Back


Job Detail

Senior Security Architect

Medavie

Newfoundland and Labrador, Newfoundland and Labrador

Senior Security Architect

Medavie

Newfoundland and Labrador, Newfoundland and Labrador
 
Salary: Information not available
 
Remote
New Brunswick
Nova Scotia
Newfoundland and Labrador
Manitoba
Alberta
Montreal, Québec
Prince Edward Island
Ontario, Canada
Full time
Posted 12 Days Ago
R-268494

Position Type:

Permanent

If you’re looking for a fulfilling career that can make a real difference in your life, and the lives of others, you’ve come to the right place.

As a national health solutions partner, we put people first in everything we do — and that begins with our team of 8,000+ professionals who bring a cross-section of diverse life experiences and career expertise to Medavie. By collaborating and innovating together, our employees are creating industry-leading solutions in insurance, primary care and emergency medical services that impact millions of lives in Canada each year.

Our mission is to improve the wellbeing of Canadians so that every life can be lived to the fullest — and it’s reflected in our award-winning culture. We celebrate individuality and value the diverse perspectives and skills our employees contribute. We go beyond providing competitive pay and comprehensive benefits to offer opportunities for personal and professional growth, flexible work options, meaningful experiences, and supportive leadership. Medavie is where employees can be their best selves, feel they belong, and achieve their full potential. Be part of it by applying for a position with us today.

The Opportunity:

The Senior Security Architect is a strategic technical leader responsible for designing, implementing, and governing enterprise-wide security architectures that protect the organization’s information assets, infrastructure, and applications.

This role partners closely with business leaders, technology teams, and risk management functions to ensure security capabilities are aligned with business objectives, regulatory requirements, and modern threat landscapes.

The Senior Security Architect provides deep expertise across security domains—including cloud, identity, network, data protection, application security, and zero trust—and drives the adoption of secure design principles across the enterprise

technology ecosystem.

Key Responsibilities:

Strategic Security Architecture:

  • Develop and maintain the enterprise security architecture roadmap aligned with corporate security strategy and business goals.

  • Establish security reference architectures, patterns, and standards covering on- premises, cloud, and hybrid environments.

  • Lead architectural assessments for new technologies, platforms, and major initiatives.

Design, Engineering & Implementation:

  • Architect secure solutions across cloud (Azure/AWS), applications, data, and networks.

  • Define security controls and requirements for system designs, integrations, and third-party technologies.

  • Review technical designs and solution architectures to ensure adherence to security best practices and compliance requirements.

Security Governance, Risk & Compliance:

  • Ensure alignment with regulatory, privacy, and internal policy requirements (e.g., ISO 27001, NIST CSF, SOC 2, PCI-DSS, Personal Health Information Acts).

  • Partner with risk, compliance, and audit functions to assess security posture and identify architectural gaps.

  • Create and maintain security documentation, architectural diagrams, and standards.

Collaboration & Leadership:

  • Serve as a senior advisor to IT, engineering, and business leaders on secure architecture and emerging threats.

  • Lead cross-functional architecture reviews and security design workshops.

  • Mentor engineering and security staff, promoting security-by-design across the organization.

Threat Modeling & Emerging Technologies:

  • Lead threat modeling and architectural risk assessments for critical systems and new initiatives.

  • Monitor industry trends, threat intelligence, and technology advancements to evolve security architecture.

  • Evaluate and recommend new security technologies and capabilities.

Required Qualifications:

Education: Bachelor’s degree in Computer Science, Cybersecurity, Engineering, or related field. Masters preferred.

Experience:

  • 8–12+ years of experience in cybersecurity with at least 5 years in architecture-level roles.

  • Proven experience designing and securing cloud, hybrid, and enterprise-class environments.

Certifications:

  • CISSP (Certified Information Systems Security Professional)

  • TOGAF (or equivalent enterprise architecture certification)

Other Qualifications:

  • Ability to design end-to-end security architectures (application, infrastructure, identity, data, network) from requirements through implementation.

  • Strong command of security principles: least privilege, defense-in-depth, secure-by-design/default, separation of duties, trust boundaries, threat modeling concepts.

  • Able to produce architecture artifacts: reference architecture, solution designs, security patterns, exception/risk acceptances, and architecture decision records (ADRs).

  • Deep understanding of authentication and authorization models (SSO, federation, OAuth2/OIDC, SAML, Kerberos where relevant).

  • Privileged access concepts (PAM), role/attribute-based access (RBAC/ABAC), conditional access, identity lifecycle and governance basics.

  • Familiarity with MFA patterns, device posture, session controls, and identity as the primary control plane. · Proven experience securing workloads in Azure / AWS / GCP (pick one as minimum; multi-cloud as preferred).

  • Core cloud security concepts: shared responsibility model, segmentation, security groups/NSGs, KMS/key management, secrets management, logging/monitoring, cloud-native IAM.

  • Understanding of hybrid connectivity patterns and security (VPN/ExpressRoute/DirectConnect equivalents, routing, DNS).

  • Solid grounding in network security architecture: segmentation, firewalls, WAF, DDoS protections, proxies, secure remote access, DNS security.

  • Understanding of TLS/PKI basics, certificate lifecycle, and secure connectivity patterns.

  • Ability to advise and design for secure SDLC: security requirements, design reviews, CI/CD security controls, dependency management, code scanning concepts.

Preferred/Assets:

  • Strong security architecture across two or more cloud providers. · Deep understanding of cloud landing zones, guardrails, policy-as-code, and centralized identity patterns.

  • Practical experience implementing Zero Trust concepts: identity-centric access, continuous verification, device trust, micro-segmentation, adaptive access.

  • Experience with SSE/SASE models (secure web gateway, CASB, ZTNA) and enterprise proxy strategy.

  • Familiarity with workload identity and supply chain security for containers.

  • Strong CI/CD security patterns: SAST/DAST/IAST, SBOM, dependency governance, artifact signing, policy gates.

  • Familiarity with supply chain frameworks (e.g., SLSA concepts) and secure build pipelines.

  • Ability to drive automation: policy-as-code, infrastructure-as-code guardrails (Terraform/ARM/Bicep concepts), automated compliance evidence.

  • Scripting familiarity (PowerShell/Python) for security enablement and control validation.

  • Deeper crypto knowledge: HSM design, envelope encryption patterns, rotation strategies, mTLS at scale, certificate automation.

  • Experience designing enterprise key management strategy (centralized vs distributed, BYOK/HYOK patterns where relevant).

  • Experience mapping security architecture to regulated requirements (e.g., healthcare, financial services, government contracting).

  • Evidence-based control design supporting audits and third-party assurance (SOC 2, ISO, etc.).

  • Strong alignment with enterprise architecture practices: capability mapping, target state roadmaps, reference architectures, technology standards.

  • Proven ability to reduce complexity and technical debt via platform patterns.

  • Strong knowledge of adversary tradecraft and mitigations (MITRE ATT&CK mapping, detection-informed architecture).

  • Experience designing for resilience against ransomware, credential theft, lateral movement, and abuse of cloud control planes.

  • Mentors other architects and engineers; establishes reusable patterns and guardrails.

  • Leads cross-domain programs (IAM modernization, secure cloud adoption, data security program, etc.).

Language Skills: English (Spoken and Written) required. French (Spoken and Written) considered an asset  

Security Clearance Requirement: In conjunction with our contract with the Federal Government, you will be required to have Reliability Status Clearance (Enhanced Level B). This includes Fingerprinting, Criminal Record Check, Credit Check and you must have resided in Canada for at least 5 years and hold Permanent Resident or Citizenship Status. 

What’s in it for you? 

What makes us a different kind of employer? Our award-winning culture, a team who really cares, unmatched training and support are all dedicated to ensuring you are set up for success. 

What we offer: 

  • Permanent full-time position with strong career growth opportunities. 

  • Hybrid or remote work arrangements. 

  • Flexible work environment and work-life balance. 

  • 100% employer-paid health, dental, and vision benefits (effective Day 1). 

  • 100% employer-matched Defined Contribution Pension Plan. 

  • Annual performance-based Incentive Bonus. 

  • A gifted week of vacation in your first year + optional Vacation Purchase Program. 

  • Support for professional development, training, and certifications. 

  • Wellness programs, health resources, and fitness discounts. 

 
Pay Range: 
$99,177 - $132,236 

#CBM2

#LI-VS1

This posting is for an existing vacancy within our organization / Ce poste est actuellement vacant au sein de notre organisation.

The Base Pay range may vary depending on the successful candidate or other relevant job-related factors such as knowledge, skills, qualifications, experience and education/training. In addition to Base Pay, eligible Medavie employees may participate in various performance-based incentive programs. Payments under these programs are discretionary and subject to both individual and organizational results.  


We believe our employees should reflect the communities we serve and welcome applications from candidates of all backgrounds. To provide the best experience possible, we will support you with accommodations or adjustments at any stage of the recruitment process. Simply inform our Recruitment team of your needs.  We are committed to making sure recruitment, retention, advancement, and compensation are fair and accessible while following all relevant human rights and privacy laws. We appreciate everyone who has shown interest in this position. Only those selected for an interview will be contacted.


While Medavie may use automated tools, including AI, to support application screening, candidates are expected to complete all recruitment interactions independently—without AI assistance—to ensure a fair and equitable process.


If you experience any technical issues throughout the application process, please email: Medavie.Recruitment@medavie.ca.

We are committed to hiring military and Veteran spouses and encourage you to identify your connection with the MSEN when reaching out to us or applying to any of our open roles.

 

Have questions or want to learn more about us? We would love to hear from you!

joy.bonaidollo@medavie.ca

 

Whenever possible, reach out to a named contact rather than a general inbox  - it helps ensure a quicker, more personalized response. If you hit a bounce-back, let us know at

employment.Emploi@cfmws.com

 

 

About Medavie

 

Who we are

We’re a team of over 8,000 professionals serving clients from coast-to-coast with operations in most provinces. We provide health benefits to nearly 1 in 10 Canadians and manage emergency medical services for nearly 1 in 15 Canadians.

We’ve been a leading health services partner for individuals, employers and governments across Canada for 80 years and a premier all-in-one carrier that provides health, dental, travel, life and disability benefits to individuals and organizations.

We've been recognized as one of Canada's Most Admired Corporate Cultures, one of Canada's Top 100 Employers, and an Imagine Caring Company.

 

What we value

Our values are inherent to our culture and provide the framework for each interaction we have and transaction we make, while providing a clear set of expectations to empower employees to do the right thing for everyone we serve. We are:

Caring – We show compassion in everything we do

Accountable – We follow through on our commitments

Responsive – We have the courage to act and adapt

Innovative – We encourage and value new ideas

Community-minded – We achieve more together

More than simply a poster on the wall, our mission of improving the wellbeing of Canadians represents the purpose of our organization ― and we align that with our culture.

 

What we give back

As a not-for-profit organization, we don’t answer to shareholders. Instead, we invest our earnings in our business, our communities and, most importantly, our employees. We use some of these earnings to support:

Programs to support causes that are close to our employees' hearts, matching the volunteer hours and donations they contribute

An annual United Way workplace campaign led by employees in each of our locations

The Medavie Foundation, which invests in community initiatives and organizations that improve the wellbeing of Canadians, focuses on some of the most pressing mental and physical health challenges facing Canadians.

 

We want to meet you as you are

At Medavie Blue Cross, we foster a culture of openness, understanding and a sense of belonging where everyone can bring their true selves to work. Nearly 70% of our management roles are held by women and we’re committed to creating a diverse, equitable and inclusive workplace where everyone is valued for who they are and what they contribute. We will accommodate people with disabilities during the recruitment, selection and hiring processes.

 

What we offer

If you live our values and deliver results, you’ll experience meaningful, rewarding work in a purpose-centred, inclusive organization that provides:

Flexible work options: We want you to work where you work best. We offer work from home, from the office, or a hybrid of the two, while ensuring you feel connected to your team and to our purpose. Our flexibility goes beyond location. We also have flexible working hours and part-time options available.

Competitive compensation: We believe in rewarding our employees for the skills they bring to their jobs and the results they deliver. This includes competitive compensation that will reflect your experience and expertise and annual performance-based incentives, a 100% employer-matched defined contribution pension plan, an employee RRSP, one-on-one financial counselling, vacation and personal days to help you rest, refuel and balance your life.

Career Growth: Internal talent mobility and growth are an integral part of our success. Employees are empowered to own their career development and have rewarding experiences in a variety of work areas. Supportive leadership will encourage and coach you to maximize your potential so you can access multiple learning pathways to develop. Our leadership development program and other programs, such as mentoring, performance-based management and education assistance, are offered to provide employees with an environment of lifelong learning.

 

Outstanding benefits: Wellbeing is at the centre of everything we do and this starts with our employees. To help you take a proactive approach to your health, we provide:

  • Comprehensive benefits to support you and your family, including fully paid premiums for medical, dental and vision insurance
  • Extensive mental health support (including virtual care options and an employee family assistance program)
  • Health spending and personal wellness accounts that allow you to claim everything from art gallery memberships to Wi-Fi, fitness membership discounts, and more
  • A digital rewards and recognition program to support and empower you on your wellbeing journey
  • Family-friendly and inclusive benefits like maternity and paternity leave top-up, gender affirmation support and fertility coverage to support your growing family