
Cybersecurity Architect
- Toronto, ON
- Permanent
- Full-time
- Work Location- 335 King Street East, Toronto, ON
- Employee Type - Regular Employee FT Salaried
- Hybrid Work - This position currently offers a hybrid work schedule. Subject to change. The in-office requirement is a minimum of three days per week (Tuesday, Wednesday & Thursday), with the flexibility to work from home on the remaining days.
- Initial Posting Close Date - Septemeber 15, 2025
- Develop and maintain enterprise-wide security architecture for IT, OT, and Cloud.
- Design secure network, cloud (AWS, Azure, GCP), and hybrid environments.
- Create security reference models, segmentation strategies, and governance frameworks.
- Implement controls for ICS, SCADA, and critical infrastructure.
- Conduct risk assessments, threat modeling, and compliance gap analysis.
- Assess vulnerabilities in IT, OT, and cloud systems, including third-party risks.
- Develop mitigation strategies for operational and cloud-specific risks.
- Align security programs with NIST, ISO 27001, IEC 62443, NERC CIP, and other cloud security frameworks.
- Ensure compliance with SOC 2, FedRAMP, GDPR, and industry-specific regulations.
- Establish and enforce security policies, procedures, and baselines.
- Deploy network and cloud security tools (CASB, CSPM, CWPP, IAM, encryption).
- Implement secure architectures for LAN, WAN, DMZ, data centers, and OT networks.
- Integrate monitoring, DevSecOps, and automated response capabilities.
- Partner with IT, OT, cloud, and engineering teams to implement controls.
- Work with vendors, regulators, and leadership on security posture and best practices.
- Mentor team members and support security awareness efforts.
- Develop IR playbooks and disaster recovery plans for IT, OT, and cloud.
- Support forensic investigations and root cause analysis.
- Establish backup and recovery procedures for critical systems.
- Monitor emerging threats and industry trends.
- Conduct architecture reviews and recommend enhancements.
- Evaluate new technologies for adoption.
- Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, Engineering, or a related field.
- A minimum of one advanced certification (e.g., CISSP, ISSAP, SABSA) is required.
- Cloud security certifications such as CCSP or platform-specific credentials (AWS, Azure, GCP) are preferred.
- OT/ICS certifications such as GICSP or GRID are preferred.
- Minimum 7 years of cybersecurity experience, including 3+ years in OT/ICS security and 3+ years in cloud security.
- Strong background in cloud and network security technologies, including TCP/IP, firewalls, IDS/IPS, VPNs, and cloud-native security tools (CASB, CSPM, CWPP).
- Experience with security assessment tools, SIEM, identity management, DevSecOps practices, industrial control systems (SCADA, DCS, PLC) and OT protocols (Modbus, DNP3, EtherNet/IP).
- Familiarity with compliance frameworks (NIST, IEC 62443, NERC CIP, GDPR) and regulated industries (utilities, manufacturing, chemical).