Enterprise Security Architect

S I Systems

Toronto

Hybrid

CAD 140,000 - 180,000

Full time

40 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

S I Systems is seeking an Enterprise Security Architect to lead the design and delivery of enterprise-wide cybersecurity initiatives in a hybrid Toronto, Canada setting. You will guide secure solutions, mentor junior architects, and align security with business objectives and technology strategy.

You will influence enterprise architecture, contribute to policy development, and support risk-based security programs, staying ahead of evolving threats and regulatory standards.

Qualifications

  • Bachelor’s degree in STEM, Computer Science, Engineering, or related field.
  • 12+ years IT/Information Security experience.
  • 5+ years Secure Application Architecture experience.
  • 8+ years Secure Software development & DevSecOps in SSDLC.
  • Experience with SAST, DAST, SCA, IAST tools.
  • Experience designing secure architectures (networking, Cloud, IDP, API, tokenization, Identity management).
  • Awareness of Canadian regulatory environments (OSFI, PIPEDA).
  • Experience securing public cloud offerings (Azure).
  • Information Security Certifications: CISSP, CCSP, GISP, GSE.

Responsibilities

  • Design and establish enterprise application security architecture frameworks, patterns and reference models aligned with business objectives and risk tolerance.
  • Lead architecture reviews of applications and systems to identify security gaps and recommend appropriate controls.
  • Architect security solutions for authentication, authorization, encryption, and secure communication channels.
  • Develop and maintain security baselines, standards, and patterns for different technology stacks (web, mobile, API, microservices) and deployment models.
  • Integrate security architecture principles into CI/CD pipelines to support DevSecOps initiatives.
  • Contribute to the development of enterprise security documentation such as policies, standards, baselines, guidelines, and procedures.
  • Provide mentorship and direction to junior security architects
  • Collaborate with project leads to define requirements, design controls, and implement scalable security services aligned with cybersecurity vision.
  • Partner with business units and enterprise architecture teams to deliver risk-based security guidance and support an integrated security service portfolio.
  • Assess security risks across programs, projects, and operational processes, and recommend architecture remediation strategies.
  • Stay current on cyber threats and emerging technologies to inform investigation techniques and enhance incident response capabilities.

Skills

Secure Application Architecture
DevSecOps
Threat Modelling
SAST
DAST
SCA
IAST
Cloud Security
Zero Trust Architecture
Stakeholder Communication

Education

Bachelor’s degree in STEM or related field

Tools

Azure

Job description

As Enterprise Security Architect you’ll play a pivotal role in shaping and delivering enterprise-wide cybersecurity initiatives. You’ll lead the design and implementation of secure solutions, guide junior architects, and collaborate with cross-functional teams to embed security into business and technology strategies. This role offers the opportunity to influence enterprise architecture, contribute to policy development, and support a risk-based approach to protecting digital assets - all while staying at the forefront of evolving cyber threats and regulatory standards.

This is a permanent, full-time role that will enjoy hybrid working arrangements.

How You'll Make an Impact:
  • Design and establish enterprise application security architecture frameworks, patterns and reference models aligned with business objectives and risk tolerance
  • Lead architecture reviews of applications and systems to identify security gaps and recommend appropriate controls
  • Architect security solutions for authentication, authorization, encryption, and secure communication channels.
  • Develop and maintain security baselines, standards, and patterns for different technology stacks (web, mobile, API, microservices) and deployment models
  • Integrate security architecture principles into CI/CD pipelines to support DevSecOps initiatives
  • Contribute to the development of enterprise security documentation such as policies, standards, baselines, guidelines, and procedures.
  • Provide mentorship and direction to junior security architects
  • Manage and participate in the Application Security Champions program
  • Collaborate with project leads to define requirements, design controls, and implement scalable security services aligned with cybersecurity vision.
  • Partner with business units and enterprise architecture teams to deliver risk-based security guidance and support an integrated security service portfolio.
  • Assess security risks across programs, projects, and operational processes, and recommend architecture remediation strategies.
  • Stay current on cyber threats and emerging technologies to inform investigation techniques and enhance incident response capabilities.
What you’ll bring to the team:
  • Bachelor’s degree in STEM, Computer Science, Engineering, or highly related field.
  • 12+ years of experience in IT and/or Information Security
  • 5+ years Secure Application Architecture experience developing and maintaining security baselines, standards, and patterns for different technology stacks (web, mobile, API, microservices) and deployment models
  • 8+ years hands-on Secure Software development & DevSecOps experience within a formalized SSDLC.
  • Extensive knowledge and experience of secure coding practices and working with SAST, DAST, SCA, IAST tools.
  • Experience in designing secure architectures e.g. networking, Cloud, IDP, API, tokenization, Identity management (OAuth2, OIDC, SAML), Zero trust Architectures etc.
  • Strong understanding of security controls across all layers of the OSI model.
  • Penetration testing experience backed up with relevant certifications e.g. OSCP, GPEN etc.
  • Experience designing secure systems and integrations with enterprise applications.
  • Awareness of Canadian regulatory environments (e.g., OSFI, PIPEDA) and their impact on security programs.
  • Experience securing public cloud offerings (Azure is preferred) with relevant Cloud/Security certifications.
  • Information Security Certifications in one or more of the following is required: CISSP, CCSP, GISP, GSE,
  • Information Technology Certifications in one or more of the following will be an asset: TOGAF, SABSA, CSSLP, GIAC GWEB/GCSA/GWAPT/GDSA/GCSA, Azure Architecture/Security certs.
  • Experience with or knowledge of PCI DSS 4.2, ISO 27001, NIST CSF and NIST 800-53 control frameworks is highly desired.
  • Strong stakeholder engagement and communication skills across technical and non-technical audiences.
Your Role in Supporting Our Members

As Enterprise Security Architect you’ll play a pivotal role in shaping and delivering enterprise-wide cybersecurity initiatives. You’ll lead the design and implementation of secure solutions, guide junior architects, and collaborate with cross-functional teams to embed security into business and technology strategies. This role offers the opportunity to influence enterprise architecture, contribute to policy development, and support a risk-based approach to protecting digital assets - all while staying at the forefront of evolving cyber threats and regulatory standards.

This is a permanent, full-time role that will enjoy hybrid working arrangements.

How You'll Make an Impact:
  • Design and establish enterprise application security architecture frameworks, patterns and reference models aligned with business objectives and risk tolerance
  • Lead architecture reviews of applications and systems to identify security gaps and recommend appropriate controls
  • Architect security solutions for authentication, authorization, encryption, and secure communication channels.
  • Develop and maintain security baselines, standards, and patterns for different technology stacks (web, mobile, API, microservices) and deployment models
  • Integrate security architecture principles into CI/CD pipelines to support DevSecOps initiatives
  • Contribute to the development of enterprise security documentation such as policies, standards, baselines, guidelines, and procedures.
  • Provide mentorship and direction to junior security architects
  • Manage and participate in the Application Security Champions program
  • Collaborate with project leads to define requirements, design controls, and implement scalable security services aligned with cybersecurity vision.
  • Partner with business units and enterprise architecture teams to deliver risk-based security guidance and support an integrated security service portfolio.
  • Assess security risks across programs, projects, and operational processes, and recommend architecture remediation strategies.
  • Stay current on cyber threats and emerging technologies to inform investigation techniques and enhance incident response capabilities.
What you’ll bring to the team:
  • Bachelor’s degree in STEM, Computer Science, Engineering, or highly related field.
  • 12+ years of experience in IT and/or Information Security
  • 5+ years Secure Application Architecture experience developing and maintaining security baselines, standards, and patterns for different technology stacks (web, mobile, API, microservices) and deployment models
  • 8+ years hands-on Secure Software development & DevSecOps experience within a formalized SSDLC.
  • Extensive knowledge and experience of secure coding practices and working with SAST, DAST, SCA, IAST tools.
  • Experience in designing secure architectures e.g. networking, Cloud, IDP, API, tokenization, Identity management (OAuth2, OIDC, SAML), Zero trust Architectures etc.
  • Strong understanding of security controls across all layers of the OSI model.
  • Extensive Threat modelling experience.
  • Penetration testing experience backed up with relevant certifications e.g. OSCP, GPEN etc.
  • Experience designing secure systems and integrations with enterprise applications.
  • Awareness of Canadian regulatory environments (e.g., OSFI, PIPEDA) and their impact on security programs.
  • Experience securing public cloud offerings (Azure is preferred) with relevant Cloud/Security certifications.
  • Information Security Certifications in one or more of the following is required: CISSP, CCSP, GISP, GSE,
  • Information Technology Certifications in one or more of the following will be an asset: TOGAF, SABSA, CSSLP, GIAC GWEB/GCSA/GWAPT/GDSA/GCSA, Azure Architecture/Security certs.
  • Experience with or knowledge of PCI DSS 4.2, ISO 27001, NIST CSF and NIST 800-53 control frameworks is highly desired.
  • Strong stakeholder engagement and communication skills across technical and non-technical audiences.

Disclaimer:

AI may be used in evaluating candidates.

This posting is for an existing vacancy.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

IT Security Architect
IT Security Architect

Groom & Associés / Associates • Montreal (administrative region)

On-site
CAD 145,000 - 230,000
Unlimited virtual healthcare
Wellness programs
Gender-inclusive paid family leave
+3
Security Architect (ID#5176)
Security Architect (ID#5176)

New Value Solutions • Regina

On-site
CAD 90,000 - 120,000
Security Architect
Security Architect

emergiTEL • Toronto

On-site
CAD 115,000 - 157,000
Security Architect
Security Architect

ISG Search Inc • Toronto

On-site
CAD 120,000 - 180,000
Security Architect (Cybersecurity, Cloud Security, Risk Management, NIST, CISSP)
Security Architect (Cybersecurity, Cloud Security, Risk Management, NIST, CISSP)

Astra-North Infoteck Inc. ~ Conquering today’s challenges, achieving tomorrow’s vision! • Toronto

Hybrid
CAD 140,000 - 195,000
Security Architect
Security Architect

Chartwell Retirement Residences • Mississauga

Hybrid
CAD 120,000 - 170,000
Hybrid working
Minimum 2 office days per week
Occasional after-hours work
Senior Cybersecurity Test Architect
Senior Cybersecurity Test Architect

Myticas Consulting • Ottawa

On-site
CAD 120,000 - 160,000
Enterprise Security Specialist
Enterprise Security Specialist

Cprvision • Whitchurch-Stouffville

Hybrid
CAD 120,000 - 135,000
Flexible working arrangements
Comprehensive benefits package
Annual bonus program
+1
Senior Security Engineer, Enterprise Security
Senior Security Engineer, Enterprise Security

United States Digital Space LLC • Toronto

On-site
CAD 133,000 - 209,000
Full Stack Engineer
Full Stack Engineer

Maplesoft Group, an SEB Company • Toronto

On-site
CAD 100,000 - 130,000