehensive medical, dental, and vision coverage tailored to your local needs
  • Time Off — PTO and public holidays to rest, recharge, and do what matters most
  • Volunteer Days — Dedicated time to give back and support the communities that matter to you
  • Ignite Days — Dedicated learning days to support continuous growth, skill development, and professional learning
  • Financial — Compensation that reflects your market and your value
  • Retirement — Retirement plans designed to help you build long‑term financial security
  • Tuition Assistance — Invest in your growth with support for continuing education and professional development
  • Flexibility — Work where you thrive, with remote and hybrid options available across most regions

Varicent is committed to creating a diverse environment and is proud to be an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability, age, or veteran status. If you require accommodation at any time during the recruitment process please email accomodations@varicent.com

Varicent is also committed to compliance with all fair employment practices regarding citizenship and immigration status. By applying for a position at Varicent and/or by using this portal, you declare and confirm that you have read and agree to our Job Applicant Privacy Notice and that the information provided by you as part of your application is true and complete and includes no misrepresentation or material omission of fact

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Director, Product Security Architect
Director, Product Security Architect

Varicent • Toronto

On-site
CAD 138,000 - 181,000
Health & Wellness
Time Off
Volunteer Days
+5
Senior Product Manager - AI
Senior Product Manager - AI

FunnelCake • Vancouver

On-site
CAD 125,000 - 165,000
Senior Product Manager - AI
Senior Product Manager - AI

Varicent • Toronto

On-site
CAD 121,200 - 159,000
Senior Product Manager - AI
Senior Product Manager - AI

FunnelCake • Toronto

On-site
CAD 121,000 - 159,000
Staff Software Engineer – Backend (Typescript / .Nodejs / AWS )
Staff Software Engineer – Backend (Typescript / .Nodejs / AWS )

Doist • Calgary

On-site
CAD 121,000 - 159,000
Health & Wellness
Time Off
Volunteer Days
+5
Business Development Representative
Business Development Representative

Spectrum Equity • Toronto

Hybrid
CAD 66,000 - 87,000
Health & Wellness
Time Off
Volunteer Days
+5
Senior Talent Acquisition Advisor
Senior Talent Acquisition Advisor

FunnelCake • Toronto

Hybrid
CAD 80,000 - 105,000
Health & Wellness
Time Off
Volunteer Days
+5
Senior Talent Acquisition Advisor
Senior Talent Acquisition Advisor

Varicent Corporation • Toronto

Hybrid
CAD 80,000 - 105,000
Health & Wellness
Time Off
Volunteer Days
+5
Senior Talent Acquisition Advisor
Senior Talent Acquisition Advisor

Varicent • Toronto

On-site
CAD 80,000 - 105,000
Health & Wellness
Time Off
Volunteer Days
+5
Senior IT Technical Support Specialist
Senior IT Technical Support Specialist

FunnelCake • Toronto

On-site
CAD 92,000 - 116,000
Health & Wellness
Time Off
Volunteer Days
+4