Enterprise Architect - Governance, Risk & Compliance (Niagara-on-the-Lake)

Enterprise Architect - Governance, Risk & Compliance (Niagara-on-the-Lake)

02 Sep
|
Niagara Health
|
Niagara-on-the-Lake

02 Sep

Niagara Health

Niagara-on-the-Lake

VACANCY NUMBER: 44110PS

JOB TITLE: ENTERPRISE ARCHITECT - GOVERNANCE, RISK AND COMPLIANCE, FT

STATUS: FULL TIME

DEPARTMENT: INFORMATION AND COMMUNICATION TECHNOLOGY

LOCATION: NIAGARA HEALTH

HOURS OF WORK: 75 HOURS PER PAY PERIOD

POSTING DATE: 01 SEPTEMBER 2026

CLOSING DATE: 14 SEPTEMBER 2026

UNION: NON UNION

WAGE RANGE: $55.320 PER HOUR THE POSITION IS COMPENSATED ACCORDING TO AN ESTABLISHED WAGE GRID, WITH PROGRESSION THROUGH THE STEPS OCCURRING IN ACCORDANCE WITH APPLICABLE POLICIES UNTIL REACHING THE MAXIMUM OF THE SALARY RANGE

POSITION OBJECTIVE:

As an integral member of Niagara Health's Cyber Security team, working under the direction of the Director of Cyber Security, the Enterprise Architect - Governance, Risk and Compliance (GRC) will serve as Niagara Health's enterprise architecture lead for cybersecurity governance, technology risk, compliance and assurance. This role will turn regulatory and cybersecurity needs into clear architecture guidance, practical standards, roadmaps, controls, and decision records. The incumbent will work closely with Niagara Health teams, consultants, contractors and vendors to make sure solutions are secure, compliant, resilient, easy to support and aligned with patient safety and business goals from design through implementation, commissioning and transition to operations.

KEY RESPONSIBILITIES:

o Lead the development, implementation, and maintenance of enterprise security architecture, governance, risk, and compliance (GRC) frameworks, standards, roadmaps, and strategic plans o Integrate cybersecurity, privacy, governance, risk, and compliance requirements into business, application, technology, cloud, medical device, and integration initiatives o Provide expert guidance and recommendations to business leaders, project teams, vendors, and internal and external parties on technology risk, security controls, compliance obligations, and remediation strategies o Lead cybersecurity, privacy, technology risk, third-party risk assessments, and Threat Risk Assessments (TRAs) for new solutions, system changes, integrations, and vendor engagements o Review and evaluate solution architectures, data flows, integrations, identity and access models, resiliency, recovery capabilities, and security controls to ensure alignment with organizational standards and risk tolerance o Develop, maintain, and oversee risk registers, control matrices, architecture assessments, compliance mappings, security requirements, exceptions, and related governance documentation o Assess the effectiveness of security and compliance controls, identify risks and gaps, recommend mitigation strategies, and track remediation activities through resolution or formal risk acceptance o Support threat modelling, business impact analyses, security testing, vulnerability assessments, penetration testing, audits, and operational readiness reviews o Evaluate third-party and supply chain risks, including cloud services,



data handling practices, connected medical technologies, software dependencies, and contractual security requirements o Ensure alignment with industry best practices and frameworks, including NIST, ISO 27001/27002, CIS Controls, and applicable healthcare, privacy, accessibility, and regulatory requirements o Lead the development and ongoing management of cybersecurity policies, standards, procedures, baselines, and architecture patterns o Establish compliance monitoring, reporting, assurance, and evidence management processes to support internal reviews, external audits, and continuous compliance efforts o Monitor emerging threats, regulatory changes, and evolving technology trends, recommending enhancements to security controls, governance practices, and architecture strategies o Support governance forums by presenting architecture decisions, risk assessments, compliance status, exceptions, and recommendations to project and executive leadership teams o Collaborate with Cybersecurity, Digital/IT, Privacy, Risk, Legal, Procurement, Clinical Engineering, Facilities, and operational teams to ensure secure and compliant technology delivery o Support major organizational initiatives through participation in design reviews, technical workshops, procurement activities, commissioning, operational readiness, and transition planning o Define and support security, privacy, audit, incident response, data protection, and service continuity requirements for contracts, projects, and vendor engagements o Mentor and support technical and project teams in secure-by-design, privacy-by-design, and risk-based decision-making practices o Drive continuous improvement of GRC processes, reporting, metrics, tools, and governance practices to enhance organizational effectiveness and patient care outcomes o Perform other related duties consistent with the scope and seniority of the position

QUALIFICATIONS:

o University degree or college diploma in Computer Science, Information Systems, Cybersecurity, Risk Management, Business, or a related field, or an equivalent combination of education and experience may be considered o Significant progressive experience in enterprise architecture, cybersecurity governance, technology risk, compliance, audit or security architecture in a complex, regulated environment o Demonstrated experience leading architecture reviews, risk assessments, third-party risk assessments, Threat Risk Assessments, control design, policy and standards development, compliance mapping,



audit support and remediation governance O Experience with large capital projects, healthcare environments, hospital operations, clinical systems, connected medical devices or critical infrastructure is a strong asset o Experience assessing cloud, network, identity, application, data, integration, operational technology and third-party architectures from a risk and compliance perspective o Proven ability to build relationships and collaborate effectively across multidisciplinary teams in a complex organizational workplace o Strong knowledge of enterprise architecture, cybersecurity, risk management, and governance frameworks, including NIST, NIST CSF, NIST SP 800-53, ISO 27001/27002, CIS Controls, and COBIT o Practical experience with governance, enterprise risk management, control assessments, policy management, audit practices, third-party risk management, and compliance reporting o Understanding of privacy and data protection principles, information classification, records retention, identity and access management, vulnerability management, incident response, resilience, and disaster recovery o Ability to analyze technical designs and communicate risks, recommendations, and solutions to both technical and non-technical audiences o Familiarity with GRC platforms, architecture repositories, risk registers, control libraries, and reporting tools is an asset o Relevant cybersecurity certifications preferred.

Certified Information Systems Security

Professional (CISSP), Certified Information Security Manager (CISM), Certified in Risk and Information Systems Control (CRISC), or Certified Information Systems Auditor (CISA), Certified in the Governance of Enterprise IT (CGEIT). Equivalent combinations of certification and demonstrated experience will be considered o Certified Cloud Security Professional (CCSP), cloud security architecture certification, or comparable cloud credential o Healthcare-focused security, privacy, risk management, or governance certifications are considered an asset o Strong analytical, critical thinking, and risk-based decision-making skills o Excellent communication, facilitation, presentation, and internal and external parties' engagement abilities o Proven organizational skills with the ability to manage multiple priorities and deadlines o Effective negotiation, conflict resolution, relationship-building, and collaboration skills o Self-motivated, adaptable, and able to work independently and within a team environment o Demonstrated professionalism, accountability, confidentiality, and reliable work performance

Questions, quoting the job posting number, may be directed to [email protected]

How to Apply:

If you are interested in this position, please visit our careers page by 11:59pm September 14, 2026 and submit an application through eRecruit. (Reference Job Posting #44110) Please note - you will need to create an eRecruit profile to apply.

📌 Enterprise Architect - Governance, Risk & Compliance (Niagara-on-the-Lake)
🏢 Niagara Health
📍 Niagara-on-the-Lake

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: enterprise architect - governance, risk & compliance (niagara-on-the-lake) / niagara-on-the-lake

Subscribe to this job alert:

Get the latest job offers by email for: enterprise architect - governance, risk & compliance (niagara-on-the-lake) / niagara-on-the-lake