Senior Security Architect

Xchange Software — Canada · Posted ~2 hours ago

Senior Contract Hybrid

Skills

cybersecurity security architecture enterprise security threat modeling cloud security enterprise architecture security frameworks

🔓 Log in to save this job, tailor your resume & track your apply process — 7 days free, no card needed.

Log in to add to target list

Summary ✨ AI‑Generated

Seeking an experienced security professional to define enterprise security standards, guide architecture decisions, lead reviews, and drive secure technology initiatives across large-scale environments.

Highlights

Senior-level security architecture role focused on enterprise strategy, technology leadership, and designing secure solutions across complex environments.

Description

There are Multiple Openings for Security Consultant like Security Analyst/Engineer/Lead/Architect Position: 1) Role: Senior Security Architect Type: Contract Location: Mississauga, ON – (Hybrid- 3 days in office) Duration: 9+ months Primary focus: Security strategy, enterprise architecture, and executive influence. Target experience: 10+ years in cybersecurity, including 5+ years in architecture roles; experience in enterprise-scale organizations. What this person should be able to do · Define enterprise security architecture standards and roadmaps. · Review major technology initiatives and provide security design guidance. · Lead architecture reviews across cloud, applications, infrastructure, and third-party solutions. · Create security patterns, standards, and reference architectures. · Drive Secure by Design initiatives and lead threat modeling for critical initiatives. · Evaluate emerging technologies and associated risks. · Influence technology and business stakeholders at director and executive levels. Key technical / capability areas · Strong AWS and Azure knowledge. · Identity and access management (IAM). · Network and application security. · Executive communication and architecture review board experience. What strong candidates will demonstrate · Can connect security controls to business objectives. · Embeds security early enough to prevent design-related issues. · Communicates trade-offs clearly and credibly with senior stakeholders. Position: 2) Role: Security Architect Type: Contract Location: Mississauga, ON – (Hybrid- 3 days in office) Duration: 9+ months Primary focus: Solution design and project delivery. Target experience: 5-10 years in cybersecurity. What this person should be able to do · Partner with project teams to design secure solutions. · Conduct architecture and design reviews. · Develop security requirements for projects and vendors. · Perform threat modeling and risk assessments. · Support cloud, application, and infrastructure initiatives. · Work with engineers to implement security controls. · Review vendor security architectures. Key technical / capability areas · Strong understanding of cloud, network, infrastructure, and application security. · Experience with security frameworks and best practices. · Ability to balance risk with business and delivery requirements. What strong candidates will demonstrate · Provides timely, practical security guidance. · Identifies and mitigates risk before production. · Works as a partner to engineering and infrastructure teams rather than as a blocker. Position: 3) Role: Security Engineer Type: Contract Location: Mississauga, ON – (Hybrid- 3 days in office) Duration: 9+ months Primary focus: Build, implement, and operate security technologies. Target experience: 3-8 years in cybersecurity or infrastructure engineering. What this person should be able to do · Deploy and maintain security platforms and configure/tune security controls. · Implement automation and integrations between security tools. · Support incident response investigations. · Develop detection rules and monitoring capabilities. · Manage cloud security controls and perform security testing/validation. · Support vulnerability remediation efforts. Key technical / capability areas · SIEM: CrowdStrike Next-Gen SIEM, Microsoft Sentinel, Splunk or QRadar. · SOAR platforms. · EDR/XDR solutions. · AWS and Azure security services. · PowerShell and/or Python automation. · IAM and vulnerability management tooling. What strong candidates will demonstrate · Strong troubleshooting ability. · Hands-on experience implementing enterprise security solutions. · Improves automation, reduces manual effort, and strengthens operational security. Position: 4) Role: Application Security Analyst Type: Contract Location: Mississauga, ON – (Hybrid- 3 days in office) Duration: 9+ months Primary focus: Secure software delivery, application risk reduction, and developer enablement. What this person should be able to do · Implement and govern Secure SDLC practices. · Perform application security assessments and code review. · Lead or support threat modeling. · Operate or interpret SAST, DAST, SCA, and secrets-scanning capabilities. · Provide developer security training and promote secure coding practices. · Coordinate vulnerability management and remediation across application teams. Key technical / capability areas · Secure SDLC. · Application security testing and code review. · Threat modeling. · SAST, DAST, SCA, and secrets scanning. · Developer security education and remediation coordination. What strong candidates will demonstrate · Can translate findings into actionable guidance for developers. · Understands both technical application risk and the software delivery lifecycle. · Helps teams fix issues rather than only identifying them. Position: 5) Role: Security Operations Analyst / Engineer Type: Contract Location: Mississauga, ON – (Hybrid- 3 days in office) Duration: 9+ months Primary focus: Security monitoring, threat detection, investigation, response, and operational automation. What this person should be able to do · Monitor security events and support incident response. · Develop and improve threat detection and investigation workflows. · Work with SIEM and SOAR platforms. · Develop playbooks and automation for repeatable response activities. · Support endpoint and cloud security operations. Key technical / capability areas · SIEM and SOAR platforms. · Threat detection and investigation. · Incident response workflows. · Playbook development and automation. · Endpoint and cloud security operations. What strong candidates will demonstrate · Demonstrates analytical depth during investigations. · Can tune detection and response processes to reduce noise and improve speed. · Looks for opportunities to automate repeatable operational work.