Job Description: Solution Architect - (Security & API Infrastructure) Solution Architect with deep expertise in security, API management, and cloud infrastructure
Toronto, ON - Hybrid (4 Days WFO)
12 months
- Lead end-to-end solution design across security, API, and cloud domains — from requirements gathering and architecture definition through implementation and operational handover
- Define and enforce architecture patterns, standards, and reference architectures aligned with enterprise architecture best practices (TOGAF, Zachman, or equivalent frameworks)
- Produce high-quality solution design documents including HLDs, LLDs, data flow diagrams, sequence diagrams, and threat models
- Evaluate and recommend technology solutions, conducting proof-of-concept assessments and vendor evaluations
Security Architecture
- Design and implement enterprise security architectures encompassing encryption (at rest, in transit, and in use), key management, certificate lifecycle management, and PKI
- Architect fraud detection and identity verification solutions leveraging ThreatMetrix and similar platforms
- Define security policies for API gateways, WAFs, DDoS mitigation, and bot management
- Conduct security reviews, threat modelling, and risk assessments for new and existing solutions
- Ensure compliance with financial industry regulations (PCI-DSS, SOX, GDPR, Open Banking standards)
API & Edge Infrastructure
- Design and govern API strategies using Apigee (API proxy design, developer portals, rate limiting, OAuth/OIDC, API monetisation)
- Architect edge security and CDN solutions using Akamai and Cloudflare (WAF rules, bot management, DDoS protection, edge compute, DNS management)
- Design and manage DNS architecture including DNSSEC, traffic management, failover, and multi-CDN strategies
Cloud & Infrastructure
- Architect solutions on AWS (VPC, IAM, KMS, CloudFront, Route 53, GuardDuty, Security Hub, WAF, Shield, Lambda, ECS/EKS, API Gateway)
- Apply cloud-native security principles: zero-trust networking, least-privilege IAM, secrets management, and infrastructure-as-code security scanning
- Design hybrid and multi-cloud connectivity patterns where required
Governance & Leadership
- Contribute to and uphold architecture governance processes including architecture review boards (ARBs), design authority forums, and exception management
- Mentor and guide development teams on security best practices and architectural standards
- Collaborate with enterprise architects, engineering leads, product owners, and third-party vendors to align solutions with business strategy
- Maintain architecture decisions and contribute to the enterprise architecture repository
Required Experience & Qualifications
Core Technical Expertise
- 8+ years in solution/technical architecture roles, with at least 5 years focused on security architecture
- Proven hands-on experience with Apigee API management platform (proxy development, shared flows, target servers, analytics)
- Strong working knowledge of Akamai (Property Manager, WAF/KSD, Bot Manager, Edge DNS) and/or Cloudflare (WAF, Workers, DNS)
- Deep understanding of encryption standards and protocols (TLS 1.2/1.3, AES-256, RSA, elliptic curve, HSMs, tokenisation)
- Experience with DNS architecture at enterprise scale (DNSSEC, GSLB, authoritative vs recursive, TTL strategies)
- Practical experience with ThreatMetrix or equivalent digital identity/fraud prevention platforms
- Strong AWS architecture skills (AWS Solutions Architect Professional certification preferred)
Domain & Governance Experience
- Financial services industry experience is essential — banking, payments, insurance, or capital markets
- Demonstrated experience in enterprise architecture governance: defining standards, chairing or participating in ARBs, managing technical debt, and driving architectural compliance
- Familiarity with regulatory and compliance frameworks relevant to financial services (PCI-DSS, SOX, FCA, PSD2, Open Banking)
Architecture Practices
- Experience across the full solution lifecycle: discovery → design → build → test → deploy → operate
- Proficiency with architecture frameworks (TOGAF, C4 model, arc42) and modelling tools (e.g., , LucidChart, Draw.io,)
- Strong understanding of DevSecOps, CI/CD pipelines, and infrastructure-as-code (Terraform, CloudFormation)
- Experience with microservices, event-driven architecture, and integration patterns (REST, GraphQL, messaging/streaming)
Desirable Skills
- Additional cloud platform experience (Azure, GCP)
- Knowledge of identity platforms (Okta, Ping)
- Experience with SIEM/SOAR platforms (Splunk, Sentinel)
- Container security
Soft Skills
- Excellent stakeholder communication — ability to translate complex technical concepts for executive and non-technical audiences
- Strong analytical and problem-solving capabilities
- Comfortable operating in fast-paced, regulated environments with competing priorities
- Collaborative leadership style with experience influencing without direct authority
#J-18808-Ljbffr