Business Unit
Regular, Full time
Closing Date: October 20, 2026
The Ontario Securities Commission (OSC) is seeking a strategic and experienced
Senior Security Architect to lead the evolution of our enterprise security architecture and cybersecurity strategy.
In this highly visible role, you will partner with business and technology leaders to strengthen the OSC's security posture, mitigate emerging threats, and ensure security is embedded across technology solutions, business initiatives, cloud environments, and third-party relationships. You will serve as a trusted advisor and subject matter expert, helping to safeguard the systems and information that support Ontario's capital markets.
What You'll DoLead Security Strategy & Architecture- Define and evolve the OSC's enterprise security architecture, standards, controls, and governance framework.
- Design and recommend security solutions that align with business objectives and industry best practices.
- Identify emerging threats, assess architectural risks, and develop mitigation strategies.
- Evaluate and recommend new security technologies and tools to strengthen cybersecurity capabilities.
- Lead security architecture reviews and threat modeling activities for new initiatives, projects, and technology solutions.
- Embed Security-by-Design and Zero Trust principles into solution design and Architecture Review Board (ARB) processes.
- Develop and maintain security architecture roadmaps aligned with OSC's strategic and cybersecurity objectives.
- Assess emerging technologies, including AI, automation, and digital innovation platforms, for security and risk implications.
- Provide leadership on identity security, privileged access management (PAM), conditional access, Zero Trust architecture, and secure access strategies.
Drive Risk Management & Compliance- Lead threat and risk assessments for new and existing technologies, projects, and third-party engagements.
- Establish security metrics, KRIs, and KPIs to support informed decision-making.
- Conduct security reviews and provide recommendations to improve controls and security effectiveness.
- Support compliance with industry frameworks such as NIST, CIS Controls, and ISO 27001.
- Support the development and maintenance of security policies, standards, reference architectures, and control frameworks aligned with NIST CSF 2.0, ISO 27001, and industry best practices.
- Lead Information Security Assessments (ISAs), threat and risk assessments, and cybersecurity due diligence activities.
Strengthen Third-Party & Cloud Security- Assess suppliers and vendors for security risks and compliance.
- Review security assurance reports and collaborate on contractual security requirements.
- Guide secure cloud adoption across Azure and AWS environments.
- Promote secure development practices and DevSecOps integration.
- Assess third-party cybersecurity programs beyond SOC reports and certifications.
- Evaluate cloud security architectures across Azure, AWS, SaaS, and hybrid environments.
- Support vendor security reviews, procurement initiatives, and technology risk assessments.
Provide Leadership & Advisory Expertise- Act as a trusted advisor to senior leaders, project teams, and technology stakeholders.
- Contribute to cybersecurity strategy, governance, and awareness initiatives.
- Support vendor evaluations, procurement activities, and strategic technology decisions.
- Provide technical leadership and mentorship across security and cross-functional teams.
What You Bring- University degree in Computer Science, Engineering, or a related discipline.
- 12+ years of progressive experience in Security Architecture, Cybersecurity, Enterprise Architecture, or Information Security, including experience providing strategic guidance to senior leadership.
- Expertise in security architecture, threat and risk assessment, governance, and compliance.
- Strong knowledge of cloud security, application security, network security, and secure systems design.
- Ability to translate complex technical risks into practical business recommendations.
- Exceptional communication, stakeholder management, and influencing skills.
- CISSP strongly preferred. CISM, CCSP, CISA, TOGAF, SABSA, Azure Security, AWS Security, or equivalent security architecture certifications are considered strong assets.
- Experience with threat modeling methodologies (e.g., STRIDE), cloud security architecture, Zero Trust, third-party risk management, security governance, and cybersecurity transformation initiatives.
Grow your career and make a difference working at the OSC.
* OSC Employees: please apply in Workday using the Browse Jobs feature within your Jobs Hub *
We thank all applicants for their interest in the Ontario Securities Commission. We will contact those selected for an interview.