Job DescriptionReferral Level: Level 3Location: TorontoOverall Job PurposeThe Director, Security Architecture & Advisory sets security architecture direction for a portfolio or platform/domain. Translates enterprise standards into actionable security guidance and advice. The role defines security architecture standards and patterns, guides target-state roadmaps and resolves cross-initiative and cross-solution security architecture complexity (dependencies, integration, sequencing, and technical debt) to enable delivery through clear security standards, pragmatic security advisory support and timely risk-based decisions.
Key AccountabilitiesSecurity Architecture
- Set security architecture direction for a portfolio or platform/domain and ensure alignment to enterprise standards, technology strategy, and business priorities.
- Define and govern security domain standards, patterns, and reference designs (including security technology guardrails).
- Define and evolve the Security Domain Target Architecture and target-state roadmap, aligning sequencing and investments to multi-year priorities.
- Resolve cross-solution security architecture issues (integration, dependencies, interoperability) and drive pragmatic decisions on trade-offs and risk.
- Guide and coach security architects, ensuring consistent application of security principles and quality expectations without direct people management.
- Identify security architecture risk and technical debt and sponsor remediation and modernization plans.
- Participate in security architecture chapter activities (e.g., security standards, patterns, knowledge sharing, and peer reviews) to strengthen security practice consistency and capability maturity.
Security Advisory
- Provide trusted security advisory services to business and technology leaders, enabling risk-informed decisions and secure technology adoption.
- Lead Threat/Risk Assessments and security reviews for major programs, platforms, and initiatives, ensuring alignment with enterprise security standards, regulatory requirements, and risk appetite.
- Evaluate new technologies and vendors to determine strategic fit, advise on security risks and compensating controls for AI, data, identity, infrastructure, and third-party solutions.
AI Security
- Establish security requirements for AI platforms, control planes, agent frameworks, retrieval systems, model training, and inference environments.
- Evaluate AI platforms, models, and third-party AI services to determine security posture, architectural fit, data protection requirements, and enterprise adoption risks.
- Identify and address AI-specific security threats, including prompt injection, model poisoning, data leakage, excessive agent autonomy, insecure tool integrations, and AI supply chain risks.
- Provide security guidance for AI use cases involving sensitive, regulated, or confidential data, ensuring appropriate controls for data classification, access management, encryption, and model usage.
- Define security guardrails for AI agents, including authorization boundaries, tool access controls, execution environments, monitoring requirements, and human oversight mechanisms.
- Partner with engineering, data, privacy, and risk teams to embed secure-by-design principles throughout the AI solution lifecycle.
QualificationsSecurity Architecture and Advisory
- Extensive experience leading security architecture and advisory across complex, enterprise-scale portfolios (solution and/or domain) and enterprise platforms.
- Strong capability in security governance, standards, target-state design, integration, and roadmap definition.
- Proven ability to influence senior stakeholders and drive outcomes across multiple teams without direct line authority.
- Skilled in facilitating trade-offs and risk decisions while balancing strategic coherence with delivery pragmatism.
- Deep expertise in security architecture, cloud technologies, application security, identity, data protection, and technology risk management.
AI Security
- Strong understanding of AI security risks, including prompt injection & agent hijacking; sensitive data exposure; excessive agent authority & privilege escalation; model, memory & supply-chain manipulation.
- Strong understanding of data protection, identity and access management, cryptography, and cloud security controls as applied to AI systems.
- Experience establishing governance and security requirements for AI agents, autonomous workflows, human-in-the-loop decision processes; aligned with emerging AI regulatory requirements, responsible AI practices, and AI risk management frameworks (e.g., NIST AI RMF).
- Experience securing AI platforms such as Azure OpenAI, Anthropic Claude, Google Gemini/Vertex AI, Amazon Bedrock, Salesforce Agentforce and equivalent enterprise AI services.
The expected annual base salary range for this role is $149,500 - $192,500, which is determined based on skills, knowledge and experience and geographic location. In addition to base salary, this role is eligible for annual short-term incentive, health and well-being benefits, retirement and savings plan, paid time off and career development.
Benefits: - COMPETITIVE COMPENSATION & RECOGNITION: competitive base salary, performance-weighted bonus, education/career support, option to join Employee Share Purchase Plan with employer matching component.
- EMPLOYEE BENEFITS & INSURANCE: competitive health and dental coverage, flexible plan for you and your family and short-term & long-term disability plans.
- RETIREMENT SAVINGS PROGRAMS: voluntary Defined Contribution Pension Plan
- WORK LIFE BALANCE: paid volunteer days, competitive time off, including 10 wellness days off, WorkPerks discount program, hybrid & flex work arrangements.
- INCLUSIVE CULTURE AND DIVERSITY: living our core values: Be a Team, Be Accountable, Be Better, engaging with community through Business Resource Groups (BRG communities are volunteer employee-led groups formed around a common interest, identity, or background).
How to Apply: Interested candidates are invited to submit their resume and a cover letter detailing their qualifications and experience to
https://www.mackenzieinvestments.com/en/careers.
Artificial Intelligence in Recruitment: As part of our Talent Acquisition process, we may use artificial intelligence and automated tools to support activities such as candidate sourcing, application review, and interview scheduling. These tools support the recruitment process; all hiring decisions are made by people.
We thank all applicants for their interest in Mackenzie Investments; however, only those candidates selected for an interview will be contacted.
Please apply by September 8 2026.
#LI-JS2
#LI-Hybrid