Principal Security Architect in Haciendas del Canada, Nuevo León at Jobgether
Explore Related Opportunities
Job Description
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Principal Security Architect based in Canada.
This role is focused on shaping security architecture across products, cloud infrastructure, integrations, and emerging technologies. You will evaluate complex security designs, conduct code and vulnerability reviews, and help ensure enterprise-grade protection throughout the product lifecycle. The position combines deep technical expertise with hands-on security engineering and strategic architectural guidance. You will work across AWS, web and browser technologies, cryptography, operating systems, networks, and third-party technologies. You will also collaborate with customers, compliance teams, sales teams, and engineering stakeholders on complex security topics. The role provides an opportunity to influence product security, develop innovative security capabilities, and contribute to technical thought leadership.
Conduct security design reviews covering broad product architecture, individual product changes, cloud infrastructure, and AWS integrations.
Perform security-focused code reviews and identify potential weaknesses, vulnerabilities, and secure coding improvements.
Design and document processes for integrating and deploying enterprise Hardware Security Modules and key management solutions.
Assess third-party software, SaaS providers, and external technologies from a security and architectural perspective.
Review the design and implementation of integrations with third-party software and SaaS platforms, identifying security risks and recommending appropriate controls.
Oversee internal and external security assessments and coordinate technical follow-up on identified findings.
Perform in-depth analysis of vulnerabilities, assessing the potential impact of both third-party and product-specific security issues.
Monitor emerging technologies, web standards, and browser behavior changes and assess their potential impact on products and security architecture.
Support compliance and sales teams with technical security expertise related to regulations, customer requirements, RFPs, and security questionnaires.
Participate in detailed technical discussions with customers regarding security architecture, controls, vulnerabilities, and product capabilities.
Contribute to patent development through technical invention documentation, review, and collaboration with relevant teams.
Create and review technical materials for external audiences, including security blogs, white papers, presentations, and other technical content.
Collaborate with engineering and R&D teams to develop innovative product features and capabilities within the security domain.
Maintain a strong awareness of evolving cybersecurity threats, technologies, standards, and best practices.
Advanced knowledge of applied cryptography, including technologies such as Hardware Security Modules (HSMs) and Trusted Platform Modules (TPMs).
Strong understanding of the complete key management lifecycle, including key generation, storage, distribution, backup, rotation, revocation, and destruction.
Deep expertise in web and browser security technologies, including the Same-Origin Policy, XSS, CSRF, HTTP security headers, browser architecture, and JavaScript engine internals.
Thorough understanding of networking and operating-system fundamentals, including TCP, HTTP, TLS, DNS, firewalls, WAFs, discretionary and mandatory access controls, and sandboxing.
Strong AWS security experience, including IAM, AWS Organizations, EC2, VPC, and related cloud security capabilities.
Familiarity with static and dynamic application analysis concepts, methodologies, and tools.
Advanced proficiency in C/C++, particularly secure coding practices, along with strong experience in at least one additional programming language, preferably Python or JavaScript.
Demonstrated ability to investigate complex technical security problems hands-on and take ownership of finding practical solutions.
Strong architectural thinking and the ability to evaluate security implications across products, infrastructure, integrations, and emerging technologies.
Excellent communication skills and the ability to explain complex security concepts to engineering teams, customers, executives, compliance teams, and other non-specialist audiences.
Ability to collaborate effectively across technical and business functions and contribute to high-impact security decisions.
Master's degree in computer science, engineering, cybersecurity, or a related discipline, or equivalent experience; a PhD is preferred.
A proactive, ownership-oriented approach with a willingness to work hands-on when required to solve challenging security problems.
Competitive base salary of approximately CAD $158,000–$263,000 annually.
Actual compensation may vary based on factors such as experience, knowledge, skills, abilities, and location.
Eligibility for stock-based compensation grants based on company and individual performance.
Remote-first work environment for employees based in Canada.
Opportunity to work on complex security challenges spanning cloud infrastructure, browser technologies, cryptography, networking, and emerging technologies.
Exposure to enterprise customers and large-scale security environments.
Opportunities to contribute to security innovation, technical publications, patents, and new product capabilities.
Collaborative environment emphasizing ownership, direct communication, cross-functional teamwork, technical excellence, and customer-focused outcomes.
Equal opportunity employment environment focused on merit, competence, performance, and business needs.