Security Architect and Analyst
Duration – 12 Months
Location – Hybrid/ Mississauga, ON Canada
Start Date - October 2026
The Opportunity
The Security Architect will be responsible for defining, governing, and evolving Purolator's enterprise security architecture across cloud, on-premises, hybrid, and emerging technology environments. This is a senior advisory and governance role — not a hands-on operations role.
The contractor will serve as a strategic advisor to technology and business leaders, ensuring that security capabilities, architecture decisions, and technology investments align with Purolator's business strategy, regulatory obligations, and risk appetite. A key focus is embedding security-by-design principles into project delivery from the requirements phase onward.
Key Responsibilities
Enterprise Security Architecture
Develop, maintain, and govern enterprise security architecture strategy, standards, principles, patterns, and reference architectures.
Define target-state security architectures across cloud, on-premises, SaaS, and hybrid technology environments.
Provide architecture leadership for strategic technology investments, modernization initiatives, and digital transformation programs.
Ensure alignment between cybersecurity initiatives, enterprise architecture roadmaps, and business priorities.
Project Security Engagement
Lead security architecture reviews for net new IT projects, engaging directly with IT leaders and project architects from initiation.
Conduct security risk classification at project kick-off and define appropriate security controls based on data sensitivity, asset criticality, exposure, and regulatory scope.
Review functional and non-functional requirements for security adequacy; provide formal written sign-off before architectural design work begins.
Conduct architectural design reviews and document findings; govern risk exceptions through a formal Risk Acceptance Memo (RAM) process.
Hand off approved security documentation and open risk items to the Information Security team for ongoing tracking.
Security Design & Risk Management
Lead threat modelling, security risk assessments, and architecture reviews for enterprise initiatives and critical projects.
Define security control frameworks covering identity and access management, data protection, application security, network security, cloud security, and integration security.
Security Architect — Contract Engagement | Purolator Inc. | Confidential 3
Translate business objectives, regulatory requirements, and risk tolerance into measurable security capabilities and architecture standards.
Evaluate emerging technologies and recommend secure adoption approaches.
Cloud, Data & Platform Security
Provide architecture leadership for cloud security, including governance, identity, data protection, workload security, and platform controls.
Define and govern security requirements for APIs, integrations, data platforms, AI solutions, and digital products.
Partner with cloud governance and technology teams to establish secure cloud adoption practices.
AI Security Governance
Lead security architecture aspects of AI-enabled solutions, automation platforms, and intelligent agents.
Establish governance practices for AI-related security risks, oversight mechanisms, and accountability frameworks.
Define security requirements for AI systems, including data protection, model governance, access controls, and responsible use.
Stakeholder Engagement & Advisory
Act as a trusted advisor to senior technology and business leaders on cybersecurity risks, architecture decisions, and technology trade-offs.
Present security architecture recommendations, risks, and investment considerations to leadership audiences.
Communicate complex security concepts in business-relevant terms, enabling informed decision-making at all levels.
Collaborate across Enterprise Architecture, Solution Architecture, Product Teams, Security Operations, and Infrastructure Services.
Vendor & Third-Party Security
Provide security architecture guidance for vendor evaluations, procurement activities, and technology partnerships.
Participate in third-party security assessments and define minimum security standards for vendor and partner engagements.
Security Architect — Contract Engagement | Purolator Inc. | Confidential 4
Assess data residency, privacy, and regulatory implications associated with technology solutions and vendor services.
Qualifications
Education
University degree in Computer Science, Information Technology, Cybersecurity, Engineering, or a related discipline.
Equivalent combination of education and demonstrated experience will be considered.
Experience
8+ years of progressive experience in cybersecurity, information security, enterprise architecture, solution architecture, or related technology leadership roles.
Demonstrated experience designing and governing security architectures in complex enterprise environments.
Experience supporting cloud transformation initiatives and hybrid technology ecosystems.
Experience conducting security risk assessments, architecture reviews, and threat modelling.
Experience reviewing functional and non-functional requirements for security adequacy and providing formal sign-off in a project governance context.
Experience advising senior leadership and cross-functional stakeholders on technology risk and architecture decisions.
Preferred Certifications
CISSP — Certified Information Systems Security Professional
SABSA, TOGAF, or equivalent enterprise architecture certification
CCSP — Certified Cloud Security Professional
CISM — Certified Information Security Manager
Azure, AWS, or Google Cloud security architect certifications
Security Architect — Contract Engagement | Purolator Inc. | Confidential 5
Technical Skills
|
Candidates should demonstrate depth across the following areas:Enterprise Security Architecture
|
Cloud Security Architecture
|
Identity & Access Management
|
|
Data Protection & Privacy Controls
|
Application & API Security
|
Network & Infrastructure Security
|
|
Threat Modelling & Risk Assessment
|
Security Control Frameworks & Standards
|
Security Governance & Compliance
|
|
Functional & Non-Functional Security Requirements
|
Risk Acceptance & Residual Risk Management
|
Shift-Left & Secure-by-Design Practices
|
|
AI Governance & Emerging Technology Security
|
Vendor & Third-Party Risk Management
|
Executive Communication & Stakeholder Advisory
|