12 Aug
|
Ardent Softsol
|
Toronto
12 Aug
Ardent Softsol
Toronto
Solution Architect – Security & API Infrastructure
Location: Toronto, ON – Hybrid (4 Days Onsite)
Contract Duration: 6–12 Months
Industry: Financial Services Position Overview
We are seeking an experienced Solution Architect – Security & API Infrastructure to lead the design and architecture of secure, scalable, and highly available enterprise solutions across security, API management, cloud, and edge infrastructure.
The ideal candidate will have strong hands-on expertise with Apigee, Akamai and/or Cloudflare, AWS, enterprise DNS, security architecture, identity/fraud platforms, and API infrastructure.
Experience within the financial services or banking industry is essential.
This role will work closely with Enterprise Architects, Engineering Leads, Product Owners, Security teams, and third-party vendors to define architecture standards, drive solution delivery, and ensure compliance with enterprise and regulatory requirements.
Key Responsibilities
Architecture & Solution Design
Lead end-to-end solution architecture from requirements discovery and architecture definition through implementation, deployment, and operational handover.
Define and enforce architecture patterns, standards, principles, and reference architectures aligned with enterprise architecture frameworks such as TOGAF, Zachman, or equivalent.
Develop high-quality architecture deliverables, including:
High-Level Design (HLD)
Low-Level Design (LLD)
Data Flow Diagrams
Sequence Diagrams
Architecture Decision Records (ADRs)
Threat Models
Evaluate technology platforms and architectural alternatives through proof-of-concept assessments and vendor evaluations.
Ensure solutions meet requirements for scalability, availability, resiliency, security, performance, and maintainability.
Security Architecture
Design enterprise security architectures covering encryption, key management, certificate lifecycle management, PKI, tokenization, and secrets management.
Define security controls and architecture patterns for API gateways, WAF, DDoS protection, bot management, and edge security.
Architect fraud detection and digital identity verification solutions using ThreatMetrix or equivalent platforms.
Conduct security architecture reviews, threat modeling, risk assessments, and security control evaluations.
Apply Zero Trust, least-privilege access, defense-in-depth, and secure-by-design principles.
Ensure solutions align with applicable financial services regulations and security standards, including PCI-DSS, SOX, GDPR, PSD2, FCA, and Open Banking requirements.
API & Edge Infrastructure
Define and govern enterprise API strategies using Apigee, including:
API proxy architecture and development
Shared flows
Target servers
OAuth/OIDC
Rate limiting and traffic management
API analytics
Developer portals
API monetization
Architect and govern edge security and CDN solutions using Akamai and/or Cloudflare.
Design and manage
WAF policies and rules
Bot management
DDoS protection
Edge computing
DNS services
Traffic routing and optimization
Design enterprise DNS architectures incorporating DNSSEC, GSLB, authoritative and recursive DNS, TTL strategies, failover, and multi-CDN approaches.
Cloud & Infrastructure Architecture
Architect secure and scalable solutions on AWS, leveraging services such as:
VPC
IAM
KMS
CloudFront
Route 53
GuardDuty
Security Hub
AWS WAF
AWS Shield
Lambda
ECS/EKS
API Gateway
Apply cloud-native security practices, including Zero Trust networking, least-privilege IAM, secrets management, encryption, and infrastructure-as-code security scanning.
Design hybrid and multi-cloud connectivity and integration patterns where required.
Ensure cloud solutions follow enterprise security, architecture, and operational standards.
Architecture Governance & Leadership
Participate in and support enterprise architecture governance processes, including Architecture Review Boards (ARBs), Design Authority forums, and technical exception management.
Define and maintain architecture standards, patterns, and technical guidelines.
Identify and manage technical debt and architectural risks.
Mentor engineering and development teams on secure architecture principles and enterprise standards.
Collaborate with Enterprise Architects, Engineering Leads, Product Owners, Security teams, and external vendors.
Maintain architecture decisions, standards, and documentation within the enterprise architecture repository.
Influence technical decisions across teams without requiring direct management authority.
Required Qualifications & Experience
Core Technical Expertise
8+ years of experience in Solution Architecture, Technical Architecture, or related architecture roles.
Minimum 5 years of experience focused on Security Architecture.
Strong hands-on experience with Apigee API Management, including API proxies, shared flows, target servers, and analytics.
Strong working knowledge of Akamai and/or Cloudflare, including:
Akamai Property Manager
Akamai WAF/KSD
Akamai Bot Manager
Akamai Edge DNS
Cloudflare WAF
Cloudflare Workers
Cloudflare DNS
Deep understanding of security protocols and encryption standards, including:
TLS 1.2/1.3
AES-256
RSA
Elliptic Curve Cryptography
HSMs
Tokenization
Strong experience designing and managing enterprise-scale DNS architectures, including DNSSEC, GSLB, authoritative vs. recursive DNS, TTL strategies, and traffic management.
Hands-on experience with ThreatMetrix or equivalent digital identity/fraud prevention platforms.
Robust AWS architecture experience across security, networking, compute, API, and edge services.
AWS Solutions Architect – Professional certification is preferred.
Financial Services & Governance
Financial services industry experience is mandatory, including banking, payments, insurance, or capital markets.
Proven experience with enterprise architecture governance, including:
Architecture standards
Architecture Review Boards
Design authority
Technical debt management
Architecture compliance
Exception management
Strong understanding of financial services regulatory and compliance requirements such as PCI-DSS, SOX, FCA, PSD2, GDPR, and Open Banking.
Architecture & Engineering Practices
Experience across the complete solution lifecycle: Discovery → Design → Build → Test → Deploy → Operate.
Proficiency with architecture frameworks and methodologies such as TOGAF, C4 Model, and arc42.
Experience with architecture and modeling tools such as Lucidchart and Draw.io.
Strong understanding of DevSecOps, CI/CD, and Infrastructure as Code (IaC).
Hands-on experience with Terraform and/or CloudFormation.
Strong knowledge of microservices, event-driven architecture, and enterprise integration patterns.
Experience with REST, GraphQL, messaging, and streaming technologies.
Nice-to-Have Skills
Experience with additional cloud platforms such as Microsoft Azure or Google Cloud Platform (GCP).
Knowledge of identity and access management platforms such as Okta or Ping Identity.
Experience with SIEM/SOAR platforms, including Splunk and Microsoft Sentinel.
Knowledge of container and Kubernetes security.
Experience with API security, service mesh, and modern cloud-native security architectures.
📌 Solution Architect – Security & API Infrastructure (Toronto)
🏢 Ardent Softsol
📍 Toronto