09 Aug
|
Venterra Realty
|
Vaughan
09 Aug
Venterra Realty
Vaughan
Reports to: VP of TechnologyHybrid / Corporate Office in Richmond Hill, OntarioSalary: $130,000 - $170,000; up to 10% discretionaryincentive target*OpportunityWe are seeking an AWS Security Architect to join our team in a newly created, high‐impact individual contributor role. This position is designed for a senior‐level subject matter expert (SME) who brings both deep hands‐on engineering capability and strategic architectural leadership.You will lead the design and evolution of secure, scalable AWS environments within a complex, multi‐tenant architecture, with a focus on maturing the environment and driving security improvements. This role will be instrumental in defining how security is consistently enforced, ensuring both flexibility and a strong security posture at scale.You will shape how security is embedded across infrastructure, platforms, applications, and data, focusing on tenant‐aware design, identity‐centric controls, and scalable guardrails. This is an opportunity to define standards, influence platform direction, and build enterprise‐grade cloud security capabilities from the ground up.The ideal candidate is an excellent communicator and thrives in cloud‐native, product‐driven environments, partners closely with Engineering and Data teams, and brings a strong perspective on secure‐by‐design and tenant‐aware architecture patterns. A background in software development or development‐driven environments is also a strong asset.Key Job ResponsibilitiesDefine, own, and evolve the AWS cloud security architecture across complex, multi‐account, multi‐tenant environments, ensuring proper tenant isolation and secure shared servicesDesign and implement scalable, tenant‐aware security guardrails, controls,
and landing zone frameworksEstablish and maintain secure configuration baselines and policy enforcement that operate effectively across multiple tenants and environmentsServe as the AWS security subject matter expert, providing both strategic direction and hands‐on technical leadership in high‐complexity environmentsArchitect and implement secure multi‐tenancy models, including isolation strategies (account, VPC, and application‐level), segmentation, and boundary enforcementPartner with Infrastructure, Software Engineering, and Data Engineering teams to embed security into multi‐tenant platforms and development workflowsDrive identity‐first security architecture, ensuring solid tenant‐aware IAM design, least‐privilege access, and federation strategiesIntegrate security into DevSecOps pipelines, supporting secure delivery of applications across tenantsContribute to and enhance security monitoring, detection, and incident response, including tenant‐level visibility and response patternsSupport security governance, compliance, and audit readiness, ensuring controls scale effectively across tenants without introducing operational frictionContinuously evaluate and improve security posture in distributed, high‐scale, multi‐tenant cloud environmentsRequired Qualifications7+ years of experience in cybersecurity, cloud security, or security engineering4+ years of architecture experience securing AWS environments at scaleProven experience designing and securing complex, multi‐tenant cloud architectures,
including tenant isolation and segmentation strategiesDemonstrated ability to operate at both strategic architectural and hands‐on engineering levelsExcellent communicator, conversant in working across teams to drive security improvements and communicating complex information to senior leadershipDeep expertise in AWS security services (IAM, Config, GuardDuty, Security Hub, CloudWatch)Strong experience designing tenant‐aware identity and access management (IAM) models, ideally including Entra ID and OAuth expertiseExperience with infrastructure as code (Terraform and/or AWS CloudFormation) in large‐scale, multi‐environment deploymentsSolid knowledge of cloud network security, including segmentation approaches for multi‐tenant environments (VPCs, WAF, firewalls, VPNs)Experience securing CI/CD pipelines in shared or multi‐tenant delivery environmentsProven track record implementing secure baselines, guardrails, and policy‐driven controls at scalePreferred QualificationsExperience with AWS Control Tower and multi‐account landing zone architecturesExperience designing secure multi‐tenant platform patterns (SaaS or shared services models)Experience with Amazon Macie and data protection in multi‐tenant contextsAn understanding of securing Agentic AI deployment, ideally including Bedrock/AgentCoreFamiliarity with Microsoft security tooling (Sentinel, Defender XDR, Entra ID)Background in software development or engineering‐led organizations (strong asset)Experience working in cloud‐native, product‐driven, or SaaS environmentsAWS Certified Security – SpecialtyCISSP or equivalent certificationAccessibility accommodations are available on request for candidates taking part in all stages of the selection process.Work Authorization Requirement: Applicants must be legally authorized to work in Canada at the time of application and throughout employment. The company does not provide visa sponsorship for this role. #J-18808-Ljbffr
📌 Aws Security Architect (Vaughan)
🏢 Venterra Realty
📍 Vaughan