Solution Architect Security & API Infrastructure
Job Summary
Solution Architect (Security & API Infrastructure)
Toronto Ontario (Hybrid 4 Days Work From Office)
612 Months
8 Years (5 Years in Security Architecture)
- Solution Architecture
- Security Architecture
- API Infrastructure
- Apigee API Management
- AWS Cloud Architecture
- Akamai
- Cloudflare
- Enterprise Security
- Financial Services
- Lead end-to-end solution architecture across security API and cloud domains.
- Gather requirements and define solution architecture from design through implementation and operational handover.
- Establish architecture patterns standards and reference architectures aligned with enterprise frameworks (TOGAF Zachman etc.).
- Produce architecture artifacts including:
- High-Level Design (HLD)
- Low-Level Design (LLD)
- Data Flow Diagrams
- Sequence Diagrams
- Threat Models
- High-Level Design (HLD)
- Evaluate emerging technologies through Proof of Concepts (POCs) and vendor assessments.
- Design enterprise security architectures covering:
- Encryption at Rest
- Encryption in Transit
- Encryption in Use
- Key Management
- Certificate Lifecycle Management
- Public Key Infrastructure (PKI)
- Encryption at Rest
- Architect fraud detection and digital identity verification solutions using ThreatMetrix or equivalent platforms.
- Define security policies for:
- API Gateways
- Web Application Firewalls (WAF)
- DDoS Protection
- Bot Management
- API Gateways
- Conduct:
- Threat Modeling
- Security Reviews
- Risk Assessments
- Threat Modeling
- Ensure compliance with financial industry standards including:
- PCI-DSS
- SOX
- GDPR
- Open Banking
- PCI-DSS
- Design enterprise API strategies using Apigee including:
- API Proxy Design
- Shared Flows
- Target Servers
- Developer Portals
- Analytics
- OAuth/OIDC
- Rate Limiting
- API Monetization
- API Proxy Design
- Architect edge security solutions using:
- Akamai
- Cloudflare
- Akamai
- Configure:
- WAF Rules
- Bot Manager
- DDoS Protection
- Edge Compute
- DNS Management
- WAF Rules
- Design enterprise DNS architecture including:
- DNSSEC
- Traffic Management
- Failover
- Multi-CDN Strategies
- GSLB
- TTL Strategies
- DNSSEC
- Design secure AWS cloud solutions utilizing:
- VPC
- IAM
- KMS
- CloudFront
- Route 53
- GuardDuty
- Security Hub
- AWS WAF
- AWS Shield
- Lambda
- ECS/EKS
- API Gateway
- VPC
- Implement cloud-native security principles:
- Zero Trust Networking
- Least Privilege IAM
- Secrets Management
- Infrastructure-as-Code Security
- Zero Trust Networking
- Design hybrid and multi-cloud connectivity architectures.
- Participate in Architecture Review Boards (ARBs) and Design Authority forums.
- Define enterprise architecture standards and governance.
- Mentor development teams on architecture and security best practices.
- Collaborate with:
- Enterprise Architects
- Engineering Teams
- Product Owners
- Third-party Vendors
- Enterprise Architects
- Maintain architecture documentation and enterprise architecture repositories.
- 8 years in Solution or Technical Architecture.
- 5 years focused on Security Architecture.
- Hands-on experience with:
- Apigee API Management
- API Proxy Development
- Shared Flows
- Target Servers
- Analytics
- Apigee API Management
- Strong expertise with:
- Akamai (Property Manager WAF/KSD Bot Manager Edge DNS)
- Cloudflare (WAF Workers DNS)
- Akamai (Property Manager WAF/KSD Bot Manager Edge DNS)
- Deep understanding of:
- TLS 1.2 / TLS 1.3
- AES-256
- RSA
- Elliptic Curve Cryptography
- HSM
- Tokenization
- TLS 1.2 / TLS 1.3
- Enterprise DNS architecture experience.
- Practical experience with ThreatMetrix or similar fraud prevention platforms.
- Strong AWS architecture experience (AWS Solutions Architect Professional preferred).
- Financial Services experience is mandatory:
- Banking
- Payments
- Insurance
- Capital Markets
- Banking
- Experience with:
- Architecture Governance
- Technical Debt Management
- Architecture Review Boards (ARBs)
- Enterprise Standards
- Architecture Governance
- Knowledge of compliance frameworks:
- PCI-DSS
- SOX
- FCA
- PSD2
- Open Banking
- PCI-DSS
- Experience across the complete solution lifecycle:
- Discovery
- Design
- Build
- Test
- Deploy
- Operate
- Discovery
- Familiarity with architecture frameworks:
- TOGAF
- C4 Model
- arc42
- TOGAF
- Experience using:
- Lucidchart
- Lucidchart
- Strong understanding of:
- DevSecOps
- CI/CD Pipelines
- Terraform
- AWS CloudFormation
- DevSecOps
- Experience with:
- Microservices
- Event-Driven Architecture
- REST APIs
- GraphQL
- Messaging & Streaming
- Microservices
- Microsoft Azure
- Google Cloud Platform (GCP)
- Okta
- Ping Identity
- Splunk
- Microsoft Sentinel
- SIEM/SOAR Platforms
- Container Security
- Excellent stakeholder communication.
- Ability to present complex technical concepts to executive and non-technical audiences.
- Strong analytical and problem-solving skills.
- Ability to work in fast-paced highly regulated environments.
- Collaborative leadership with experience influencing cross-functional teams.
- Solution Architect
- Security Architect
- Enterprise Architecture
- API Infrastructure
- Apigee
- API Gateway
- OAuth
- OpenID Connect (OIDC)
- AWS
- Cloud Architecture
- Akamai
- Cloudflare
- WAF
- DDoS Protection
- Bot Management
- ThreatMetrix
- PKI
- TLS 1.3
- AES-256
- RSA
- HSM
- Tokenization
- DNS
- DNSSEC
- Route 53
- CloudFront
- IAM
- KMS
- GuardDuty
- Security Hub
- Zero Trust
- DevSecOps
- Terraform
- CloudFormation
- TOGAF
- C4 Model
- REST APIs
- GraphQL
- Microservices
- Event-Driven Architecture
- Financial Services
- Banking
- PCI-DSS
- SOX
- PSD2
- Open Banking
- Architecture Review Board (ARB)
- Solution Design
- High-Level Design (HLD)
- Low-Level Design (LLD)
- Threat Modeling
- Security Architecture
Required Skills:
60-70
Required Education:
Backend Engineer Kotlin Microservices & AKSRole Overview:We are seeking a highly skilled backend developer with strong experience in modern programming languages and frameworks with primary expertise in Kotlin and exposure to Java microservices and cloud Skills:Proficiency in Kotlin with additional experience in Java (Spring Boot Spring Security) and JavaScript () 5 years of backend development experience including: oUnit testing frameworks (e.g.