OverviewAI Engineering transforms emerging AI capabilities and business needs into secure, scalable, production-ready applications and platforms for KPMG Canada. The team works across application, data, platform and emerging AI technologies in close collaboration with ITS, Security, Risk, Legal, Global teams and business stakeholders.
As the Enterprise Architect for AI Engineering, you will provide architectural leadership across our technology portfolio, with particular emphasis on security, compliance, risk management and production readiness. You will manage high-level technical architecture, ensure alignment with KPMG enterprise standards, and help establish the controls, patterns and technology choices that enable secure delivery.
You will also serve as a key interface between AI Engineering and KPMG's broader architecture, security and technology organizations, coordinating the reviews and approvals required to move solutions safely into production.
What you will do- Author the architecture of AI Engineering solutions, creating and maintaining high-level architecture documentation and Technical Architecture Documents (TADs) covering application, data, integration, cloud infrastructure, network, identity, security, deployment and operations.
- Ensure new solutions and material changes align with KPMG enterprise architecture, cloud, security, data and technology standards.
- Lead security architecture and production-readiness reviews, identifying required controls, risks and remediation activities, and coordinating the approvals required to move solutions into production.
- Govern vulnerabilities and security findings continuously across applications, infrastructure, containers, dependencies and cloud environments; assess risk, drive remediation and coordinate mitigating controls, exceptions or risk acceptance where required.
- Review significant application, infrastructure, network, platform and AI-related changes for architecture, security and compliance impact.
- Establish and evolve reusable architecture patterns, security controls and guardrails that enable teams to deliver securely and consistently.
- Review, select and govern SDLC tooling used by development teams, including source control, CI/CD, infrastructure-as-code, security scanning, artifact management and deployment tooling, coordinating enterprise and security approvals where required.
- Act as the primary compliance and control reviewer for AI Engineering, maintaining required evidence and supporting internal reviews, external assessments, certifications and audits.
- Partner with engineering, DevOps/SRE, platform and product teams to embed secure-by-design practices, including identity, least privilege, network security, secrets management, logging, monitoring and data protection.
- Assess security and architecture implications of AI technologies, including models, agents, enterprise data integrations, AI platforms, content-safety controls and third-party services.
- Maintain visibility into key architecture decisions, risks, exceptions and remediation commitments, and communicate material issues to AI Engineering leadership and relevant enterprise stakeholders.
- Monitor developments in cloud, cybersecurity, AI security, enterprise architecture and regulatory requirements and translate them into practical standards and controls.
Focus Area
Approx. %
Responsibilities
Architecture & Technical Governance
30%
Own high-level architecture and TADs; review solution designs and material changes; ensure alignment with enterprise architecture, cloud, data and technology standards.
Security & Vulnerability Governance
20%
Lead security architecture reviews; oversee vulnerabilities and findings; assess risk; drive remediation and mitigating controls; coordinate security exceptions where required.
Production Readiness & Enterprise Approvals
25%
Coordinate the architecture, security and compliance path to production and ensure required reviews, controls, evidence and approvals are completed.
Compliance, Risk & Assurance
15%
Act as AI Engineering's primary compliance reviewer; monitor control effectiveness; maintain evidence and support audits, certifications and assessments.
Standards, Guardrails & SDLC Tooling
10%
Define reusable architecture and security guardrails; review and govern development/SDLC tooling; translate evolving technology and security requirements into practical engineering standards.
What you bring to the role- A university degree in computer science, engineering, cybersecurity, information systems or a related discipline.
- Significant experience in enterprise, solution, cloud or security architecture within complex enterprise environments.
- Strong experience designing and reviewing production-grade cloud applications and platforms across applications, APIs, data, infrastructure, identity, networking, security and operations.
- Strong knowledge of cloud security and secure-by-design principles, including identity and access management, least privilege, network security, encryption, secrets management, logging, monitoring and vulnerability management.
- Experience with Microsoft Azure and cloud-native architecture, preferably including Azure networking, Entra ID, Key Vault, Application Gateway/WAF, Azure Front Door, Azure Container Apps or Kubernetes, Azure Monitor, Defender for Cloud and Sentinel.
- Strong understanding of modern DevSecOps and SDLC tooling, including source control, CI/CD, infrastructure-as-code, software composition analysis, SAST, container/image scanning and artifact management.
- Experience working with technologies such as GitHub, Terraform, containers and automated deployment pipelines, with the ability to assess new development tooling from architecture, security and enterprise-readiness perspectives.
- Strong understanding of security and compliance frameworks and control environments, such as NIST-based controls,
- ISO standards, secure SDLC practices and enterprise technology risk management.
- Experience supporting architecture, cybersecurity, risk, compliance and audit reviews and producing the documentation and evidence required to demonstrate control effectiveness.
- Experience assessing vulnerabilities and security findings, determining risk, identifying mitigating controls and working through risk-acceptance and exception processes.
- Familiarity with security considerations for generative AI and agentic systems, including enterprise data access, identity, model and service integrations, content safety and governance.
- Ability to translate complex technical and security topics into clear architecture decisions, risks and recommendations for technical teams and senior stakeholders.
- Strong collaboration, organizational and written communication skills, with the ability to drive architecture, security and approval activities across multiple enterprise groups.
KPMG Ontario Region Pay Range InformationThe expected base salary range for this position is $105,000 to $155,000 and may be eligible for bonus awards. The determination of an applicant's base salary within this range is based on the individual's location, skills & competencies, and unique qualifications. In addition, KPMG offers a comprehensive and competitive Total Rewards program.