Enable job alerts via email!

Lead Security Architect

FSRA News

Toronto

Hybrid

CAD 88,000 - 129,000

Full time

Yesterday
Be an early applicant

Job summary

A financial services regulator in Toronto is seeking a Lead Security Architect to design secure systems aligned with business goals and industry best practices. This temporary role involves developing enterprise security architecture, leading security risk assessments, and integrating security controls into development pipelines. Candidates should have extensive cybersecurity experience and relevant academic qualifications. The position offers a competitive salary range of $88,496.00 - $128,625.00.

Benefits

Defined benefit pension plan
Comprehensive benefits plan
Investment in personal and professional growth

Qualifications

  • 7+ years experience in cybersecurity focused on security architecture.
  • Experience with security frameworks (NIST CSF, ISO 27001, etc.).
  • Ability to communicate complex security issues to non-technical teams.

Responsibilities

  • Develop and maintain enterprise security architecture.
  • Lead projects for security risk identification and assessments.
  • Integrate security controls into CI/CD pipelines.

Skills

Cybersecurity expertise
Analytical skills
Technical communication
Project management

Education

Bachelor’s or Master’s degree in Cybersecurity, Computer Science, or Information Technology
Professional certifications (CISSP, CISA, CISM, etc.)

Tools

SIEM
IAM
SAST tools
DAST tools

Job description

At FSRA, our vision is to ensure financial safety, fairness, and choice for Ontarians. As a financial services regulator, we’re passionate about protecting consumers. Our principles-based approach means we can quickly and effectively respond to the changing needs of consumers and the industry.

Our team combines industry expertise with commitment to public service. We attract individuals who are interested in meaningful work and who measure success through outcomes, not inputs.

At FSRA, we invest in the personal and professional growth of our team. We offer a competitive compensation package that includes an employer-matched defined benefit pension plan , comprehensive and competitive benefits plan, a hybrid work model and flexible work arrangements. We prioritise learning and development, wellbeing, diversity, equity, inclusion and belonging, and community giving.

Join FSRA and help us shape the future of regulation for generations to come!

Job Description:

*Note - This is a temporary role for approximately 18 months*

Purpose of Position

The Lead Security Architect will work with IT teams , business teams , compliance teams, AI teams and vendor partners to design and implement secure systems and infrastructure aligning with business objectives /goals, regulatory requirements and industry best practices as part of FSRA’s digital transformation effort .

T he Lead Security Architect will e nsure security requirements are embedded across existing and modernized technology stack, including cloud platforms, DevSecOps pipelines, and enterprise applications so that sensitive data and systems remain protected from cyber threats .

Key Responsibilities

The Lead Security Architect ensures that information security strategies and technologies align with organizational goals, regulatory requirements, and industry’s best practices through the following responsibilities:

  • Develop s and maintain s the overall enterprise security architecture and patterns for cloud and hybrid applications, networks, containers, and infrastructure , including designing security solutions, establishing security standards, and creating security roadmaps and ensuring alignment with industry standards , regulatory and compliance requirements, and FSRA’s business and IT strategies.

  • Lead s end-to-end projects related to security risk identification, assessments, security architecture reviews, and threat modeling activities for new and existing systems to mitigate security risks, and develop incident response plans.

  • Define s and maintain s security standards for secure software development at FSRA ; d evelops and recommends short-and long-term security standards and strategies, providing expertise to executive and front-line management

  • Integrates security controls into CI/CD pipelines using DevSecOps best practices .

  • Collaborates with AI/ML and data science teams to integrate security into AI product lifecycle.

  • Provides subject matter expertise , guidance and strategic advice to internal and external stakeholders, including business and IT colleagues to guide the implementation of security frameworks, enable security management and provide recommendations for effective governance.

  • Leads consultations / collaborations with enterprise architects, IT, business, and compliance teams to implement effective security governance ensuring FSRA adheres to relevant security regulations, policies, and industry best practices ; leads consultations and project status meeting s to provide updates, discuss risk and mitigation security strategies .

  • Define s and enforce s secure coding standards and practices across development teams through mentorship, training, and testing .

  • Evaluate s and implement s application security tools for SAST, DAST, and SCA for continuous identif ication, remediat ion, and reporting of software vulnerabilities. Integrate application security tools with other enterprise tools such as SIEM, IAM , ITSM, etc .

  • Respond s to emerging threats by adjusting security architecture and guiding incident response planning.

  • Work s with stakeholders across the organization, including IT teams, business units, and management, to ensure alignment and understanding of security requirements.

  • Prepares reports and delivers presentations to senior management , p rovid ing technical direction to teams and management related to complex security issues .

Qualifications

Education

  • Bachelor’s or M aster’s degree in Cybersecurity, Computer Science, Information Technology, or related fiel d - or a combination of education, training and experience deemed equivalent.

  • Professional certifications such as CISSP, CISA, CISM, SABSA, CCSP, Azure Security Engineer.

Experience

  • 7+ years of progressive experience in cybersecurity, with at least 3 years focused on security architecture , including identifying, assessing, and mitigating security risks .

  • Experience working in regulatory agency or with a regulated financial organization , an asset

Technical/ Core Skills

  • I n-depth knowledge of on-prem and cloud-based technology platforms such as firewalls, operating systems, databases, containers, web services, data lakes, etc.

  • Demonstrated expertise in cybersecurity with the ability to foster security awareness across technical functions and businesses , with proven application of end-to-end cybersecurity architecture .

  • Advanced experience with enterprise IT processes such as patch management, release management, identity and access management, change management, etc.

  • In-depth knowledge of , and experience with , enterprise security standards and frameworks (e.g., SABSA, NIST CSF , ISO 27001, PCI DSS, PIPEDA , CIS , OWASP) , cloud security, application security, and security architecture principles .

  • Proven knowledge and c urrency with emerging threats and technologies and p proficiency with security concepts and technologies (e.g., SBOM, zero-trust, disaster recovery, extended detection & response, application security posture management, identity threat detection & response , quantu m cryptography, encryption, c loud-native security tools, vulnerability scanners, SAST tools, DAST tools ).

  • Strategic influencing skills to present information, insights and recommendations to senior leader s hip on issues related to security standards, risks, strategies and implementation .

  • Demonstrated analytical and strategic thinking skills and be able to synthesize information from multiple sources to determine inter-relationships and security impacts to FSRA’s IT and business; to conduct incident investigation, forensic data analysis, and threat identification.

  • Proficiency in security tools, forensic analysis, and incident detection and response technologies.

  • Proven communication , consultative and advisory skills to act as a lead security resource and be able to communicate complex technical information to both technical and non-technical audiences while clearly articulating risk to the business .

  • Proven project management skills to manage corporate and cross-program security projects and initiatives.

* Please note that this position will close at 11:59PM on September 4, 2025*

Job Posting End Date:

09/04/2025

Job postings close at 11:59pm on the date noted.

Compensation Grade:

Grade 07-AMAPCEO

Compensation Range:

$88,496.00

-

$128,625.00

Bargaining Unit:

AMAPCEO

Job Code:

Job Code: 7A001F

Employment Type:

Fixed Term (Fixed Term)

Scheduled Weekly Hours:

36.25

FSRA is committed to ensuring equity in employment. Our goal is to create a diverse, inclusive workforce that reflects the communities we serve and to ensure our services and communications are accessible to all individuals. Accommodation is available under the Ontario Human Rights Code.

NOTE: ONLY QUALIFIED CANDIDATES WILL BE CONSIDERED

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.

Similar jobs