Application Security Architect (Threat Modeling & Security Architecture)
The role focuses on driving enterprise threat modeling initiatives and defining security architecture patterns. It involves partnering with development teams to ensure secure design decisions and developing APIs to support security enablement.
- Hybrid
- Toronto, ON
- Posted Jul 29, 2026
- Apply by Aug 28, 2026
- 1 position
Job summary
We are seeking a highly skilled Application Security Architect to join our Application Security team. This role will be responsible for driving enterprise threat modeling initiatives, defining security architecture patterns, supporting development teams with secure design decisions, and contributing to security engineering efforts including API development and security enablement. The ideal candidate combines strong security architecture expertise with hands-on application security experience and the ability to influence engineering teams across the organization. Experience: 7+ Years Location: Hybrid / Remote Key Responsibilities Partner with application teams to conduct and complete threat models for new and existing applications. Lead threat modeling workshops and identify risks, attack vectors, and mitigation strategies. Develop and maintain reusable security architecture patterns and secure design standards. Provide on-demand security architecture support and guidance to development teams. Research, document, and maintain Architecture Decision Records (ADRs). Review application, API, and database designs from a security perspective. Design and develop APIs as needed to support security initiatives. Analyze vulnerabilities and provide risk-based remediation recommendations. Required Skills Application Security Threat Modeling (STRIDE, PASTA preferred) Security Architecture & Design Threat & Vulnerability Management REST APIs / Web Services API Security Database Architecture & Design PostgreSQL GitHub, GitLab, Bitbucket, or SVN JIRA Technical Documentation & ADRs AI / GenAI Security Awareness Preferred Skills OWASP Top 10 Secure SDLC (SSDLC) Cloud Security (Azure, AWS, GCP) DevSecOps Security Certifications (CISSP, CSSLP, CCSP, TOGAF)
What you’ll do
The role focuses on driving enterprise threat modeling initiatives and defining security architecture patterns. It involves partnering with development teams to ensure secure design decisions and developing APIs to support security enablement.
Requirements
Candidates need over 7 years of experience with expertise in threat modeling frameworks like STRIDE or PASTA and security architecture. Proficiency in API security, database design, and version control tools is required.
Listed skills
- PostgreSQLPreferred
Other relevant skills
Identified from the job description. Confirm important requirements above.
- Application Security
- Threat Modeling
- Security Architecture
- Threat & Vulnerability Management
- REST APIs
- API Security
- Database Architecture
- PostgreSQL
- GitHub
- GitLab
- Bitbucket
- SVN
- JIRA
- Technical Documentation
- ADRs
- AI / GenAI Security
Job areas
- Security & Safety
- Software
- Technology
- Engineering
- Consulting
Additional details
- Minimum experience
- 5+ years
- Apply by
- Aug 28, 2026
- Posting language
- English
- Working hours
- 40 hours per week
- Seniority
- Associate
- Application method
- Direct apply is available
