Senior Application Security Architect, Enterprise Technology
$115,000–$130,000 year
On-siteToronto, Ontario, Canada
Job Summary
Define and maintain practical secure software development lifecycle (SDLC), application security architecture, and production-readiness standards. Establish risk-based review criteria to perform security reviews of internet-facing, sensitive-data, AI-enabled, and other high-risk applications. Conduct threat modelling and architecture assessments covering applications, APIs, data flows, identity, cloud services, third-party dependencies, and deployment topology. Perform targeted source-code reviews of security-critical areas, including authentication, authorization, input handling, data access, secrets, session management, and integrations. Assess controls related to identity, API security, encryption, secrets management, network exposure, segmentation, logging, monitoring, and data protection. Document and prioritize material risks and remediation; validate that required controls are addressed, maintain review evidence, and route material exceptions through formal risk acceptance. Develop reusable secure reference architectures, design patterns, checklists, and guidance that help teams deliver secure and supportable solutions. Define and support appropriate automated security controls within CI/CD pipelines, including code, dependency, secret, container, and infrastructure-as-code scanning. Assess open-source and third-party components for provenance, known vulnerabilities, patching practices, and supportability, and identify licensing concerns for review with Legal or Procurement. Apply established application, cloud, identity, data, and software supply-chain security principles to AI/LLM applications, self-hosted models, AI coding tools, and other emerging technologies. Partner with cybersecurity, cloud services, infrastructure, analytics, development teams, and business stakeholders to provide practical guidance and support remediation while maintaining clear ownership within accountable teams. Support selected proofs of concept, validation testing, and post-deployment verification where hands-on technical involvement adds value.
Required Qualifications
- 7+ years of relevant experience across application security, software/cloud engineering, DevSecOps or cybersecurity, with significant application security or secure architecture experience
- Proven experience with security architecture reviews, threat modelling and secure design assessments for modern applications, APIs and cloud services
- Strong knowledge of secure SDLC and application security controls, including identity and access, API security, secrets management, encryption and data protection
- Strong coding and code-review skills in at least one modern language, with the ability to assess unfamiliar codebases
- Experience with Python, C#/.NET, JavaScript/TypeScript, Java or SQL
- Experience securing cloud applications across identity, networking, APIs, containers, managed services and ingress
- Practical knowledge of DevSecOps and application security testing, including CI/CD controls, SAST, DAST, SCA, secrets scanning and container security
- Strong judgement and communication skills, with the ability to translate security risks into practical recommendations and influence stakeholders without direct authority
- Experience with Microsoft Azure and Entra ID, including identity, secret management, networking and application hosting
- Experience assessing AI/LLM applications, self-hosted models or AI-assisted development; familiarity with Ollama, MCP, RAG, AI agents or similar technologies
- Experience assessing open-source software, third-party dependencies and software supply-chain risk, including vulnerability and patch management
- Financial services or other regulated-industry experience, and/or relevant application security or cloud certifications
- Applicants must be legally entitled to work in the country where the role is based, or eligible for any necessary work authorization or permit
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.