Senior Cybersecurity Test Architect (35651)
Design and lead the enterprise security testing strategy across applications, infrastructure, and cloud environments. Establish security testing standards and develop threat-based scenarios to validate security requirements.
- On-site
- Ottawa, ON
- Posted Aug 26, 2026
- Apply by Sep 25, 2026
- 1 position
More jobs you can apply to directly
Similar opportunities posted by employers hiring on Jobs.ca, with no external application form.
Job summary
Senior Cybersecurity Test Architect Role Overview We are seeking a Senior Cybersecurity Test Architect to design and lead the enterprise security testing strategy across applications, infrastructure, cloud environments, and system integrations. This role will establish security testing standards, develop threat-based test approaches, and ensure security requirements are effectively validated through repeatable and measurable testing. Key Responsibilities Define the enterprise security testing strategy, architecture, and coverage model across applications, infrastructure, cloud, and integrations. Develop threat models and security test scenarios using industry-standard methodologies such as STRIDE and MITRE ATT&CK. Design repeatable and scalable security testing approaches for: Identity and Access Management (IAM) APIs and microservices Data flows and system integrations Cloud environments Application and infrastructure security Define the security testing tooling strategy, including both manual and automated testing capabilities. Establish security testing standards, processes, and best practices across development and infrastructure teams. Ensure security testing is traceable to security requirements, policies, controls, and risk objectives. Identify security gaps and vulnerabilities and provide recommendations for remediation. Support complex security risk assessments, investigations, and escalations. Collaborate with cybersecurity, architecture, development, cloud, infrastructure, and engineering teams to integrate security testing throughout the SDLC. Provide technical leadership and guidance on security testing methodologies, automation, and continuous security validation. Produce clear technical documentation, test strategies, architecture diagrams, and security assessment reports. Required Skills & Experience 8+ years of experience in cybersecurity architecture, security engineering, security testing, or a related discipline. Strong experience developing enterprise security test strategies and architectures. Hands-on experience with threat modeling methodologies, including STRIDE, MITRE ATT&CK, or equivalent frameworks. Strong knowledge of cloud security architecture across AWS, Azure, and/or GCP. Experience with API security, identity architecture, IAM, authentication, and authorization. Strong understanding of application, infrastructure, network, and integration security. Experience defining and implementing manual and automated security testing approaches. Strong understanding of security controls, requirements, risk management, and compliance frameworks. Excellent technical documentation, architecture, and communication skills. Ability to work effectively with technical teams, architects, developers, and security stakeholders. Preferred Qualifications Experience integrating security testing into CI/CD and DevSecOps environments. Knowledge of security testing tools and automation frameworks. Experience with container, Kubernetes, and cloud-native security. Familiarity with security frameworks such as NIST, ISO 27001, CIS, OWASP, or similar. Relevant cybersecurity certifications such as CISSP, SABSA, GIAC, or cloud security certifications would be an asset. ,
What you’ll do
Design and lead the enterprise security testing strategy across applications, infrastructure, and cloud environments. Establish security testing standards and develop threat-based scenarios to validate security requirements.
Requirements
Requires over 8 years of experience in cybersecurity architecture or engineering with expertise in threat modeling and cloud security. Proficiency in IAM, API security, and the ability to integrate security testing into the SDLC is essential.
Listed skills
- Microsoft AzurePreferred
- CI/CDPreferred
- Amazon Web ServicesPreferred
- Google CloudPreferred
Other relevant skills
Identified from the job description. Confirm important requirements above.
- Cybersecurity Architecture
- Security Testing
- Threat Modeling
- STRIDE
- MITRE ATT&CK
- Cloud Security
- AWS
- Azure
- GCP
- API Security
- IAM
- DevSecOps
- CI/CD
- Network Security
- Risk Management
- Technical Documentation
Job areas
- Security & Safety
- Technology
- Software
- Engineering
- Consulting
Additional details
- Minimum education
- Professional degree
- Minimum experience
- 10+ years
- Apply by
- Sep 25, 2026
- Posting language
- English
- Working hours
- 40 hours per week
- Seniority
- Mid-Senior level
