Cybersecurity Architect Category: Cyber Security
Main location: Canada, Ontario, Mississauga
Alternate Location(s): Canada, Alberta, Calgary
Canada, Ontario, Ottawa
Canada, Quebec, Montreal
Canada, Ontario, Toronto
Position ID:J1026-0597
Employment Type: Full Time
Position Description: Location: Can be situated anywhere in Canada within proximity to a CGI office to facilitate a hybrid work model
Bilingualism: English/French highly preferrred
Security Clearance: Ability to obtain Federal level Reliability or Secret Security Clearance.
The Cybersecurity Solution Architect is responsible for designing secure, scalable, and resilient technology solutions that align with organizational security standards, enterprise architecture principles, regulatory requirements, and business objectives.The role provides cybersecurity architecture leadership across cloud, on premises, and hybrid environments and works closely with business stakeholders, enterprise architects, infrastructure and application teams, security operations, risk and compliance teams, and technology vendors.The Cybersecurity Solution Architect will translate business and technical requirements into practical security architectures, identify security risks and control requirements, evaluate technologies, and provide architectural guidance throughout the solution lifecycle.
CGI is providing a reasonable estimate of the pay range for this role. The determination of this range includes factors such as skill set level, geographic market, experience and training, and licenses and certifications. Compensation decisions depend on the facts and circumstances of each case. A reasonable estimate of the current range is $90,000-$140,000. This role is an existing vacancy.
#LI-AB19
Your future duties and responsibilities: Key Responsibilities:
Security Architecture & Solution Design
Design end to end cybersecurity architectures for enterprise applications, infrastructure, cloud platforms, networks, and digital services.
Develop security architecture diagrams, solution designs, security patterns, reference architectures, and technical standards.
Review solution architectures and identify security risks, vulnerabilities, architectural gaps, and required security controls.
Ensure security requirements are incorporated throughout the solution design and implementation lifecycle.
Apply security by design, defense in depth, least privilege, Zero Trust, and secure by default principles.
Provide architectural guidance for on premises, cloud, SaaS, PaaS, IaaS, and hybrid environments.
Evaluate proposed architecture changes and provide recommendations to improve security, resilience, scalability, and operational effectiveness.
Cloud & Infrastructure Security
Design and review security architectures for Microsoft Azure, AWS, and/or Google Cloud environments.
Define security requirements for cloud identity, networking, workloads, storage, encryption, logging, monitoring, and data protection.
Provide guidance on secure cloud landing zones, network segmentation, private connectivity, firewalls, WAF, API security, workload protection, and cloud security posture management.
Assess container, Kubernetes, serverless, and modern application architectures where applicable.
Support secure integration between cloud and on premises environments.
Identity & Access Management
Develop architecture and security patterns for Identity and Access Management (IAM).
Provide guidance on authentication, authorization, Single Sign On (SSO), Multi Factor Authentication (MFA), federation, Privileged Access Management (PAM), and identity governance.
Apply Zero Trust principles to identity, endpoint, application, network, and data access.
Review service accounts, application identities, machine identities, and privileged access models.
Application & Data Security
Provide security architecture guidance throughout the Software Development Lifecycle (SDLC).
Define security requirements for applications, APIs, databases, integrations, and third party services.
Support secure DevSecOps practices, including security testing and controls within CI/CD pipelines.
Advise on encryption, key management, secrets management, certificate management, tokenization, and data loss prevention.
Review application threat models and recommend appropriate mitigating controls.
Support secure adoption of AI, automation, and emerging technologies where applicable.
Security Technology & Controls
Provide architectural guidance and technical oversight across security capabilities including:
SIEM and Security Operations
Endpoint Detection and Response (EDR/XDR)
Network Detection and Response (NDR)
Firewalls, IDS/IPS and network segmentation
Secure Access Service Edge (SASE) and SSE
Cloud security and CNAPP/CSPM
Identity and Privileged Access Management
Data Loss Prevention (DLP)
Vulnerability Management
Email and collaboration security
Web Application Firewalls and API security
Encryption and Key Management
Secrets and Certificate Management
Security automation and orchestration
Backup, recovery, resilience, and ransomware protection
Risk, Governance & Compliance
Perform architectural security assessments and document identified risks and recommended controls.
Translate cybersecurity policies, standards, regulatory requirements, and risk requirements into technical security controls.
Support threat modelling and security risk assessments for new solutions and significant technology changes.
Document architectural decisions, risks, exceptions, assumptions, and compensating controls.
Support compliance with applicable frameworks and standards such as NIST CSF, NIST 800 53, ISO/IEC 27001, CIS Controls, PCI DSS and SOC 2.
Collaborate with Governance, Risk and Compliance teams to ensure appropriate security controls are implemented and evidenced.
Stakeholder & Project Engagement
Act as the cybersecurity architecture representative on technology programs and projects.
Collaborate with Enterprise Architecture, Infrastructure, Cloud, Application Development, Data, Security Operations and business teams.
Translate complex cybersecurity risks and architectural decisions into clear recommendations for technical and non technical stakeholders.
Participate in architecture review boards and security design reviews.
Work with vendors and technology partners to evaluate proposed products and solutions.
Review vendor architectures, security capabilities, integration requirements, and technical proposals.
Provide cybersecurity input into RFPs, RFQs, statements of work, technology evaluations, and procurement activities.
Required qualifications to be successful in this role: QUALIFICATIONS:
Bachelor's degree in Computer Science, Information Technology, Cybersecurity, Engineering, or a related discipline, or equivalent professional experience.
Typically 8+ years of experience in information technology or cybersecurity, including significant experience in security architecture, engineering, or solution design.
Strong understanding of enterprise cybersecurity architecture and security design principles.
Experience designing security solutions across cloud, on premises, and hybrid environments.
Strong knowledge of network security, IAM, application security, cloud security, endpoint security, data protection, and security monitoring.
Experience conducting security architecture reviews, risk assessments, and threat modelling.
Understanding of modern application architectures, APIs, microservices, containers, and DevSecOps.
Ability to develop architecture diagrams, technical specifications, security requirements, and solution documentation.
Strong analytical, problem solving, communication, and stakeholder management skills.
Ability to communicate cybersecurity risks and technical concepts effectively to both technical teams and senior business stakeholders.
PREFERRED QUALIFICATIONS
Experience with technologies and platforms such as:
Microsoft Azure and Microsoft 365
Amazon Web Services (AWS)
Google Cloud Platform (GCP)
Microsoft Entra ID
Microsoft Sentinel
Microsoft Defender
Palo Alto Networks
Fortinet
CrowdStrike
CyberArk
Okta
Splunk
Zscaler
ServiceNow
Relevant professional certifications are considered an asset, including:
CISSP
CCSP
SABSA
TOGAF
Microsoft Certified: Cybersecurity Architect Expert
AWS Certified Security - Specialty
Google Professional Cloud Security Engineer
GIAC security certifications
KEY COMPETENCIES
The successful candidate will demonstrate strong capabilities in:
Cybersecurity solution architecture
Enterprise security architecture
Cloud and hybrid security
Zero Trust architecture
Identity and access management
Network and infrastructure security
Application and API security
Data security and privacy
Threat modelling and security risk assessment
Security technology evaluation
Architecture governance
Technical documentation
Stakeholder engagement and consulting
Vendor and solution assessment
Technical leadership and decision making
Use of the term 'architect' in this job posting refers to the technical sense related to Information Technology (IT) and does not imply that the individual practices architecture or possesses the requisite license as prescribed by the applicable provincial or territorial architect regulator. We are seeking individuals with expertise in IT architect-related functions, but licensure from an architect regulator is not a prerequisite for this position. Architecture is a regulated profession in Canada which is restricted in terms of use of titles and designation.
Skills: - Cybersec. Incident Remediation
- Risk analysis
- Security Architecture
- Security assessment
- Solutions Architecture