About the company
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Director, Product Security Architect based in Canada.
This is a highly technical leadership role focused on embedding security into products from the earliest stages of design and development. You will shape secure-by-design practices across SaaS products, cloud platforms, and AI-enabled solutions. The role partners closely with Product, Engineering, Architecture, Cloud Operations, AI, Legal, and Security teams.
Responsibilities
- Define and execute the Product Security Architecture and Secure-by-Design strategy, roadmap, standards, and reference architectures for cloud-native and AI-enabled products.
- Partner with Product and Engineering teams to integrate security requirements into development workflows, epics, user stories, and AI software development lifecycle processes.
- Lead threat modeling and security architecture reviews, producing data flow diagrams, trust boundary analysis, abuse cases, attack paths, security requirements, remediation plans, and residual risk documentation.
- Assess recurring vulnerabilities, penetration testing results, security incidents, and assessment findings to identify systemic architectural weaknesses and improve security standards.
- Review distributed systems, microservices, APIs, mobile applications, identity solutions, cloud-native platforms, containers, Kubernetes, serverless environments, and AI-enabled architectures.
- Translate security risks into practical architectural recommendations and work directly with engineering teams to implement and validate remediation.
- Establish reusable threat models, secure design patterns, security requirements, and architecture libraries that can be adopted across engineering teams.
- Conduct security architecture reviews across AWS, Azure, and IBM Cloud environments and define appropriate cloud security guardrails and secure deployment patterns.
- Partner with AI teams to assess security risks associated with LLM-enabled products, AI development environments, and agentic workflows.
- Develop security standards, training materials, architecture guidance, and governance practices while communicating risks and recommendations effectively to both technical and executive audiences.
- Identify opportunities to automate security architecture and design validation and continuously improve secure development processes.
- Build strong relationships across Product, Engineering, Architecture, Cloud, Security, and Legal teams while influencing risk-based decision-making and security trade-offs.
Requirements
- 10+ years of information security experience, including substantial hands-on experience in Product Security, Application Security, Security Architecture, or Software Security Engineering.
- 3+ years of hands-on experience in Application Security Architecture and Threat Modeling.
- 3–5 years of software development or software engineering experience.
- Strong knowledge of secure application design, cloud security, modern software architectures, DevSecOps, and secure SDLC practices.
- Demonstrated experience securing web, API, mobile, cloud-native, and AI-enabled applications.
- Expertise with threat modeling methodologies such as STRIDE, CAPEC, and MITRE ATT&CK.
- Practical knowledge of AWS, Azure, or IBM Cloud security architectures.
- Experience with AI-enabled development environments, LLM security, or agentic architectures is highly relevant.
- Strong analytical and problem-solving abilities, with the capacity to identify architectural risks and translate them into actionable engineering solutions.
- Excellent communication and stakeholder management skills, with the ability to influence senior technical and business leaders.
- Ability to operate effectively in a highly collaborative, cross-functional environment and balance technical depth with pragmatic risk management.
- Relevant certifications such as ISC2 ISSAP, CISSP, CSSLP, OSCP, or cloud security certifications are considered an asset.
Conditions
- Estimated annual base salary of $138,200–$181,400 CAD, with actual compensation determined by qualifications, experience, market data, and other job-related factors.
- Potential additional compensation through bonuses and other applicable incentive programs.
- Comprehensive medical, dental, and vision coverage tailored to local needs.
- Paid time off and public holidays.
- Dedicated volunteer days to support causes and communities that matter to you.
- Ignite Days dedicated to learning, professional development, and continuous skill growth.
- Retirement plans designed to support long-term financial security.
- Tuition assistance for continuing education and professional development.
- Remote and hybrid work options available across most regions, providing flexibility to work where you thrive.
- A collaborative and inclusive environment focused on innovation, learning, and meaningful professional growth.
- Opportunities to influence security strategy across SaaS, cloud, and emerging AI technologies.