Senior Cybersecurity Test Architect

  • Location: Ottawa, Ontario
  • Type: Contract
  • Job #35651

Senior Cybersecurity Test Architect

Role Overview

We are seeking a Senior Cybersecurity Test Architect to design and lead the enterprise security testing strategy across applications, infrastructure, cloud environments, and system integrations. This role will establish security testing standards, develop threat-based test approaches, and ensure security requirements are effectively validated through repeatable and measurable testing.

Key Responsibilities

  • Define the enterprise security testing strategy, architecture, and coverage model across applications, infrastructure, cloud, and integrations.
  • Develop threat models and security test scenarios using industry-standard methodologies such as STRIDE and MITRE ATT&CK.
  • Design repeatable and scalable security testing approaches for:
    • Identity and Access Management (IAM)
    • APIs and microservices
    • Data flows and system integrations
    • Cloud environments
    • Application and infrastructure security
  • Define the security testing tooling strategy, including both manual and automated testing capabilities.
  • Establish security testing standards, processes, and best practices across development and infrastructure teams.
  • Ensure security testing is traceable to security requirements, policies, controls, and risk objectives.
  • Identify security gaps and vulnerabilities and provide recommendations for remediation.
  • Support complex security risk assessments, investigations, and escalations.
  • Collaborate with cybersecurity, architecture, development, cloud, infrastructure, and engineering teams to integrate security testing throughout the SDLC.
  • Provide technical leadership and guidance on security testing methodologies, automation, and continuous security validation.
  • Produce clear technical documentation, test strategies, architecture diagrams, and security assessment reports.

Required Skills & Experience

  • 8+ years of experience in cybersecurity architecture, security engineering, security testing, or a related discipline.
  • Strong experience developing enterprise security test strategies and architectures.
  • Hands-on experience with threat modeling methodologies, including STRIDE, MITRE ATT&CK, or equivalent frameworks.
  • Strong knowledge of cloud security architecture across AWS, Azure, and/or GCP.
  • Experience with API security, identity architecture, IAM, authentication, and authorization.
  • Strong understanding of application, infrastructure, network, and integration security.
  • Experience defining and implementing manual and automated security testing approaches.
  • Strong understanding of security controls, requirements, risk management, and compliance frameworks.
  • Excellent technical documentation, architecture, and communication skills.
  • Ability to work effectively with technical teams, architects, developers, and security stakeholders.

Preferred Qualifications

  • Experience integrating security testing into CI/CD and DevSecOps environments.
  • Knowledge of security testing tools and automation frameworks.
  • Experience with container, Kubernetes, and cloud-native security.
  • Familiarity with security frameworks such as NIST, ISO 27001, CIS, OWASP, or similar.
  • Relevant cybersecurity certifications such as CISSP, SABSA, GIAC, or cloud security certifications would be an asset.
Attach a Resume file. Accepted file types are DOC, DOCX, PDF, HTML, and TXT.

We are uploading your application. It may take a few moments to read your resume. Please wait!