10 Sep
|
apptoza
|
Toronto
Position: Solution Architect
Location: Toronto, ON (4 days Hybrid)
Contract: Long Term
About the Role
We are seeking an experienced Solution Architect with deep expertise in security, API management, and cloud infrastructure to join our enterprise architecture team within the financial services sector. This role bridges strategic architecture governance with hands-on solution design, ensuring secure, scalable, and compliant systems from concept through production.
Key Responsibilities
Architecture & Design
- Lead end-to-end solution design across security, API, and cloud domains — from requirements gathering and architecture definition through implementation and operational handover
- Define and enforce architecture patterns, standards, and reference architectures aligned with enterprise architecture best practices (TOGAF, Zachman, or equivalent frameworks)
- Produce high-quality solution design documents including HLDs, LLDs, data flow diagrams, sequence diagrams, and threat models
- Evaluate and recommend technology solutions, conducting proof-of-concept assessments and vendor evaluations
Security Architecture
- Design and implement enterprise security architectures encompassing encryption (at rest, in transit, and in use), key management, certificate lifecycle management, and PKI
- Architect fraud detection and identity verification solutions leveraging ThreatMetrix and similar platforms
- Define security policies for API gateways, WAFs, DDoS mitigation, and bot management
- Conduct security reviews, threat modelling, and risk assessments for recent and existing solutions
- Ensure compliance with financial industry regulations (PCI-DSS, SOX, GDPR, Open Banking standards)
API & Edge Infrastructure
- Design and govern API strategies using Apigee (API proxy design, developer portals, rate limiting,
OAuth/OIDC, API monetisation)
- Architect edge security and CDN solutions using Akamai and Cloudflare (WAF rules, bot management, DDoS protection, edge compute, DNS management)
- Design and manage DNS architecture including DNSSEC, traffic management, failover, and multi-CDN strategies
Cloud & Infrastructure
- Architect solutions on AWS (VPC, IAM, KMS, CloudFront, Route 53, GuardDuty, Security Hub, WAF, Shield, Lambda, ECS/EKS, API Gateway)
- Apply cloud-native security principles: zero-trust networking, least-privilege IAM, secrets management, and infrastructure-as-code security scanning
- Design hybrid and multi-cloud connectivity patterns where required
Governance & Leadership
- Contribute to and uphold architecture governance processes including architecture review boards (ARBs), design authority forums, and exception management
- Mentor and guide development teams on security best practices and architectural standards
- Collaborate with enterprise architects, engineering leads, product owners, and third-party vendors to align solutions with business strategy
- Maintain architecture decisions and contribute to the enterprise architecture repository
Required Experience & Qualifications
Core Technical Expertise
- 8+ years in solution/technical architecture roles, with at least 5 years focused on security architecture
- Proven hands-on experience with Apigee API management platform (proxy development,
shared flows, target servers, analytics)
- Solid working knowledge of Akamai (Property Manager, WAF/KSD, Bot Manager, Edge DNS) and/or Cloudflare (WAF, Workers, DNS)
- Deep understanding of encryption standards and protocols (TLS 1.2/1.3, AES-256, RSA, elliptic curve, HSMs, tokenisation)
- Experience with DNS architecture at enterprise scale (DNSSEC, GSLB, authoritative vs recursive, TTL strategies)
- Practical experience with ThreatMetrix or equivalent digital identity/fraud prevention platforms
- Strong AWS architecture skills (AWS Solutions Architect Qualified certification preferred)
Domain & Governance Experience
- Financial services industry experience is essential — banking, payments, insurance, or capital markets
- Demonstrated experience in enterprise architecture governance: defining standards, chairing or participating in ARBs, managing technical debt, and driving architectural compliance
- Familiarity with regulatory and compliance frameworks relevant to financial services (PCI-DSS, SOX, FCA, PSD2, Open Banking)
Architecture Practices
- Experience across the full solution lifecycle: discovery → design → build → test → deploy → operate
- Proficiency with architecture frameworks (TOGAF, C4 model, arc42) and modelling tools (e.g., , LucidChart, Draw.io,)
- Solid understanding of DevSecOps, CI/CD pipelines, and infrastructure-as-code (Terraform, CloudFormation)
- Experience with microservices, event-driven architecture, and integration patterns (REST, GraphQL, messaging/streaming)
Desirable Skills
- Additional cloud platform experience (Azure, GCP)
- Knowledge of identity platforms (Okta, Ping)
- Experience with SIEM/SOAR platforms (Splunk, Sentinel)
- Container security
📌 Solutions Architect (Toronto)
🏢 apptoza
📍 Toronto