Enterprise Security Architect securing technology for Vancity, a member-owned Canadian credit union. Designing enterprise application security frameworks, controls, and risk-based cybersecurity solutions.
Responsibilities
Design and establish enterprise application security architecture frameworks, patterns, and reference models aligned with business objectives and risk tolerance
Lead architecture reviews of applications and systems to identify security gaps and recommend appropriate controls
Architect security solutions for authentication, authorization, encryption, and secure communication channels
Develop and maintain security baselines, standards, and patterns for web, mobile, API, and microservices technology stacks and deployment models
Integrate security architecture principles into CI/CD pipelines to support DevSecOps initiatives
Contribute to enterprise security policies, standards, baselines, guidelines, and procedures
Provide mentorship and direction to junior security architects
Manage and participate in the Application Security Champions program
Collaborate with project leads to define requirements, design controls, and implement scalable security services
Partner with business units and enterprise architecture teams to deliver risk-based security guidance and support an integrated security service portfolio
Assess security risks across programs, projects, and operational processes and recommend architecture remediation strategies
Stay current on cyber threats and emerging technologies to inform investigation techniques and enhance incident response capabilities
Requirements
Bachelor’s degree in STEM, Computer Science, Engineering, or highly related field
12+ years of experience in IT and/or Information Security
5+ years of Secure Application Architecture experience developing and maintaining security baselines, standards, and patterns
8+ years of hands-on Secure Software Development and DevSecOps experience within a formalized SSDLC
Extensive knowledge of secure coding practices
Experience with SAST, DAST, SCA, and IAST tools
Experience designing secure architectures involving networking, cloud, IDP, API, tokenization, identity management, OAuth2, OIDC, SAML, and Zero Trust architectures
Strong understanding of security controls across all layers of the OSI model
Extensive threat modelling experience
Penetration testing experience backed by relevant certifications such as OSCP or GPEN
Experience designing secure systems and integrations with enterprise applications
Awareness of Canadian regulatory environments, including OSFI and PIPEDA
Experience securing public cloud offerings; Azure is preferred
Relevant cloud/security certifications
Information Security certification in one or more of CISSP, CCSP, GISP, or GSE is required
Information Technology certifications such as TOGAF, SABSA, CSSLP, GIAC certifications, or Azure Architecture/Security certifications are an asset
Experience with or knowledge of PCI DSS 4.2, ISO 27001, NIST CSF, and NIST 800-53 control frameworks is highly desired
Strong stakeholder engagement and communication skills across technical and non-technical audiences
Ability to communicate clearly and confidently across the organization
Planning and coordination skills for operating plans, processes, methods, and standards
Strong problem-solving, decision-making, investigative, and risk-assessment skills
Self-motivated and inquisitive approach with the ability to deliver results without continuous supervision
Employment references, credentials, and relevant certifications may be checked and verified
Benefits
Competitive rewards and benefits
Annual incentive program eligibility, subject to program eligibility requirements
Customizable flexible benefit packages for permanent employees
3–4 weeks of vacation per year for new employees, with additional days earned over time
2 extra statutory holidays in addition to BC’s 11 statutory holidays
Care days for personal or family illness
Immediate health and dental coverage from the hire date
Three levels of health and dental coverage to choose from
Defined benefit pension providing guaranteed income for life
Career development opportunities through Vancity Talent Programs
Accessible and barrier-free recruitment support and accommodations
Information Security Advisor conducting cyber - risk assessments and contract reviews for Sun Life, a global financial - services company. Advising business and technology teams on security controls, compliance, and risk remediation.
Director leading IT and cybersecurity operations for the Azrieli Foundation, a Canadian philanthropic organization. Assessing technology risks, overseeing infrastructure, vendors, incident response and executive technology strategy.
Data Security Specialist protecting Sun Life’s financial - services data through DLP, CASB and insider - threat programs. Investigating cyber risks and advancing enterprise data protection.
Senior SaaS Security Manager protecting RBC’s banking platform from third - party cloud risks. Leading controls, vulnerability management, compliance, and security transformation initiatives.
Développeur.euse sécurité cloud protégeant l’infrastructure de nesto, plateforme de financement hypothécaire canadienne. Conception de contrôles cloud, automatisation DevSecOps et réponse aux incidents.
Lead SCADA and cybersecurity engineer designing compliant electric - substation systems for GE Vernova. Coordinating multidisciplinary teams, vendors, testing, estimates, and project risk for decarbonized energy infrastructure.
Join RBC's Application Security Group to develop innovative security solutions, mentor junior staff, and collaborate across teams to enhance decision - making and automate tasks.
Lead SCADA and cybersecurity engineer designing compliant substation systems for GE Vernova. Guiding project teams, vendor designs, estimates, and acceptance testing for cleaner energy infrastructure.
Senior security advisor simulating cyber threats and strengthening defenses for Desjardins, North America's largest cooperative financial group. Leading complex initiatives, methodologies and cybersecurity risk mitigation.