As Enterprise Security Architect you’ll play a pivotal role in shaping and delivering enterprise-wide cybersecurity initiatives. You’ll lead the design and implementation of secure solutions, guide junior architects, and collaborate with cross-functional teams to embed security into business and technology strategies. This role offers the opportunity to influence enterprise architecture, contribute to policy development, and support a risk-based approach to protecting digital assets - all while staying at the forefront of evolving cyber threats and regulatory standards.
This is a permanent, full-time role that will enjoy hybrid working arrangements.
How You'll Make an Impact:
- Design and establish enterprise application security architecture frameworks, patterns and reference models aligned with business objectives and risk tolerance
- Lead architecture reviews of applications and systems to identify security gaps and recommend appropriate controls
- Architect security solutions for authentication, authorization, encryption, and secure communication channels.
- Develop and maintain security baselines, standards, and patterns for different technology stacks (web, mobile, API, microservices) and deployment models
- Integrate security architecture principles into CI/CD pipelines to support DevSecOps initiatives
- Contribute to the development of enterprise security documentation such as policies, standards, baselines, guidelines, and procedures.
- Provide mentorship and direction to junior security architects
- Manage and participate in the Application Security Champions program
- Collaborate with project leads to define requirements, design controls, and implement scalable security services aligned with cybersecurity vision.
- Partner with business units and enterprise architecture teams to deliver risk-based security guidance and support an integrated security service portfolio.
- Assess security risks across programs, projects, and operational processes, and recommend architecture remediation strategies.
- Stay current on cyber threats and emerging technologies to inform investigation techniques and enhance incident response capabilities.
What you’ll bring to the team:
- Bachelor’s degree in STEM, Computer Science, Engineering, or highly related field.
- 12+ years of experience in IT and/or Information Security
- 5+ years Secure Application Architecture experience developing and maintaining security baselines, standards, and patterns for different technology stacks (web, mobile, API, microservices) and deployment models
- 8+ years hands-on Secure Software development & DevSecOps experience within a formalized SSDLC.
- Extensive knowledge and experience of secure coding practices and working with SAST, DAST, SCA, IAST tools.
- Experience in designing secure architectures e.g. networking, Cloud, IDP, API, tokenization, Identity management (OAuth2, OIDC, SAML), Zero trust Architectures etc.
- Strong understanding of security controls across all layers of the OSI model.
- Penetration testing experience backed up with relevant certifications e.g. OSCP, GPEN etc.
- Experience designing secure systems and integrations with enterprise applications.
- Awareness of Canadian regulatory environments (e.g., OSFI, PIPEDA) and their impact on security programs.
- Experience securing public cloud offerings (Azure is preferred) with relevant Cloud/Security certifications.
- Information Security Certifications in one or more of the following is required: CISSP, CCSP, GISP, GSE,
- Information Technology Certifications in one or more of the following will be an asset: TOGAF, SABSA, CSSLP, GIAC GWEB/GCSA/GWAPT/GDSA/GCSA, Azure Architecture/Security certs.
- Experience with or knowledge of PCI DSS 4.2, ISO 27001, NIST CSF and NIST 800-53 control frameworks is highly desired.
- Strong stakeholder engagement and communication skills across technical and non-technical audiences.
Your Role in Supporting Our Members
As Enterprise Security Architect you’ll play a pivotal role in shaping and delivering enterprise-wide cybersecurity initiatives. You’ll lead the design and implementation of secure solutions, guide junior architects, and collaborate with cross-functional teams to embed security into business and technology strategies. This role offers the opportunity to influence enterprise architecture, contribute to policy development, and support a risk-based approach to protecting digital assets - all while staying at the forefront of evolving cyber threats and regulatory standards.
This is a permanent, full-time role that will enjoy hybrid working arrangements.
How You'll Make an Impact:
- Design and establish enterprise application security architecture frameworks, patterns and reference models aligned with business objectives and risk tolerance
- Lead architecture reviews of applications and systems to identify security gaps and recommend appropriate controls
- Architect security solutions for authentication, authorization, encryption, and secure communication channels.
- Develop and maintain security baselines, standards, and patterns for different technology stacks (web, mobile, API, microservices) and deployment models
- Integrate security architecture principles into CI/CD pipelines to support DevSecOps initiatives
- Contribute to the development of enterprise security documentation such as policies, standards, baselines, guidelines, and procedures.
- Provide mentorship and direction to junior security architects
- Manage and participate in the Application Security Champions program
- Collaborate with project leads to define requirements, design controls, and implement scalable security services aligned with cybersecurity vision.
- Partner with business units and enterprise architecture teams to deliver risk-based security guidance and support an integrated security service portfolio.
- Assess security risks across programs, projects, and operational processes, and recommend architecture remediation strategies.
- Stay current on cyber threats and emerging technologies to inform investigation techniques and enhance incident response capabilities.
What you’ll bring to the team:
- Bachelor’s degree in STEM, Computer Science, Engineering, or highly related field.
- 12+ years of experience in IT and/or Information Security
- 5+ years Secure Application Architecture experience developing and maintaining security baselines, standards, and patterns for different technology stacks (web, mobile, API, microservices) and deployment models
- 8+ years hands-on Secure Software development & DevSecOps experience within a formalized SSDLC.
- Extensive knowledge and experience of secure coding practices and working with SAST, DAST, SCA, IAST tools.
- Experience in designing secure architectures e.g. networking, Cloud, IDP, API, tokenization, Identity management (OAuth2, OIDC, SAML), Zero trust Architectures etc.
- Strong understanding of security controls across all layers of the OSI model.
- Extensive Threat modelling experience.
- Penetration testing experience backed up with relevant certifications e.g. OSCP, GPEN etc.
- Experience designing secure systems and integrations with enterprise applications.
- Awareness of Canadian regulatory environments (e.g., OSFI, PIPEDA) and their impact on security programs.
- Experience securing public cloud offerings (Azure is preferred) with relevant Cloud/Security certifications.
- Information Security Certifications in one or more of the following is required: CISSP, CCSP, GISP, GSE,
- Information Technology Certifications in one or more of the following will be an asset: TOGAF, SABSA, CSSLP, GIAC GWEB/GCSA/GWAPT/GDSA/GCSA, Azure Architecture/Security certs.
- Experience with or knowledge of PCI DSS 4.2, ISO 27001, NIST CSF and NIST 800-53 control frameworks is highly desired.
- Strong stakeholder engagement and communication skills across technical and non-technical audiences.
Disclaimer:
AI may be used in evaluating candidates.
This posting is for an existing vacancy.