Security Architect - Senior (Toronto)

Security Architect - Senior (Toronto)

29 Aug
|
S M Software Solutions
|
Toronto

29 Aug

S M Software Solutions

Toronto

Senior Security Architect

Client: Supply Ontario

Requisition: RQ00773

Location: Toronto, Ontario, Canada –

- Hybrid

Work Location: 525 University Avenue, Toronto, Ontario

Assignment Type: Hybrid; onsite requirements are subject to Hiring Manager discretion

Start Date: October 1, 2026

End Date: March 31, 2027

Engagement: 124 Business Days

Hours: 7.25 hours/day, 5 days/week

Public Sector Experience: Preferred

Application Deadline: Wednesday, September 2, 2026 at 10:00 AM EST

Apply To: [email protected]

Role Overview

Supply Ontario is seeking a Senior Security Architect to perform security architecture assessments and consultations required prior to project go-live. The successful candidate will ensure product and project architectures comply with approved security architecture standards, cloud decision records, Ontario policies, and applicable security requirements.

The Senior Security Architect will support multiple projects and ensure security assessments are completed accurately and on schedule without impacting project go-live timelines. The role requires extensive experience in IT security, cloud architecture, security controls, threat modeling, and enterprise security architecture.

Key Responsibilities

- Develop and maintain security reference architectures, network diagrams, standards, patterns, and guidelines supporting enterprise information security policies and standards.
- Define security requirements and provide guidance on technologies throughout the project lifecycle, particularly for cloud environments.
- Assess the optimal placement and adequacy of technologies to achieve effective cloud security architectures based on the applicable cloud service model.
- Analyze proposed solution architectures, technologies, designs, and IT development processes to identify threats, vulnerabilities, security gaps, and potential risks.
- Conduct security architecture assessments and recommend solutions that strengthen the security of applications, infrastructure, business processes, and technology environments.
- Identify deviations from approved security standards and patterns and recommend appropriate remediation strategies.
- Act as a Subject Matter Expert on complex security architecture initiatives and develop associated plans and deliverables.
- Manage multiple security-related projects simultaneously and provide status updates to senior management.
- Leverage existing security architecture best practices while proposing and integrating new practices across business, information, application, security, and technical infrastructure architecture.
- Identify and escalate security issues and collaborate with project teams to ensure application management and quality standards are maintained.
- Support project teams in completing mandatory security architecture assessments in a timely manner prior to go-live.

Required Skills &

- Experience

Skill / Experience Requirement IT security principles, practices, technologies, programs,



and procedures 10+ years Cloud architecture and security controls Strong knowledge required Cybersecurity / Cloud Security Architecture certification such as CISSP-ISSAP, CCSP, or GDSA Required ArchiMate, TOGAF, SABSA, or Zachman certification Asset Threat modeling techniques including STRIDE, PASTA, and MITRE ATT&CK; 5–7 years Cloud and on-premises security controls and architecture 5–7 years Technical and executive-level reports and presentations 5+ years Security threats, vulnerabilities, safeguards, and risk mitigation Strong expertise Information security frameworks such as ISO 27001/2 and NIST Strong knowledge Security technologies including firewalls, IDS/IPS, PKI, IAM, authentication, RBAC, malware defense, LAN/WAN, and secure communications Strong knowledge Ability to work independently and establish objectives with management direction Required Stakeholder relationship management and cross-functional collaboration Required

Desired Skills

- Strong understanding of both cloud and on-premises system/application architectures and security controls.
- Deep knowledge of security threats, vulnerabilities, safeguards, and secure practices across application development, testing, QA, and data-center operations.
- Experience with Operating System security, LAN/WAN technologies, Internet protocols, secure communications, firewalls, IDS/IPS, PKI, Identity and Access Management, authentication, RBAC, and malware defense.
- Solid understanding of ISO 27001/2 and NIST information security frameworks.
- Excellent verbal and written communication skills with the ability to explain architecture concepts to technical and non-technical audiences.
- Ability to operate with a high level of autonomy.
- Strong ability to establish and maintain sustainable relationships with stakeholders, partners, and colleagues.

Rated Criteria Threat Modeling – 30 Points
- 5–7 years of hands-on experience with threat modeling methodologies such as STRIDE, PASTA, and MITRE ATT&CK.;
- Experience developing data-flow diagrams and identifying attack vectors.
- Ability to use threat modeling outcomes to inform secure design decisions and risk mitigation strategies across systems and applications.

Cloud &
- On-Prem Security Architecture – 30 Points

- 5–7 years of extensive experience with cloud and on-premises security controls and architecture.
- Ability to identify gaps between current security posture and industry standards, best practices, and regulatory requirements.
- Experience proposing security architecture enhancements and mitigation strategies.

Team Collaboration – 20 Points
- Demonstrated ability to collaborate effectively with colleagues across multiple functions.
- Ability to share information openly,



support team members, contribute to shared objectives, and maintain a positive and respectful team environment.

Presentation &
- Executive Reporting – 20 Points

- 5+ years of experience authoring technical and executive-level reports.
- Proven experience preparing presentation decks and delivering presentations to stakeholders and senior leadership.

Deliverables
- Security architecture assessments identifying gaps, deviations from approved standards/patterns, threats, vulnerabilities, and recommended security enhancements.
- Development, maintenance, and contribution to security architecture standards, patterns, and reference architectures for cloud environments.
- Security architecture recommendations ensuring appropriate technology placement and controls based on the applicable cloud service model.
- Technical and executive-level security architecture documentation, reports, and presentations as required.

Work Arrangement &
- Additional Terms
- The position is currently classified as Hybrid.
- The work location is Flexible, with onsite requirements determined at the Hiring Manager’s sole discretion.
- The engagement is for 124 Business Days, with an option to extend for up to an additional 126 Business Days at the Agency’s discretion.
- The engagement may also be extended for unused Business Days at the Agency’s discretion.
- The resource must comply with all Agency policies and procedures.
- The Agency will provide a laptop.
- The resource is expected to provide at least one additional monitor, external keyboard, and mouse at their own expense.
- When working remotely, the resource must have a private office space and cannot work from an open communal space.
- The home-office internet connection must be hard-wired and provide suitable bandwidth for the role’s IT requirements.
- If the required home-office conditions cannot be met, the resource will transition to full-time onsite work and the hybrid option will no longer be available.
- Agency systems cannot be accessed from outside the Province of Ontario without prior written approval.
- Agency assets, including laptops and related equipment, cannot be removed from Ontario without prior written approval from the Agency.

How to Apply If this opportunity matches your profile, please send the following documents to [email protected] by Wednesday, September 2, 2026 at 10:00 AM EST:

- Updated Resume in Word format –
- Mandatory
- Skills Matrix and References –
- Mandatory
- Expected Hourly Rate –
- Mandatory
- Visa Status –
- Mandatory
- LinkedIn ID –
- Mandatory

Applications without the mandatory documents cannot be processed or submitted. If this role is not suitable for you, please forward it to qualified Senior Security Architects / Cybersecurity Architects with 10+ years of IT security experience and strong expertise in cloud and on-premises security architecture, threat modeling, security controls, enterprise security frameworks, and pre-go-live security assessments.

📌 Security Architect - Senior (Toronto)
🏢 S M Software Solutions
📍 Toronto

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: security architect - senior (toronto) / toronto