Talent.com
freelance.ca
SecDesign Security Architectfreelance.ca • Montreal, Canada
SecDesign Security Architect

SecDesign Security Architect

freelance.ca • Montreal, Canada
30+ days ago
Job type
  • Full-time
Job description
Role: SecDesign Security ArchitectLocation: Montreal, QC - Hybrid – 3 days onsite in a weekContract RoleRole Descriptions: The mission of the SecDesign team is to provide security architecture assessments of technology systems and processes to identify business risks and recommend remedial action based on established security standards or security best practices. The SecDesign Generalist is an internal consultant that is working on multiple security architecture and design assessments spanning multiple classes of technologies. It is an opportunity to get involved in multiple business units and technologies inherent to the mission of SecDesign. The Integrator works with team members (Technology, Business, Suppliers, Stakeholders and Partners) globally to perform SecDesign assessments. To be successful as an Integrator the candidate must have broad technology experience coupled with risk management, communication, and time management skills. The candidate will also be working with a global team of experts on modernizing the Firm’s SDLC platform to enable deployment automation to private and public cloud endpoints and SaaS-based tooling. This role affords the opportunity to get in on the ground floor to help build the next generation of development and deployment tooling across a diverse set of tech stacks for the next decade A SecDesign Generalist has the following responsibilities: 1. Lead SecDesign deep dives with the requestor of the assessment. 2. Prioritize risks identified in relation to business risks. 3. Conduct assessment and provide technology risk/requirements to the requestor. Areas covered: a. Authentication, Authorization, Auditing b. Application Security – Session Security, Vulnerability/Pen Testing items, Input Validation c. Secure data transport and storage d. Network Security Principles and best practices. e. Cloud Security Principles and best practices 1. Periodically review security reference architecture (security blueprints) and conduct updates/enhancements. 2. Participate in various Operational and Technology Risk governance processes. 3. Assist in identifying new areas and opportunities of technology investment for the firm.Skills and Experience Soft Skills (Required) 1. Excellent communication skills: written, oral, presentation, listening. 2. Ability to influence through factual reasoning. 3. Time management: ability to handle multiple concurrent assessments, plan based deliverable management, strong follow up and tracking. 4. Strong focus on delivery when presented with short timelines and increased involvement from senior management. 5. Ability to adjust communication of technology risks vs business risks based on the audience. Security Architecture Skills 1. Required – In depth knowledge of application, network, and platform security vulnerabilities. Ability to explain these vulnerabilities to developers. 2. Required – Experience in conducting Information Security, IT Security, Audit assessments. Presenting the outcomes of the assessment and obtaining buy in. 3. Required – Strong focus on reviewing technical designs and functional requirements to identify areas of Security weakness. 4. Required – Knowledge of Cloud Service Providers (AWS/Google/Azure) cloud, DevOps and CI/CD 5. Required – The candidate must have working experience in at least three of the following application/network security domains: a. Authentication: SAML, SiteMinder, Kerberos, OpenId b. Entitlements and identity management c. Data protection, data leakage prevention and secure data transfer and storage d. App Security - validation checking, software attack methodologies. e. Cryptography – encryption and hashing 6. Desired - Prior experience administering systems for version control (Bitbucket, Github), issue tracking (Jira), continuous integration (Jenkins, Github Actions), or release management. 7. Desired – Knowledge of standard network model and the risks that present at each layer, the functions of network equipment such as switches, routers, firewalls, proxies, VPNs, and load-balancers, and understanding of common network architectures. 8. Desired - The candidate must have working knowledge of the primary operating systems (Unix, Windows, z/OS, Mac OS), the configuration and management of that platform at an enterprise scale, the security risks to that platform, and how to mitigate those risks. 9. Desired - experience in testing tools, at least one of Veracode, Fortify, OunceLabs, AppScan, WebInspect, BurpDevelopment Experience 1. Required – Even though the SecDesign Integrator role is not a development role, the candidate must have previous background in programming, design, and application architecture. 2. Required – In order to be a practical SecDesign Integrator the candidate must have experience implementing complex applications in an enterprise environment. 3. Required – working knowledge of programming and scripting languages: Java, JavaScript, C#, C/C++, Perl, Python, Ruby 4. Desired – In-depth knowledge of web technologies such as Web Browsers, Web Servers, Web ServicesOther Areas of Expertise 1. Frameworks, protocols, and subsystems: J2EE, .NET, Spring, RPC, SOAP, MQSeries, JMS, RMI, JMX, Hibernate. 2. Knowledge of JSP /Servlet/EJB or ASP.NET, HTTP/HTTPS, Cookies, AJAX, JavaScript, Flex / Silverlight. 3. Database design and programming experience 4. Experience of liaising with 3rd Party Entities (exchanges, suppliers, regulators) 5. Experience in conducting and / or reviewing penetration tests, dynamic vulnerability assessments and static vulnerability assessments. 6. Understanding of geographic regulations and their impact on Security assessments 7. Previous experience in Financial Services is preferred. 8. CISSP or other industry qualification 9. Desired – experience working with global organizations.Educational Requirements Bachelor’s Degree (or equivalent) with minimum 5 years relevant work experience in high-paced, enterprise environment Recruiting Notes Many application security candidates will have a lot of knowledge in using the testing tools identified in the job description. This is good but if their experience is solely in using the tools and not as a part of other responsibilities, then they may not be a fit for this position. If a resume / CV tends to focus heavily on risk assessments at a high level (i.e. conducted risk assessments with several users) but does not detail what was involved in those risk assessments, they may not be at a technical level required for this position. Communication skills are important for this role since they will be interacting with many groups on a global scale. Please screen for strong spoken and written communication
Create a job alert for this search

SecDesign Security Architect • Montreal, Canada

Similar jobs

Senior Security Architect - Remote, Equity, Impact

CliniaMontreal
Remote
Full-time

A digital health company is seeking a Senior Security Specialist in Montreal to lead security architecture and manage incidents across cloud environments.Responsibilities include developing securit... Show more

 • Promoted

Staff Security Engineer: Remote Lead & AppSec Architect

Super.comMontreal (administrative region), QC, CA
Remote
Full-time

A technology company in Canada is seeking a Staff Software Engineer specializing in Security to lead and mentor engineers within the Security & Privacy team.The successful candidate will drive appl... Show more

 • Promoted

Security Architect

AGFA HealthCareMontreal (administrative region), QC, CA
Full-time

We are hiring an experienced security Architect who is responsible for designing and implementing security within our architecture.This role involves working closely with cross-functional teams (en... Show more

 • Promoted

Senior Remote Mainframe Security Architect

Open Systems TechnologiesMontreal (administrative region), QC, CA
Remote
Full-time

A leading IT solutions provider is seeking an experienced Enterprise Z-Security Architect for a fully remote position.The role involves mainframe security operations, support, and on-call duties, r... Show more

 • Promoted

Architecte de sécurité

Caisse de dépôt et placement du Québecmontreal (administrative region), qc, Canada
Full-time

Au sein de l’équipe Architecture de sécurité, la personne titulaire du poste travaillera principalement sur la préparation, la rédaction et la production des livrables d’architecture de sécurité li... Show more

 • Promoted

OT Security Solutions Architect & Growth Engineer

Fortinet, Inc.Montreal (administrative region), QC, CA
Full-time

A cybersecurity company is seeking an OT Business Development Engineer in Montreal to lead technical engagements on OT security solutions.Candidates should have at least 5 years of experience in pr... Show more

 • Promoted

Cyber Security Architect

Intuitive.aiMontreal (administrative region), QC, CA
Full-time

Talent Acquisition Leader | Hiring Cloud Professionals Globally.Cloud is one of the fastest-growing (INC 5000, CRN) Cloud & SDx solution and services companies supporting enterprise customers on a ... Show more

 • Promoted

Senior Zero Trust Architect & Advisory Leader (Remote)

Palo Alto NetworksMontreal (administrative region), QC, CA
Remote
Full-time

A leading cybersecurity firm is seeking a Principal Consultant for their Zero Trust Advisory practice in Toronto.This role involves leading complex client engagements and transforming security arch... Show more

 • Promoted

Cyber Security Architect

Hamilton Barnes?Montréal, Montreal (administrative region), Canada
Full-time

Be among the first 25 applicants.Cyber Security Architect (Hybrid-Monteal).A multi-million $ CanadianEnvironmental Services company is seeking an experienced Cyber Security Architect!.Architect ent... Show more

 • Promoted

Lead Architect

ResonaiteMontreal (administrative region), QC, CA
Full-time

Our client in the Fintech space is seeking a Lead Architect to evolve its core technology architecture across cloud infrastructure, distributed systems, data platforms, and AI-enabled systems.Defin... Show more

 • Promoted

Cloud Security Architect & Security Solutions Architect - C$126,765 - C$149,135 A Year

A leading financial institutionLe Plateau, Canada
Full-time

Seeking a Cloud Security Architect to secure cloud environments and lead cloud security strategies for a financial institution in Ottawa, offering competitive salary and benefits. Show more

 • Promoted

Strategic Information Security Architect

ColliersMontreal (administrative region), QC, CA
Full-time

Transform global security architecture as a Strategic Information Security Architect.Spearhead cloud migration security strategies while ensuring systems are secure and compliant.This pivotal role ... Show more

 • Promoted

Principal Software Supply Chain Security Architect

GitLabMontreal (administrative region), QC, CA
Full-time

A leading software development firm is seeking a Principal Engineer for Software Supply Chain Security.In this role, you will lead the strategy for securing software delivery on the platform.Respon... Show more

 • Promoted

AI Architect Driving Compliance Solutions Across Multiple Jurisdictions

P2PMontreal (administrative region), QC, CA
Full-time

Lead the charge in designing AI-based compliance solutions as a skilled architect.Engage in full-stack development that automates compliance processes across various regions and products while ensu... Show more

 • Promoted

Bilingual Senior Security Architect - Compliance Team

Intello Technologies Inc.montreal (administrative region), qc, Canada
Full-time

Bilingual Senior Security Architect - Compliance Team.Location: Montréal, QC, CA, H3B 1S6 Vancouver, BC, CA Ottawa, ON, CA Toronto, ON, CA Calgary, AB, CA Edmonton, AB, CA.Jobs by Category: Securit... Show more

 • Promoted

Futures Risk Architect for Web3 DEX

AsterMontreal (administrative region), QC, CA
Full-time

A decentralized trading platform is seeking a Risk Control Specialist to optimize risk management for futures trading.This role involves identifying and mitigating risks associated with trading act... Show more

 • Promoted

SAP Security Architect

Addmore Groupmontreal (administrative region), qc, Canada
Full-time

Our client is hiring an SAP Security Architect.Location: Montreal or Greater Toronto Area.Workplace Type: Hybrid – Onsite 4 days/week mandatory.Salary: $117,560 to $154,300 (offers vary commensurat... Show more

 • Promoted

Security Architect - Mainframe

Tech Talent InternationalMontreal
Full-time

About the job Security Architect - Mainframe.Fortune 100/500/1000 companies to small and mid‑sized organizations in Canada/US.Senior Mainframe Security Architect (ACF2 and RACF).IT infrastructure c... Show more

 • Promoted

Senior Security Engineer at Confluence Montreal

Confluencemontreal (administrative region), qc, Canada
Full-time

Shape the future of security at Confluence in Montreal as a Senior Security Engineer.Focus on vulnerability remediation and improve security practices across IT infrastructure.In this pivotal role,... Show more

 • Promoted

Architecte Technologique - Architectures Cloud & Sécurité

TMCMontreal (administrative region), QC, CA
Full-time

Une entreprise en technologie recherche un architecte technologique à Montréal pour définir et maintenir des principes d’architecture, concevoir des systèmes robustes et évaluer les évolutions tech... Show more