Opens an external site
- Employment type
- Full-time
- Experience level
- Lead · 10+ years
- Minimum education
- Professional degree
- Apply by
- Sep 17, 2026
- Posting language
- English
- Working hours
- 40 hours per week
Job summary
The role involves defining and implementing enterprise security architecture standards across cloud, on-premises, and AI environments. It also requires driving secure-by-design principles and providing authoritative security guidance to senior stakeholders and engineering teams.
Job details
Expert Security Architecture At CN, everyday brings new and exciting challenges. You can expect an interesting environment where you’re part of making sure our business is running optimally and safely―helping keep the economy on track. We provide the kind of paid training and opportunities that long-term careers are built on and we recognize hard workers who strive to make a difference. You will be able to thrive in our close-knit, safety-focused culture working together as ONE TEAM. The careers we offer are meaningful because the work we do matters. Join us! Job Summary The purpose of this role is to evaluate technology solutions, configurations, and designs against security requirements, and define cybersecurity reference architectures and standards across enterprise environments at CN (including cloud, on-premises, data, and emerging technologies such as AI). This role drives secure-by-design principles across engineering and operational teams by integrating security into architecture practices, development workflows, and enterprise technology decisions. Main Responsibilities Security Architecture Practice Define and implement enterprise security architecture controls to manage risk while enabling business capabilities across domains such as cloud platforms, enterprise applications, data, AI/ML, industrial systems, networking, and end-user technologies. Ensure security architecture across enterprise environments is maintainable, sustainable, and properly documented. Define and enforce security design patterns and controls for Artificial Intelligence (AI) and Generative AI workloads, including model lifecycle security, data protection, and responsible use. Assess AI-enabled solutions for emerging risks such as prompt injection, model manipulation, data leakage, and unauthorized use of enterprise data. Partner with Responsible AI, Data, and Architecture teams to integrate security controls into AI and machine learning solutions. Define security standards and guardrails for AI technologies aligned with enterprise policies, regulatory expectations, and risk tolerance. Contribute to the development of secure AI usage guidelines and governance frameworks. Maintain and build relevant, current, valid, and reliable team knowledge related to security architecture to leverage existing cybersecurity infrastructure and process, where appropriate, and drive configuration standards while supporting digital transformation in the I&T environment Facilitate key decisions involving architecture and technologies. Influence enterprise architecture decisions by providing authoritative security guidance across programs and portfolios. Act as a trusted advisor to senior stakeholders on security architecture trade-offs and risk decisions. Advance security team accomplishments and competence by planning delivery of solutions; answering technical and procedural questions for less experienced team members; teaching improved processes; mentoring team members Produce architecture artifacts that are audit-ready and aligned with enterprise governance and compliance requirements. Security Roadmap and Strategy Report to the Senior Manager, Security Architecture and support the execution of the enterprise security architecture strategy defined by the CISO organization. Operate as a senior individual contributor within the Security Architecture team, providing technical leadership and influencing cross-functional delivery teams. Define the proper course of action and investment strategy by building business cases and security roadmaps Engage technology and cybersecurity vendor ecosystems to understand capabilities and drive improvements in the overall security posture. Engage the cybersecurity vendor ecosystem to understand capabilities, options for compensating controls and risk mitigations to facilitate the selection of partners that integrate with the overall architecture Continuously monitor and evaluate the environment through self-assessments and independent security reviews. Enable management to identify deficiencies and inefficiencies and to initiate improvement actions though security roadmap and strategies Working Conditions Occasional business travel (Canada and US) in accordance with CN policy Requirements Experience Minimum 12 years overall work experience Minimum 8 years I&T experience Minimum 5 years experience in security architecture across enterprise environments (including cloud, applications, data, or infrastructure). Proven experience in applying a structured approach to problem resolution in large, geographically dispersed organizations with 24/7 operations Multi-cloud experience including AWS, Azure, and Google Cloud Platform, an asset Experience with Agile and DevOps methodologies, an asset Railroad, transportation, or Global industrial experience is a significant asset Education/Certification/Designation Bachelor’s degree in Computer Science, Computer Engineering, Electrical Engineering, System Analysis, or another relevant field At least one recognized security certification (e.g., CISSP, CISM, CISA, CCSP, CCSK, GIAC or equivalent), demonstrating a strong foundation in information security principles across enterprise environments. Architecture related certifications (TOGAF, Zachman, CISSP-ISSAP, etc.) asset Competencies Ability to define and organize an architecture security apparatus in reusable building blocks: patterns, services, components, capability models, etc. Demonstrated capability to understand the security implications of complex business operations and how they are linked to technological solutions that provide practical risk mitigation and business enablement Ability to derive security requirements from vaguely formulated business needs Ability to interact with a broad cross-section of personnel to explain and enforce security measures Excellent written and verbal communication skills Detail-oriented self-starter with a high level of commitment and personal motivation Knack for prioritizing tasks and working in a fast-paced environment Technical Skills/Knowledge Strong knowledge of the processes, methodologies, tools, and techniques, used for building large information technology systems Knowledge of standards, regulations and legislation governing Information Security, e.g. NIST, ISO 27001, OWASP Knowledge of general IT security architecture and technologies including: service-oriented-architectures, mobile technologies including Mobile Device Management (MDM), data-centric design, advanced analytics, AI, Identity and Access Management (IAM) lifecycles, Digital Forensics, End Point Protection, Encryption, Encryption Key Management, Database Security, Enterprise Directory Services, IDS, IPS, Next Generation Firewalls, Application Firewalls, Enterprise Password Vaults, Cloud SaaS /PaaS/IaaS Security, SIEM, etc., an asset. Knowledge of enterprise security architecture domains including application security, data security, identity and access management, network security, and operational technology (OT) security. Understanding of securing APIs, OpenID Connect, OAuth an asset Understanding networking including SD-networks and service meshes, an asset Knowledge of container security concerns, especially with Kubernetes, an asset For internal candidates, note that the grade level of the position will depend on the employee's experience. About CN CN is a world-class transportation leader and trade-enabler. Essential to the economy, to the customers, and to the communities it serves, CN safely transports more than 300 million tons of natural resources, manufactured products, and finished goods throughout North America every year. As the only railroad connecting Canada’s Eastern and Western coasts with the Southern tip of the U.S. through a 19,500 mile rail network, CN and its affiliates have been contributing to community prosperity and sustainable trade since 1919. CN is committed to programs supporting social responsibility and environmental stewardship. At CN, we work as ONE TEAM, focused on safety, sustainability and our customers, providing operational and supply chain excellence to deliver results. About CN CN is a premium railroad that sustainably generates value for our customers, shareholders, employees, and stakeholders with an unwavering commitment to safety and service. Essential to the economy, to the customers, and to the communities it serves, CN safely transports more than 300 million tons of natural resources, manufactured products, and finished goods throughout North America every year. CN's network connects Canada's Eastern and Western coasts with the U.S. South through a 20,000-mile rail network. CN and its affiliates have been contributing to community prosperity and sustainable trade since 1919. CN powers the North American economy and is committed to programs supporting social responsibility and environmental stewardship. At CN, we are dedicated to building North America's safest, most inclusive and sustainable railroad, which includes reflecting the communities in which we operate. Research shows that candidates often don't apply unless they feel they fit the job posting at 100%. To all potential applicants, even if you don't meet every job requirement listed in a posting, we still encourage you to apply. If you require an accommodation for the recruitment process (including alternate formats of materials, accessible meeting rooms or other accommodations), please get in touch with our team at [email protected]. As an equal opportunity employer, qualified candidates will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, protected veteran status, and other protected status as required by applicable law. Please monitor your email on a regular basis as communication to applicants is done via email.
What you’ll do
The role involves defining and implementing enterprise security architecture standards across cloud, on-premises, and AI environments. It also requires driving secure-by-design principles and providing authoritative security guidance to senior stakeholders and engineering teams.
Requirements
Candidates must have at least 12 years of work experience, including 5 years specifically in security architecture within enterprise environments. A bachelor's degree in a relevant field and at least one recognized security certification such as CISSP or CISM are required.
Benefits
• Paid training • Career development opportunities
Listed skills
- Compliance · Preferred
- Risk Management · Preferred
- Agile · Preferred
- Stakeholder Management · Preferred
Other relevant skills
Identified from the job description. Confirm important requirements above.
- Security architecture
- Cybersecurity
- Cloud security
- AI security
- Risk management
- Enterprise architecture
- Data protection
- Identity and access management
- Network security
- Security governance
- Compliance
- Mentoring
- Stakeholder management
- Agile
- DevOps
- Security design patterns
- Certified Information System Auditor (CISA)
- Influencing Skills
- Emerging Risk
- Self-Starter
- Responsible AI
- Container Security
- Generative Artificial Intelligence
- Certified Cloud Security Professional (CCSP)
- Influencing Without Authority
- Multi-Cloud
- Supply Chain
- Master Data Management
- IT Security
- Business Operations
- Workflow Management
- Endpoint Security
- Advanced Analytics
- Technology Solutions
- Emerging Technologies
- Google Cloud Platform (GCP)
- Digital Transformation
- Technical Leadership
- Technology Ecosystems
- Risk Mitigation
- Planning
- IT Security Architecture
- Architecture Strategy
- Research
- Application Programming Interface (API)
- Agile Methodology
- Artificial Intelligence
- Amazon Web Services
- Application Security
- Electrical Engineering
Job areas
- Security & Safety
- Technology
- Software
- Data & Analytics
- Transportation
- IT Security Architect
- Enterprise Architect
- Systems Analysts
- Business Intelligence Analysts
- Data Scientists
More jobs you can apply to directly
Similar opportunities posted by employers hiring on Jobs.ca, with no external application form.
Bédard Ressources Humaines
ITAD Services Representative #1265
SponsoredDirect employerEasy Apply- On-site
- Mississauga, ON
- Posted Sep 16, 2026
Bédard Ressources Humaines
Responsable d’expédition
SponsoredDirect employerEasy Apply- On-site
- Mascouche, QC
- Posted Sep 16, 2026
Dalfen Ltée
Building Superintendent
SponsoredDirect employerEasy Apply- On-site
- Sainte-Agathe-Des-Monts, QC
- Posted Sep 15, 2026
