Senior Security Architect
Vancity View all jobs
- Vancouver, BC
- $130,900-157,000 per year
- Permanent
- Full-time
- Design and establish enterprise application security architecture frameworks, patterns and reference models aligned with business objectives and risk tolerance
- Lead architecture reviews of applications and systems to identify security gaps and recommend appropriate controls
- Architect security solutions for authentication, authorization, encryption, and secure communication channels
- Develop and maintain security baselines, standards, and patterns for different technology stacks (web, mobile, API, microservices) and deployment models
- Providing hands-on security architecture support for application, infrastructure, and cloud initiatives, aligned with industry best practices
- Participating in security risk assessments across projects and operational processes, recommending mitigation and remediation strategies
- Collaborating with enterprise architecture and technology teams to deliver practical, risk-based security guidance
- Supporting secure application design and DevSecOps practices across the SDLC
- Contribute to the development of enterprise security documentation such as policies, standards, baselines, guidelines, and procedures.
- Provide mentorship and direction to junior security architects
- Manage and participate in the Application Security Champions program
- Collaborate with project leads to define requirements, design controls, and implement scalable security services aligned with Vancity’s cybersecurity vision.
- Partner with business units and enterprise architecture teams to deliver risk-based security guidance and support an integrated security service portfolio.
- Assess security risks across programs, projects, and operational processes, and recommend architecture remediation strategies.
- Stay current on cyber threats and emerging technologies to inform investigation techniques and enhance incident response capabilities.
- Bachelor’s degree in STEM, Computer Science, Engineering, or a closely related field
- 12+ years of experience in Information Security
- 5+ years of experience in Security Architecture
- Experience contributing to secure architecture design across areas such as networking, cloud, identity, APIs, and application security
- Experience designing/engineering solutions to meet PCI DSS 4 requirements
- Experience in designing secure architectures e.g. networking, Cloud, IDP, API, tokenization, Identity management (OAuth2, OIDC, SAML), microservices, Zero trust Architectures etc.
- Hands-on experience with DevSecOps and application development within a formal SDLC
- Familiarity with secure coding practices and security testing tools such as SAST, DAST, SCA, and IAST
- Threat modeling experience and understanding of common attack vectors
- Exposure to penetration testing activities or remediation efforts (certifications such as OSCP or GPEN would be an asset)
- Experience working with & securing public cloud platforms (Azure preferred)
- Awareness of Canadian regulatory environments (e.g., OSFI, PIPEDA) and their impact on security design
- Knowledge of security frameworks such as NIST CSF, NIST 800-53, ISO 27001, PCI DSS
- Security certifications such as CISSP, CSSLP, CCSP, SABSA, CISM, CISA is an asset
- Strong stakeholder engagement and communication skills across technical and non-technical audiences.
- Collaborative – you enjoy working alongside senior architects, engineers, and business partners to solve complex problems
- Curious & Growth-Oriented – you’re eager to deepen your security architecture expertise and stay current in a rapidly evolving field
- Analytical – you can assess risks, evaluate trade-offs, and recommend pragmatic security solutions
- Organized & Reliable – you manage competing priorities effectively and deliver high-quality work with consistency
- Self-Motivated – you take initiative, follow through on commitments, and seek opportunities to learn and improve
- Living Wage Employer: We’re the largest private-sector Living Wage Employer in Canada and consistently ranked among Canada’s Top Employers.
- Customizable Benefits: Permanent employees receive flexible benefit packages that can be tailored annually to meet evolving needs.
- Generous Vacation: New employees start with 3-4 weeks of vacation per year, with additional days earned over time.
- Extra Stat Holidays: In addition to BC’s 11 statutory holidays, we offer 2 extra days, plus care days for personal or family illness.
- Immediate Health Coverage: Health and dental benefits begin on your hire date, with three levels of coverage to choose from.
- Defined Benefit Pension: Our retirement plan provides a guaranteed income for life, recognizing that retirement looks different for everyone.