Senior Application Security Architect, Enterprise Technology

ONCAP

$115K — $130K *
Enterprise Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 7+ years of experience in application security, software/cloud engineering, DevSecOps or cybersecurity
  • Significant experience in application security architecture and secure design assessments
  • Strong knowledge of secure SDLC and application security controls
  • Proficient coding skills in modern programming languages, especially Python, C#/.NET, JavaScript/TypeScript, Java or SQL
  • Experience securing cloud applications and managing identity, networking, and APIs
  • Familiarity with DevSecOps practices and application security testing methodologies
  • Excellent judgement and communication skills for stakeholder engagement

Responsibilities

  • Define secure software development lifecycle (SDLC) and application security standards
  • Establish risk-based criteria for security reviews of high-risk applications
  • Conduct comprehensive threat modelling and architecture assessments
  • Perform in-depth source-code reviews of critical security areas
  • Assess security controls across identity, API security, encryption, and more
  • Document and prioritize risks, ensuring proper controls are in place
  • Develop reusable secure reference architectures and guidance for teams
  • Support automation of security controls within CI/CD pipelines
  • Evaluate open-source and third-party components for vulnerabilities
  • Apply security principles to AI/LLM applications and emerging technologies
  • Collaborate with various teams to ensure effective security practices
  • Contribute to proofs of concept and validation testing

Benefits

  • Opportunity to work with emerging technologies and AI/LLM platforms
  • Collaborative work culture with cross-functional teams
  • Exposure to a diverse range of cloud security challenges
  • Access to continuous learning and professional development resources
  • Influence and shape security practices within the organization
Full Job Description
The Opportunity:

We are seeking an experienced security professional to join our Enterprise Technology group as a Senior Application Security Architect, based in Toronto. Reporting to the Manager, IT Cloud Services, this role will strengthen how Onex assesses and secures internally developed, vendor-integrated, open-source and emerging technology solutions. The successful candidate will lead practical application security architecture reviews, threat modelling and secure software development lifecycle standards; perform targeted reviews of security-critical code and controls; and partner with technology and business teams to move solutions safely into production. The role has a strong cloud application security focus, with exposure to AI/LLM platforms and other emerging technologies, and requires someone who can balance technical depth, sound judgement and collaborative delivery.

Key Responsibilities:
  • Define and maintain practical secure software development lifecycle (SDLC), application security architecture and production-readiness standards.
  • Establish risk-based review criteria and perform security reviews of internet-facing, sensitive-data, AI-enabled and other high-risk applications and platforms.
  • Conduct threat modelling and architecture assessments covering applications, APIs, data flows, identity, cloud services, third-party dependencies and deployment topology.
  • Perform targeted source-code reviews of security-critical areas, including authentication, authorization, input handling, data access, secrets, session management and integrations.
  • Assess controls related to identity, API security, encryption, secrets management, network exposure and segmentation, logging, monitoring and data protection.
  • Document and prioritize material risks and remediation; validate that required controls are addressed, maintain review evidence and route material exceptions through formal risk acceptance.
  • Develop reusable secure reference architectures, design patterns, checklists and guidance that help teams deliver secure and supportable solutions.
  • Define and support appropriate automated security controls within CI/CD pipelines, including code, dependency, secret, container and infrastructure-as-code scanning, in partnership with the teams that own implementation and operation.
  • Assess open-source and third-party components for provenance, known vulnerabilities, patching practices and supportability, and identify licensing concerns for review with Legal or Procurement.
  • Apply established application, cloud, identity, data and software supply-chain security principles to AI/LLM applications, self-hosted models, AI coding tools and other emerging technologies.
  • Partner with cybersecurity, cloud services, infrastructure, analytics, development teams and business stakeholders to provide practical guidance and support remediation while maintaining clear ownership within accountable teams.
  • Support selected proofs of concept, validation testing and post-deployment verification where hands-on technical involvement adds value.

Candidate Profile:
  • 7+ years of relevant experience across application security, software/cloud engineering, DevSecOps or cybersecurity, with significant application security or secure architecture experience.
  • Proven experience with security architecture reviews, threat modelling and secure design assessments for modern applications, APIs and cloud services.
  • Strong knowledge of secure SDLC and application security controls, including identity and access, API security, secrets management, encryption and data protection.
  • Strong coding and code-review skills in at least one modern language, with the ability to assess unfamiliar codebases. Experience with Python, C#/.NET, JavaScript/TypeScript, Java or SQL is particularly relevant.
  • Experience securing cloud applications across identity, networking, APIs, containers, managed services and ingress.
  • Practical knowledge of DevSecOps and application security testing, including CI/CD controls, SAST, DAST, SCA, secrets scanning and container security.
  • Strong judgement and communication skills, with the ability to translate security risks into practical recommendations and influence stakeholders without direct authority.

Preferred Qualifications:
  • Experience with Microsoft Azure and Entra ID, including identity, secret management, networking and application hosting.
  • Experience assessing AI/LLM applications, self-hosted models or AI-assisted development; familiarity with Ollama, MCP, RAG, AI agents or similar technologies is an asset.
  • Experience assessing open-source software, third-party dependencies and software supply-chain risk, including vulnerability and patch management.
  • Financial services or other regulated-industry experience, and/or relevant application security or cloud certifications.

Additional information:

The expected base salary range for this position is C$115,000-130,000 on an annualized basis.

All-in compensation may vary based on several factors, such as relative experience, education level attained, professional certifications, geographical location, etc. to account for local market conditions.

This position is for a current vacancy.

#LI-DNI

Similar Jobs

More Jobs at ONCAP

More Enterprise Technology Jobs

Find similar Senior Application Security Architect, Enterprise Technology jobs: