Senior Security Architect (Greater Toronto Area)

Senior Security Architect (Greater Toronto Area)

02 Sep
|
StafinGo
|
Greater Toronto Area

02 Sep

StafinGo

Greater Toronto Area

Senior Security Architect – Cloud & Enterprise Security in GTA- Full-time onsite

Job Type: Contract

Location: Toronto, Ontario, Onsite

Contract Start: October 1st, 2026

Contract End: March 31st, 2027

Extension: Opportunity for an additional 126 business days

Pay Range: $80/hour T4 – $100/hour INC

Public Sector Experience: Nice to Have

About the Opportunity :

Stafingo is seeking an experienced Senior Security Architect to support a major enterprise technology environment in Ontario.

The successful candidate will join a security architecture function responsible for reviewing and assessing technology solutions before implementation and production deployment. The role will focus on ensuring that proposed architectures meet established security standards, enterprise security patterns, cloud architecture principles, and risk-management requirements.

This is a highly technical and consultative position suited to a senior security professional who can independently assess complex cloud and on-premises architectures, identify security gaps and vulnerabilities, develop practical remediation strategies, and communicate recommendations effectively to both technical teams and senior leadership.

The resource will work across multiple initiatives simultaneously and will have significant interaction with architects, project teams, technology specialists, business stakeholders, and senior management.

Key Responsibilities :

Security Architecture & Solution Assessment

- Conduct comprehensive security architecture reviews of proposed applications, platforms, infrastructure, and technology solutions.
- Assess solution designs against established enterprise security standards, architecture patterns, policies, and control requirements.
- Identify security architecture gaps, deviations, vulnerabilities, and potential attack vectors.
- Develop practical recommendations and mitigation strategies to strengthen the overall security posture of proposed solutions.
- Review architectures throughout the project lifecycle, from initial design through implementation and production readiness.
- Evaluate the appropriate security architecture and technology placement for different cloud service and deployment models.
- Provide guidance on secure integration between cloud-based and on-premises environments.
- Support architecture decisions by identifying security implications, risks, dependencies, and trade-offs.

Cloud & Enterprise Security

- Develop and contribute to cloud security architecture standards, patterns, reference architectures, and design guidelines.
- Advise project teams on appropriate security controls for cloud platforms and services.
- Evaluate security controls across public/private cloud, hybrid, and traditional data-centre environments.
- Assess identity, access, network, data, application, infrastructure, and platform security controls.
- Help establish secure target-state architectures while reducing redundant, inconsistent, or siloed security solutions.
- Recommend improvements aligned with recognized security frameworks, standards, and industry best practices.

Threat & Risk Analysis

- Apply threat-modeling methodologies to applications, integrations, infrastructure, and enterprise systems.
- Identify threats, vulnerabilities, attack vectors, trust boundaries,



and potential security weaknesses.
- Develop and review data-flow diagrams and architecture documentation to support threat analysis.
- Apply methodologies and frameworks such as STRIDE, PASTA, and MITRE ATT&CK; where appropriate.
- Evaluate risks associated with application development, testing, QA, deployment, and operational environments.
- Recommend security safeguards and compensating controls based on identified risks.

Security Technology Assessment Provide architecture guidance across a broad range of security technologies and capabilities, including:

- Identity and Access Management (IAM)
- Authentication and authorization
- Role-Based Access Control (RBAC)
- Privileged access
- PKI and certificates
- Network security
- Firewalls
- IDS/IPS
- Secure communications
- LAN/WAN security
- Internet protocols and applications
- Operating system security
- Endpoint and malware protection
- Application security
- Data protection
- Cloud security controls
- Infrastructure security

Governance, Standards & Documentation

- Develop and maintain security reference architectures, standards, patterns, diagrams, and implementation guidelines.
- Contribute to enterprise security architecture documentation and reusable design patterns.
- Review project deliverables for compliance with approved security requirements.
- Identify and escalate security architecture issues that could affect project delivery or production readiness.
- Prepare technical assessments, architecture recommendations, decision documents, and executive-level reports.
- Maintain clear documentation of findings, risks, decisions, recommendations, and remediation activities.

Stakeholder & Advisory Leadership

- Act as a senior subject-matter expert and trusted security advisor to project and technology teams.
- Work collaboratively with enterprise architects, solution architects, infrastructure teams, application teams, cloud specialists, cybersecurity teams, and business stakeholders.
- Explain complex security architecture concepts in a clear and practical manner to technical and non-technical audiences.
- Present architecture assessments, risks, recommendations, and status updates to senior leadership.
- Manage multiple security architecture assessments and related initiatives concurrently.
- Establish productive and sustainable relationships with internal teams, partners, vendors, and stakeholders.
- Work independently while aligning priorities and deliverables with organizational direction.

Required Qualifications :

- 10+ years of professional experience in IT security , including security principles, practices, technologies, programs, controls, and procedures.
- Strong hands-on understanding of cloud security architecture and security controls .
- Demonstrated experience assessing complex enterprise technology architectures.
- Robust knowledge of both cloud and on-premises security architecture .




- Experience identifying security gaps and recommending architecture improvements and risk mitigations.
- Strong understanding of security threats, vulnerabilities, safeguards, and secure design principles.
- Excellent written and verbal communication skills.
- Demonstrated ability to prepare technical and executive-level documentation and presentations.
- Ability to work independently with limited supervision and manage multiple priorities.
- Strong collaboration and relationship-building skills.

Required / Preferred Certifications : Candidates should hold a recognized cybersecurity or cloud-security architecture certification such as:

- CISSP-ISSAP
- CCSP
- GDSA

Additional architecture certifications are considered an asset, including:
- TOGAF
- SABSA
- ArchiMate
- Zachman

Candidates with 5–7 years of hands-on threat-modelling experience will be strongly preferred.

Relevant experience includes:

- STRIDE
- PASTA
- MITRE ATT&CK;
- Data-flow diagrams
- Attack-vector identification
- Threat identification and analysis
- Secure design recommendations
- Risk mitigation strategies
- Application and infrastructure threat assessments

Cloud & On-Premises Security Architecture Robust candidates will demonstrate 5–7 years of extensive experience assessing and designing security controls across cloud and traditional enterprise environments.

Experience should include:

- Cloud security architecture
- Hybrid environments
- On-premises infrastructure
- Security-control assessments
- Architecture gap analysis
- Industry standards and best practices
- Regulatory/security requirements
- Security architecture enhancements
- Risk mitigation

Collaboration & Teamwork Demonstrated ability to work effectively across technical and business functions, including:

- Sharing knowledge and information
- Supporting colleagues
- Working across architecture and cybersecurity teams
- Building strong stakeholder relationships
- Contributing to common delivery objectives
- Working respectfully in multidisciplinary environments

Executive & Technical Presentations Candidates should have 5+ years of experience preparing and delivering technical and executive-level materials, including:

- Security architecture assessments
- Executive briefings
- Architecture recommendations
- Technical reports
- Risk presentations
- Security findings
- Status reports
- Decision papers
- Presentations to senior leadership

Why Consider This Opportunity? This is an excellent opportunity for a senior cybersecurity professional to contribute to enterprise-level security architecture and cloud transformation initiatives while working alongside experienced technology, architecture, and cybersecurity professionals.

How to Apply :

If you are a Senior Security Architect, Cloud Security Architect, Enterprise Security Architect, Cybersecurity Architect, or Security Architecture Consultant with the required experience, we encourage you to apply.

Please apply to the job posting or submit your updated resume highlighting your experience with security architecture assessments, cloud security, threat modelling, security controls, enterprise architecture, and executive-level presentations to [email protected] for immediate consideration.

📌 Senior Security Architect (Greater Toronto Area)
🏢 StafinGo
📍 Greater Toronto Area

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: senior security architect (greater toronto area) / greater toronto area

Subscribe to this job alert:

Get the latest job offers by email for: senior security architect (greater toronto area) / greater toronto area