×
Register Here to Apply for Jobs or Post Jobs. X

Threat Modeler​/Security Architect – AI Security, Cloud & DevSecOps

Job in Toronto, Ontario, C6A, Canada
Listing for: Astra-North Infoteck Inc. ~ Conquering today’s challenges, achieving tomorrow’s vision!
Full Time position
Listed on 2026-07-21
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security, Data Security, IT Consultant
Salary/Wage Range or Industry Benchmark: 120000 - 180000 CAD Yearly CAD 120000.00 180000.00 YEAR
Job Description & How to Apply Below
Position: Threat Modeler / Security Architect – AI Security, Cloud & DevSecOps

Threat Modeler / Security Architect – AI Security, Cloud & Dev Sec Ops  Must Have Technical/Functional Skills Security Architecture & Threat Modeling

  • Threat Modeler and Security Architect with a strong development background.
  • Experience in Artificial Intelligence, Machine Learning, and Data Science with expertise in enterprise architecture, AI product security, and digital transformation.
  • Strong hands‑on experience with cloud‑native architectures, including AWS and GCP.
  • Experience with secure AI system development, AI governance, and cybersecurity best practices.
  • Experience with threat modeling frameworks, attack vectors, and vulnerability analysis, including:
    • CAPEC
    • ATT&CK
    • STRIDE
Application Security & Dev Sec Ops
  • Experience with application security controls across:
    • Web applications
    • APIs
    • Mobile applications
    • AI systems
  • Knowledge of security frameworks and standards, including:
    • NIST 800-53
    • NIST Cybersecurity Framework (CSF)
    • OWASP ASVS
  • Experience with Application Security design and Dev Sec Ops  practices.
  • Full‑stack knowledge of application architectures, including:
    • Single Page Applications
    • REST APIs
    • SOAP APIs
    • Mobile applications
  • Experience with:
    • Java
    • Java Script
    • Mobile application development
Database, Cloud & Identity Security
  • Knowledge of database architectures, including:
    • Oracle
    • SQL
    • DB2
    • No

      SQL databases
  • Experience with cloud security architecture, design, implementation, and operations.
  • Exposure to IAM controls, including:
    • OAuth 2.0
    • OIDC
    • JWT
  • Strong understanding of cryptography controls:
    • Data at rest
    • Data in motion
Certifications
  • Preferred certifications:
    • CISSP
    • CISM
    • CSSLP
    • CISA
    • CRISC
    • OSCP
Key Responsibilities Threat Modeling & Security Assessment
  • Conduct security risk assessments of applications based on system design and application code implementation.
  • Develop and manage security governance processes and procedures for:
    • Threat modeling programs
    • Application security design
    • Dev Sec Ops  programs
  • Assist in developing threat modeling governance documentation.
  • Develop reports for management related to:
    • Residual risk
    • Non‑compliance
  • Review security controls with application owners to ensure requirements are implemented.
  • Validate security control implementation against scanning tool outputs to support auditability and verification.
Security Governance & Compliance
  • Work with information security leadership to develop strategies and plans to enforce threat modeling and address control gaps.
  • Monitor and track compliance with application owners to ensure security controls are implemented as planned.
  • Assist application teams with security standard exceptions identified through threat modeling.
  • Develop and define security metrics and criteria for information security programs.
Secure Design & Engineering Enablement
  • Develop, maintain, update, and enhance:
    • Secure design patterns
    • Secure coding standards
    • Threat libraries
  • Socialize secure design patterns and secure coding standards with engineering teams.
  • Provide threat modeling consultation and guidance to application teams.
  • Enable strong developer and customer experience while collaborating with application teams.
  • Develop innovative attack techniques to evaluate protective designs and existing mitigations.
Security Strategy & Architecture
  • Participate in developing strategies for information security processes and programs.
  • Document current and future state security capabilities using industry‑leading technologies to improve IT risk management and data protection.
  • Provide security awareness and education on industry trends, efforts, and statistics.
  • Recommend resource types and skillsets required to address security project and process challenges.
  • Support investment decisions through business cases and cost‑benefit analysis.
Agile Delivery & Collaboration
  • Facilitate Agile events to help teams deliver value incrementally and iteratively.
  • Support Program Increment (PI) execution through team‐level events and collaboration with Release Train Engineers (RTE).
  • Support teams in achieving PI objectives.
  • Provide consultation and advice to assess information security risks and implement controls to protect intellectual property and sensitive data.
#J-18808-Ljbffr
Note that applications are not being accepted from your jurisdiction for this job currently via this jobsite. Candidate preferences are the decision of the Employer or Recruiting Agent, and are controlled by them alone.
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary