Senior Cloud Security Architect
Listed on 2026-06-03
-
IT/Tech
Cybersecurity, Cloud Computing
Lead the design and maturity of end-to-end cloud security across multi-cloud environments (AWS, Azure, GCP), with responsibility spanning core cyber domains, CSPM/CNAPP strategy, and emerging AI/Agentic AI security. Drive enterprise-wide security improvements through architecture, governance, and cross‑functional engagement. Leads and facilitates the design and implementation of repeatable technical solutions and processes related to technology architecture. Defines and documents efficient and transparent architecture principles, standards and guidelines regarding the proper use and deployment of business applications, data and technology within the Bank.
Partners with broader stakeholders in technology and business in defining architecture possibilities and futures. Works with business and development teams in recommending process or system design and enhancements. Ensures that systems are functionally appropriate, technically sound and well‑integrated. Provides immediate response to critical production program‑wide problems to evaluate solutions, coordinate recovery and ensure resolution.
- Own secure cloud architecture aligned to Zero Trust principles
- Act as enterprise SME across all cyber domains, driving engagement and measurable improvements
- Integrate security into platform, infrastructure, and AI adoption strategies
- Balance risk, scalability, and operational effectiveness
- Identity & Access Management (IAM / CIEM) – least privilege, identity governance
- Data Security – encryption, key management, data protection
- Network Security – segmentation, private access, WAF, DDoS
- Workload Security – VMs, containers, Kubernetes, serverless
- Cloud Posture (CSPM/CNAPP) – misconfigurations, compliance, risk visibility
- Define and mature CSPM/CNAPP platform strategy across multi‑cloud
- Establish policy frameworks, risk prioritization, and control standards
- Drive holistic visibility across assets, identities, workloads, and data
- Integrate posture insights into risk management, operations, and governance
- Improve signal‑to‑noise and remediation effectiveness at scale
- Define secure architecture patterns for AI and Agentic AI workloads
- Establish guardrails for AI service usage and autonomous workflows
- Ensure secure integration with enterprise identity, data, and cloud platforms
- Drive governance, accountability, and risk visibility across AI adoption
- Bachelor’s degree in Computer Science, Cybersecurity, or relevant field
- 7+ years specifically in cloud security with multi‑domain architecture experience
- Expertise across AWS, Azure, and/or GCP security
- Experience with CSPM/CNAPP platforms (Wiz, Prisma, Defender, etc.)
- Experience with AI/ML platforms and cloud‑based AI services
- Strong understanding of cloud security frameworks and standards (CIS, NIST, CSA, MITRE, AI RMF, OWASP LLM)
- Expert in cloud‑native security controls (IAM, KMS, VPC security, encryption, logging, and monitoring).
- Strong communication and collaboration skills, with a proven ability to influence stakeholders.
$ - $
Pay TypeSalaried
BMO is proud to be an equal employment opportunity employer. We evaluate applicants without regard to race, religion, color, national origin, sex (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, gender expression, transgender status, sexual stereotypes, age, status as a protected veteran, status as an individual with a disability, or any other legally protected characteristics. We also consider applicants with criminal histories, consistent with applicable federal, state and local law.
BMO is committed to working with and providing reasonable accommodations to individuals with disabilities. If you need a reasonable accommodation because of a disability for any part of the employment process, please send an e-mail to and let us know the nature of your request and your contact information.
#J-18808-Ljbffr(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).