Information Security Architect
Job Description & How to Apply Below
Information Security Architect
Full-Time
Canada (On‑site)
Reporting to the Director, IT Cybersecurity, the Information Security Architect is responsible for the development and oversight of security architecture, relevant security design requirements involved in new initiatives, modification and ongoing support of existing objectives and initiatives. The Information Security Architect must work with IT business partners as well as IT professionals in evaluating Information Security risks and implementing security controls across the organization.
HowYou’ll Help
- Act as a core contributor to Day & Ross’s Enterprise Architecture maturity, establishing and governing a defined and repeatable Security Architecture practice aligned with Enterprise Architecture and organizational strategy.
- Own the Security Architecture domain within the broader EA model, ensuring security principles, standards, and patterns are consistently embedded across applications, infrastructure, cloud, data, and IoT platforms.
- Define and maintain security architecture artifacts appropriate to a mature EA function, including:
- Security principles and policies
- Target‑state and transition architectures
- Reference architectures and reusable security patterns
- Architecture decision records and design guardrails
- Integrate security architecture into delivery life cycles (initiative intake, solution design, SDLC / Dev Sec Ops ), ensuring security is addressed by design rather than by exception.
- Lead security architecture reviews for new initiatives and material changes, providing authoritative guidance on design decisions, risk trade‑offs, and alignment with enterprise standards.
- Translate enterprise risk assessments, threat models, and regulatory obligations into actionable architectural requirements and remediation roadmaps.
- Contribute to the evolution of an Enterprise Security Architecture operating model, including governance forums, design review processes, and metrics that demonstrate architectural effectiveness and risk reduction.
- Design and govern IoT and telematics security architectures at enterprise scale, ensuring secure device identity, lifecycle management, connectivity, and integration with core enterprise systems.
- Partner with Enterprise Architecture, Security Operations, and Governance teams to ensure architectural standards are implementable, enforceable, and measurable.
- 7+ years of experience in information security, with hands‑on responsibility for Security Architecture within medium‑to‑large enterprise environments focused on cloud security.
- Proven experience operating within a formal Enterprise Architecture function, contributing to the transition from ad‑hoc security decisions to standardized, repeatable architecture practices.
- Demonstrated ability to define and govern security architecture artifacts, including principles, standards, reference architectures, and target‑state roadmaps.
- Strong practical experience applying architecture‑centric security frameworks such as SABSA, NIST CSF, ISO/IEC 27001/27002, and Zero Trust—translating them into concrete architectural designs, not just compliance mappings.
- Experience conducting architecture‑level risk analysis and threat modeling, and using those outputs to drive design decisions and prioritization.
- Broad understanding of enterprise technology domains (networks, identity, cloud, applications, data platforms) and how security architecture patterns apply consistently across them.
- Experience influencing architecture outcomes through design reviews, standards enforcement, and stakeholder collaboration, rather than operational authority alone.
- Relevant certifications such as CISSP‑ISSAP, SABSA SCM, CISM, or SANS Architecture‑focused credentials are strong assets.
- Ability to operate effectively in an organization maturing its Enterprise Architecture capabilities, balancing progress with pragmatism.
- Experience in transportation, logistics, or highly operational environments is a strong asset.
- Experience designing and governing IoT security architectures at scale, including device identity, authentication, lifecycle management, and secure enterprise integration.
- Familiari…
Note that applications are not being accepted from your jurisdiction for this job currently via this jobsite. Candidate preferences are the decision of the Employer or Recruiting Agent, and are controlled by them alone.
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
Search for further Jobs Here:
×