Cyber Security Solutions Architect
- Location: Ottawa, Ontario
- Remote: Remote
- Type: Contract
- Job #35515
Our client, a leading Canadian financial institution, is seeking an experienced Cyber Security Solutions Architect to support its Cyber Resilience Transformation Program.
This is an excellent opportunity for a senior cyber security professional with expertise in enterprise security architecture, cloud security, technology risk, DevSecOps, and secure solution design within highly regulated environments.
The successful consultant will provide strategic cyber security advisory services while helping shape secure architectures, improve governance, strengthen technology risk management, and support enterprise-wide cyber resilience initiatives.
Key Responsibilities
Reporting to the Assistant Director, Cyber Resilience Transformation Program, you will:
- Provide cyber security architecture and technology risk advisory services
- Assess current and target-state security architectures across cloud and on-premises environments
- Identify security risks, vulnerabilities, and compliance gaps across applications, infrastructure, and emerging technologies
- Design and govern enterprise security controls, including:
- Identity & Access Management (IAM)
- Network Security
- Data Protection
- Logging & Monitoring
- Develop security standards, reference architectures, reusable design patterns, and security building blocks
- Support secure cloud implementations, application security, and DevSecOps practices
- Lead and facilitate threat modelling activities across enterprise applications and platforms
- Enhance secure software development lifecycle (Secure SDLC) processes
- Support vulnerability management, security testing, and remediation planning
- Provide guidance on:
- SAST
- DAST
- Container Security
- Dependency Scanning
- Support the responsible adoption of AI within cyber security practices, including AI risk assessments and AI-enabled security capabilities
- Translate technical risks into meaningful business impacts and actionable recommendations
- Produce executive-level documentation, architecture artifacts, and governance reports
- Deliver workshops, knowledge transfer sessions, and technical guidance to development and business teams
Required Qualifications
- University degree or College diploma in Computer Science, Cyber Security, Information Security, Engineering, or a related discipline
- Minimum 5 years of recent experience in Information Technology and/or Cyber Security
- Minimum 3 years of recent experience as:
- Cyber Security Architect
- Senior Security Specialist
- Experience working within complex, highly regulated enterprise environments
- Demonstrated experience:
- Assessing current-state security posture
- Designing target-state security architectures
- Designing and governing enterprise security controls
- Performing security and technology risk assessments
- Identifying compliance and control gaps
- Developing enterprise security standards and reusable architecture artifacts
Technical Expertise
Strong experience with:
- Security Architecture
- Cloud Security
- Enterprise Security Controls
- IAM
- Network Security
- Data Protection
- Logging & Monitoring
- DevSecOps
- Secure SDLC
- Threat Modelling
- Vulnerability Management
- Security Testing
- SAST
- DAST
- Container Security
- Dependency Scanning
- Technology Risk Management
- AI Security Considerations
- Governance & Compliance
Nice-to-Have
Experience with:
- NIST Cyber Security Framework (CSF)
- NIST SP 800-53
- NIST SP 800-61
- NIST SP 800-92
- ISO 27001 / ISO 27002
- TOGAF
- SABSA
- Financial Services Security Architecture
- Third-Party Risk Management
Preferred Certifications
One or more of:
- CISSP
- CCSP
- CISM
- AWS Security Certifications
- Microsoft Azure Security Certifications
Work Arrangement
- Fully Remote within Canada
- Full-time (37.5 hours/week)
Mandatory Requirements
Candidates must:
- Be eligible to obtain Bank of Canada Secret Security Clearance
- Have resided in Canada for a minimum of 5 years
- Possess excellent communication and stakeholder management skills
- Be capable of presenting technical cyber security concepts to both technical and executive audiences
Candidates must also have:
- Windows 11 device capable of connecting through Azure Virtual Desktop
- Smartphone capable of running Microsoft Authenticator