Senior Security Architect
Posted · Apply by
Category: IT & Digital Services
Position Details
- Employment Type: Permanent Full Time (Non-Union)
- Closing Date: 2026-09-13
- Work Location: Hybrid
- Department: Information Technology
We offer:
- A hybrid work schedule
- A defined benefit pension plan (OMERS)
- Comprehensive health plan complemented with life and disability insurance
- A progressive work environment that promotes a work/life balance and strives to be a great place for great people to do great things
This job posting is for an existing vacancy and therefore will be filled accordingly.
What Can I Expect To Do In This Role?
Security Architecture & Solution Design
- Lead security architecture reviews for major projects and technology initiatives.
- Develop security reference architectures, standards, patterns and design guidance.
- Review application, infrastructure, cloud and integration designs and provide security recommendations.
- Partner with technical teams to incorporate security requirements into solution designs.
- Serve as the Town's subject matter expert for enterprise security architecture.
Data Security
- Define and maintain enterprise data security architecture, standards, and controls to protect sensitive information throughout its lifecycle.
- Establish security requirements and architecture patterns for data classification, encryption, key management, secrets management, and privacy protection.
- Design and implement data protection capabilities including data loss prevention (DLP), data access governance, and data egress controls across on-premises and cloud environments.
- Develop secure access models and privileged access controls for enterprise data platforms, applications, analytics solutions, and integrations.
- Establish reference architectures and security patterns for data sharing, analytics, AI-enabled solutions, and emerging technologies.
- Partner with business and technology teams to embed security controls and privacy requirements into data-related initiatives and services.
- Lead security reviews and risk assessments of data-centric systems, technologies, and third-party solutions, and drive remediation activities.
- Define and enforce secure data access and protection controls for AI-enabled solutions, with a focus on tenant isolation, data leakage prevention, and regulatory compliance.
Cloud Security & Infrastructure
- Define and maintain enterprise security architecture, standards, and controls across cloud and on-premises environments.
- Establish architecture patterns for identity and access management (IAM), network security, workload isolation, and secure service-to-service communications.
- Design and implement secure cloud foundations, including landing zones, policy-as-code, infrastructure-as-code, and secure CI/CD pipelines.
- Develop and govern cloud access control models, including federation, role-based access control (RBAC), privileged access management, and delegated administration.
- Establish threat modelling and security design review practices for cloud services, applications, and technology initiatives.
- Lead cloud security posture management (CSPM), vulnerability management, and remediation initiatives by defining standards, processes, and technical guidance.
- Ensure security, resiliency, and compliance requirements are incorporated into cloud services, including encryption, logging, monitoring, backup, recovery, and key management.
- Develop reference architectures and security patterns for emerging technologies, including AI-enabled and agentic solutions.
- Partner with technology teams to continuously improve enterprise security capabilities, architecture standards, and operational resilience.
Incident Response Leadership
- Provide senior technical expertise and architectural guidance during cybersecurity incidents.
- Develop and maintain incident response playbooks, procedures, and readiness exercises.
- Lead post-incident reviews and drive security improvements based on lessons learned.
- Support forensic readiness and response planning for emerging threats, including AI-related security incidents.
How Do I Qualify?
- Completion of a minimum three-year diploma or bachelor's degree in Business Administration, Computer Science, Information Systems, or a related field.
- Certifications in CISSP, CISM, CISA, CCIE plus relevant cloud security certifications from Microsoft or AWS.
- Master’s degree in Cybersecurity would be considered an asset.
- Minimum 8 years of progressive information security experience, including hands-on security architecture for enterprise environments.
- Deep expertise in data security concepts and controls (classification, DLP, encryption, key management, access governance, data lifecycle).
- Experience using Microsoft Purview.
- Strong cloud security experience in at least one major cloud provider (e.g., Azure, AWS, GCP), including IAM and platform guardrails.
- Demonstrated incident response leadership experience (technical lead/incident commander role) and familiarity with common IR frameworks and practices.
- Ability to create clear security requirements and guide infrastructure teams through consultation and governance.
- Proficiency in threat modeling, risk assessment, and translating risk into actionable engineering work.
- Strong written and verbal communication skills, including the ability to explain complex security trade-offs to technical and non-technical stakeholders.
Please note that this position requires a satisfactory criminal record check dated within the last 30 days as a condition of employment.
Core Knowledge Required For Success
- Strategic Thinking – thinking things through
- Engagement – working effectively with people, organizations and partners
- Management excellence – delivering results through own work, relationships and responsibilities
- Accountability and Respect – serving with integrity and respect
- Corporate Values: Teamwork, accountability, dedication, honesty, innovation