Enterprise Security Architect / Senior Security Consultant
- Location: Anywhere in Canada, but GTA is preferred as there might be occasional client meetings
- Pay Rate: $110/hr – $120/hr
- Contract Length: 3 months.
We at Raise are hiring an Enterprise Security Architect / Senior Security Consultant for one of our top clients. After establishing themselves as an industry leader, they’re now expanding their team to meet rising demand. We’re hiring right now; if you’re interested, apply below for your chance to join a great place to work.
Responsibilities:
Security Architecture & Strategy
- Lead the development of **enterprise security architecture** across domains including identity, network, endpoint, cloud, application, data, and security operations.
- Define and operationalize **Zero Trust architecture** (identity-centric controls, continuous verification, least privilege, segmentation, strong telemetry).
- Create and maintain security architecture artifacts: reference architectures, target state, roadmaps, control mappings, and exception processes.
- Translate business and regulatory needs into security requirements, patterns, and standards.
Client Consulting & Stakeholder Management
- Serve as a trusted advisor to client leadership (CISO org, technology leaders, risk/compliance, architecture boards).
- Facilitate architecture workshops, threat modeling sessions, and design reviews; document decisions and executive-ready recommendations.
- Deliver clear, pragmatic guidance that balances **risk reduction, cost, and operational feasibility**.
- Align architecture proposals with enterprise constraints: legacy platforms, vendor ecosystems, and change management realities.
Security Engineering Guidance (Design-Level)
Provide architectural direction for:
- **Identity & Access Management (IAM):** authentication, authorization, privileged access, conditional access, MFA, identity governance.
- **Cloud & Hybrid Security:** landing zone security, shared responsibility, cloud controls, posture management.
- **Network Security:** segmentation/micro-segmentation, secure remote access, egress controls, NDR strategy.
- **Endpoint & Workload Security:** EDR/XDR strategy, hardening baselines, secure configuration.
- **Data Security:** classification, DLP, encryption, key management, data access controls.
- **AppSec:** secure SDLC, DevSecOps guardrails, API security, SAST/DAST, dependency risk.
- **Security Operations:** SIEM/SOAR strategy, detection engineering approach, incident response integration, use-case roadmaps.
Financial Services / Banking Context
- Support architecture decisions with an understanding of financial services risk posture, third-party risk, audit readiness, and strong governance expectations.
- Help teams prepare materials for security governance boards, risk committees, and audit/regulatory conversations (as applicable).
Microsoft Security Focus (Preferred)
- Architect or advise on Microsoft security capabilities, such as:
- **Microsoft Entra** (ID, Conditional Access, Identity Governance, PIM/PAM integrations)
- **Microsoft Defender** suite (Endpoint, Identity, Cloud Apps, Office 365, Cloud/Workload as applicable)
- **Microsoft Sentinel** (SIEM/SOAR, analytics rules strategy, log onboarding, use-case prioritization)
- **Microsoft Purview** (Information Protection, DLP, compliance/data governance where relevant)
- Recommend integrations and operating models that align Microsoft tooling to Zero Trust outcomes.
Required Qualifications
- **8–12+ years** in cybersecurity, including significant experience in **security architecture** and **client-facing consulting**.
- Demonstrated expertise across multiple security domains (IAM, network, endpoint, cloud, app, data, and SecOps).
- Strong familiarity with **Zero Trust** as a framework and practical implementation patterns in enterprise environments.
- Experience advising complex organizations on **security architecture** and transformation roadmaps.
- Ability to produce high-quality deliverables: architecture decks, roadmaps, executive summaries, control mappings, and design documents.
- Excellent communication skills—able to translate technical concepts for executive and non-technical audiences.
Preferred / Nice-to-Have Qualifications
- Experience working with **financial services / banking** clients (or similarly regulated industries).
- Microsoft security implementation or advisory experience (Entra, Defender, Sentinel, Purview).
- Familiarity with common security frameworks and standards (e.g., NIST, ISO 27001, CIS Controls, etc.).
- Experience with threat modeling, secure architecture reviews, and security governance processes.
- Cloud security depth in Azure (preferred), plus AWS/GCP exposure is beneficial.
Certifications (Preferred)
- CISSP, CISM, CCSP
- SABSA / TOGAF (architecture-oriented)
- Microsoft Security certifications (e.g., SC-100, SC-200, SC-300, AZ-500)
- Cloud certifications (Azure/AWS/GCP security)
Core Skills & Competencies
- **Executive presence** and strong consulting toolkit (workshops, discovery, influencing, storytelling)
- Architecture rigor: principles, patterns, trade-off analysis, and governance alignment
- Strong understanding of **identity-first security** and enterprise operating models
- Ability to create actionable, phased roadmaps (quick wins + strategic target state)
- Practical risk-based decision making (not “perfect security” at the expense of delivery)
Looking for meaningful work? We can help!
Raise is an established hiring firm with over 65 years of experience. We believe strongly in making the world a better place through work, which is why we’re a certified B Corporation and donate 10% of our profits to charity.
We strive to build teams that reflect the diversity of the communities we work in. We encourage all qualified applicants to apply, including people from traditionally underrepresented groups such as women, visible minorities, Indigenous peoples, people identifying as LGBTQ2SI, veterans, and people with visible/nonvisible disabilities.
We have a dedicated webpage for accommodations where you can learn more about what we offer and request accommodations: https://raise.jobs/accommodations/
In order to submit candidates for roles, our clients will sometimes require personal information to confirm the identity of applicants and their legal status to work. Raise will never ask you for personal or banking information unless you have been selected for a job. If you are ever unsure about the legitimacy of this or another job posting by Raise (or have any other questions), please contact us at +1 800-567-9675 or hello@raiserecruiting.com