09 Aug
|
Astra North Infoteck
|
Toronto
09 Aug
Astra North Infoteck
Toronto
Job Title
Solution Architect (Security & API Infrastructure)
Location
Toronto, Ontario (Hybrid – 4 Days Work From Office)
Duration
6–12 Months
Required Experience
8+ Years (5+ Years in Security Architecture)
Primary Skills
- Solution Architecture
- Security Architecture
- API Infrastructure
- Apigee API Management
- AWS Cloud Architecture
- Akamai
- Cloudflare
- Enterprise Security
- Financial Services
Role Description
1. Architecture & Solution Design
- Lead end-to-end solution architecture across security, API, and cloud domains.
- Gather requirements and define solution architecture from design through implementation and operational handover.
- Establish architecture patterns, standards, and reference architectures aligned with enterprise frameworks (TOGAF, Zachman, etc.).
- Produce architecture artifacts including:
- High-Level Design (HLD)
- Low-Level Design (LLD)
- Data Flow Diagrams
- Sequence Diagrams
- Threat Models
- Evaluate emerging technologies through Proof of Concepts (POCs) and vendor assessments.
2. Security Architecture
- Design enterprise security architectures covering:
- Encryption at Rest
- Encryption in Transit
- Encryption in Use
- Key Management
- Certificate Lifecycle Management
- Public Key Infrastructure (PKI)
- Architect fraud detection and digital identity verification solutions using ThreatMetrix or equivalent platforms.
- Define security policies for:
- API Gateways
- Web Application Firewalls (WAF)
- DDoS Protection
- Bot Management
- Conduct:
- Threat Modeling
- Security Reviews
- Risk Assessments
- Ensure compliance with financial industry standards including:
- PCI-DSS
- SOX
- GDPR
- Open Banking
3. API & Edge Infrastructure
- Design enterprise API strategies using Apigee including:
- API Proxy Design
- Shared Flows
- Target Servers
- Developer Portals
- Analytics
- OAuth/OIDC
- Rate Limiting
- API Monetization
- Architect edge security solutions using:
- Akamai
- Cloudflare
- Configure:
- WAF Rules
- Bot Manager
- DDoS Protection
- Edge Compute
- DNS Management
- Design enterprise DNS architecture including:
- DNSSEC
- Traffic Management
- Failover
- Multi-CDN Strategies
- GSLB
- TTL Strategies
4. Cloud & Infrastructure
- Design secure AWS cloud solutions utilizing:
- VPC
- IAM
- KMS
- CloudFront
- Route 53
- GuardDuty
- Security Hub
- AWS WAF
- AWS Shield
- Lambda
- ECS/EKS
- API Gateway
- Implement cloud-native security principles:
- Zero Trust Networking
- Least Privilege IAM
- Secrets Management
- Infrastructure-as-Code Security
- Design hybrid and multi-cloud connectivity architectures.
5. Governance & Leadership
- Participate in Architecture Review Boards (ARBs) and Design Authority forums.
- Define enterprise architecture standards and governance.
- Mentor development teams on architecture and security best practices.
- Collaborate with:
- Enterprise Architects
- Engineering Teams
- Product Owners
- Third-party Vendors
- Maintain architecture documentation and enterprise architecture repositories.
Required Experience
Core Technical Expertise
- 8+ years in Solution or Technical Architecture.
- 5+ years focused on Security Architecture.
- Hands-on experience with:
- Apigee API Management
- API Proxy Development
- Shared Flows
- Target Servers
- Analytics
- Strong expertise with:
- Akamai (Property Manager, WAF/KSD, Bot Manager, Edge DNS)
- Cloudflare (WAF, Workers, DNS)
- Deep understanding of:
- TLS 1.2 / TLS 1.3
- AES-256
- RSA
- Elliptic Curve Cryptography
- HSM
- Tokenization
- Enterprise DNS architecture experience.
- Practical experience with ThreatMetrix or similar fraud prevention platforms.
- Strong AWS architecture experience (AWS Solutions Architect Professional preferred).
Domain & Governance Experience
- Financial Services experience is mandatory:
- Banking
- Payments
- Insurance
- Capital Markets
- Experience with:
- Architecture Governance
- Technical Debt Management
- Architecture Review Boards (ARBs)
- Enterprise Standards
- Knowledge of compliance frameworks:
- PCI-DSS
- SOX
- FCA
- PSD2
- Open Banking
Architecture Practices
- Experience across the complete solution lifecycle:
- Discovery
- Design
- Build
- Test
- Deploy
- Operate
- Familiarity with architecture frameworks:
- TOGAF
- C4 Model
- arc42
- Experience using:
- Lucidchart
- Draw.io
- Strong understanding of:
- DevSecOps
- CI/CD Pipelines
- Terraform
- AWS CloudFormation
- Experience with:
- Microservices
- Event-Driven Architecture
- REST APIs
- GraphQL
- Messaging & Streaming
Desirable Skills
- Microsoft Azure
- Google Cloud Platform (GCP)
- Okta
- Ping Identity
- Splunk
- Microsoft Sentinel
- SIEM/SOAR Platforms
- Container Security
Soft Skills
- Excellent stakeholder communication.
- Ability to present complex technical concepts to executive and non-technical audiences.
- Strong analytical and problem-solving skills.
- Ability to work in fast-paced, highly regulated environments.
- Team-oriented leadership with experience influencing cross-functional teams.
Preferred ATS Keywords
- Solution Architect
- Security Architect
- Enterprise Architecture
- API Infrastructure
- Apigee
- API Gateway
- OAuth
- OpenID Connect (OIDC)
- AWS
- Cloud Architecture
- Akamai
- Cloudflare
- WAF
- DDoS Protection
- Bot Management
- ThreatMetrix
- PKI
- TLS 1.3
- AES-256
- RSA
- HSM
- Tokenization
- DNS
- DNSSEC
- Route 53
- CloudFront
- IAM
- KMS
- GuardDuty
- Security Hub
- Zero Trust
- DevSecOps
- Terraform
- CloudFormation
- TOGAF
- C4 Model
- REST APIs
- GraphQL
- Microservices
- Event-Driven Architecture
- Financial Services
- Banking
- PCI-DSS
- SOX
- PSD2
- Open Banking
- Architecture Review Board (ARB)
- Solution Design
- High-Level Design (HLD)
- Low-Level Design (LLD)
- Threat Modeling
- Security Architecture
📌 Solution Architect -Security & API Infrastructure (Toronto)
🏢 Astra North Infoteck
📍 Toronto