Senior Application Security Architect, Enterprise Technology
Save this job and keep your search organized
Create a free account to save jobs, create alerts and return to this listing from your dashboard.
Senior Application Security Architect, Enterprise Technology
ABOUT ONEX:
Onex is an investor and asset manager that invests capital on behalf of Onex shareholders and clients across the globe. Formed in 1984, we have a long track record of creating value for our clients and shareholders. Onex became a public company in 1987 and is listed on the Toronto Stock Exchange under the symbol ONEX. Onex’ two primary businesses are Private Equity and Credit. In Private Equity, we raise funds from third-party investors and invest them, along with Onex’ own investing capital, through the funds of our private equity platforms: Onex Partners and ONCAP. Similarly, in Credit, we raise and invest capital across several private credit, liquid credit and public equity strategies.
Our investors include a broad range of global clients, including public and private pension plans, sovereign wealth funds, insurance companies, family offices and high net worth individuals. Onex has $56 billion in assets under management, of which $9.4 billion is Onex’ own investing capital. We generate value for our shareholders through two segments: Investing and Asset Management.
We are seeking an experienced security professional to join our Enterprise Technology group as a Senior Application Security Architect, based in Toronto. Reporting to the Manager, IT Cloud Services, this role will strengthen how Onex assesses and secures internally developed, vendor-integrated, open-source and emerging technology solutions. The successful candidate will lead practical application security architecture reviews, threat modelling and secure software development lifecycle standards; perform targeted reviews of security-critical code and controls; and partner with technology and business teams to move solutions safely into production. The role has a strong cloud application security focus, with exposure to AI/LLM platforms and other emerging technologies, and requires someone who can balance technical depth, sound judgement and collaborative delivery.
Key Responsibilities:
- Define and maintain practical secure software development lifecycle (SDLC), application security architecture and production-readiness standards.
- Establish risk-based review criteria and perform security reviews of internet-facing, sensitive-data, AI-enabled and other high-risk applications and platforms.
- Conduct threat modelling and architecture assessments covering applications, APIs, data flows, identity, cloud services, third-party dependencies and deployment topology.
- Perform targeted source-code reviews of security-critical areas, including authentication, authorization, input handling, data access, secrets, session management and integrations.
- Assess controls related to identity, API security, encryption, secrets management, network exposure and segmentation, logging, monitoring and data protection.
- Document and prioritize material risks and remediation; validate that required controls are addressed, maintain review evidence and route material exceptions through formal risk acceptance.
- Develop reusable secure reference architectures, design patterns, checklists and guidance that help teams deliver secure and supportable solutions.
- Define and support appropriate automated security controls within CI/CD pipelines, including code, dependency, secret, container and infrastructure-as-code scanning, in partnership with the teams that own implementation and operation.
- Assess open-source and third‑party components for provenance, known vulnerabilities, patching practices and supportability, and identify licensing concerns for review with Legal or Procurement.
- Apply established application, cloud, identity, data and software supply‑chain security principles to AI/LLM applications, self‑hosted models, AI coding tools and other emerging technologies.
- Partner with cybersecurity, cloud services, infrastructure, analytics, development teams and business stakeholders to provide practical guidance and support remediation while maintaining clear ownership within accountable teams.
- Support selected proofs of concept, validation testing and post‑deployment verification where hands‑on technical involvement adds value.
Candidate Profile:
- 7+ years of relevant experience across application security, software/cloud engineering, DevSecOps or cybersecurity, with significant application security or secure architecture experience.
- Proven experience with security architecture reviews, threat modelling and secure design assessments for modern applications, APIs and cloud services.
- Strong knowledge of secure SDLC and application security controls, including identity and access, API security, secrets management, encryption and data protection.
- Experience securing cloud applications across identity, networking, A