Lead Security Architect (Director level, individual contributor)
Manulife Financial
Job Description
At Manulife, we are changing the way we unlock value and secure the enterprise through technology and we want you to be part of it! We are growing our cybersecurity program with the vision to deliver quality applications using AI that add value to our customers, faster and securely, at scale. The customer is at the focus of everything we do, and millions of end users rely on our products daily.
We are building a state‑of‑the‑art cybersecurity program to better protect the firm’s critical assets.
As a Lead Security Architect, you’ll be responsible for designing, developing, and implementing robust security strategies and solutions to protect Manulife’s digital assets from advanced cyber threats. In this hub‑and‑spoke model, you will report to the Chief Security Architect and will be the dedicated security architecture lead for a specific business unit, ensuring alignment with the global security framework while addressing the unique needs of the segment. You will play a crucial role in shaping our global security posture and ensuring security is a foundational element of our technology and business initiatives.
Position Responsibilities
- Architectural Design: Lead the design and development of robust security frameworks, standards, and best practices for global systems, data, and networks. This includes creating reference architectures and implementation patterns for security solutions.
- Strategic Planning: Translate business, technology, and threat drivers into practical security roadmaps. You’ll ensure our security strategy is aligned with broader organizational goals.
- Financial Analysis: Conduct financial evaluations of security technologies, including quantifying purchasing and licensing options, estimating labor costs, and calculating the total cost of ownership, return on investment, or payback period.
- Project Management: Draft project plans for security service and technology deployments and coordinate with stakeholders across the organization to ensure successful implementation.
- Collaboration & Integration: Work closely with various teams across Manulife’s business and IT units—including enterprise architecture, development, and risk management—to seamlessly integrate security throughout the entire project lifecycle.
- Risk Management: Conduct comprehensive risk assessments to identify vulnerabilities and define necessary controls. Partner with global information risk management teams to prioritize and mitigate risks effectively.
- Security Evaluation: Continuously evaluate the security of new and emerging technologies and potential solutions. You will stay ahead of the curve on cybersecurity trends to recommend and implement innovative solutions.
- Mentorship & Communication: Act as a security subject matter expert, coaching and mentoring development teams. You will also communicate complex security standards and strategies to both technical staff and senior management with clarity and influence.
- AI Security: Design and implement security frameworks for Machine Learning (ML), Generative AI (GenAI), and Agentic AI systems. Evaluate AI‑powered security tools and integrate artificial intelligence capabilities into security operations and threat detection.
- Domain‑Specific Accountabilities:
- Application Security: Assess solution architectures for compliance with security standards, define secure service interfaces, and provide guidance to application security engineers on threat modelling and secure software development methodologies.
- Cloud Security: Provide deep expertise in securing multi‑cloud computing environments (SaaS, IaaS, PaaS), with a strong focus on platforms like Microsoft Azure and AWS.
Office Location
Toronto – Canada (ideal) or Waterloo - Canada.
Work Arrangement
Hybrid (3 days in office, 2 days from Home); Remote working option is not available.
Travel Flexibility
Willingness and ability to travel within Canada and USA to support business operations and stakeholder engagement.
Required Qualifications
To succeed in this role, a candidate must have a strong blend of technical expertise, professional experience, and interpersonal skills.
- Education & Certifications: Bachelor’s or master’s degree in computer science, information systems, cybersecurity, or a related field.
- Relevant industry certifications such as CISSP or CCSP are required.
- Experience: At least 10 years of experience specifically in senior information security architecture roles, with demonstrated progression in responsibility and complexity.
- Proven experience in the financial services industry, with understanding of regulatory requirements, compliance frameworks, and industry‑specific security challenges.
- Experience in using architecture methodologies such as SABSA, Zachman, and/or TOGAF.
- Direct, hands‑on experience or strong working knowledge of managing security infrastructure—e.g., firewalls, intrusion prevention systems (IPSs), web application firewalls (WAFs), endpoint protection, SIEM, and log management technology.
- Verifiable experience reviewing application code for security vulnerabilities.
- Experience securing CI/CD pipelines.
- Direct experience designing IAM technologies and services, including Active Directory, Lightweight Directory Access Protocol (LDAP), and Amazon Web Service (AWS) IAM.
- Extensive knowledge of full‑stack IT infrastructure, including applications, databases, operating systems—Windows, Unix, and Linux, hypervisors, IP networks—WAN and LAN, storage networks—Fibre Channel, iSCSI, and NAS, backup networks and media, containers/Kubernetes.
- Soft Skills:
- Communication: Excellent verbal and written communication skills are crucial for articulating complex technical concepts and influencing stakeholders at all levels.
- Problem‑Solving: Strong analytical, problem‑solving, and decision‑making abilities.
- Collaboration: The capacity to balance competing priorities and maintain a collaborative and positive attitude.
Preferred Qualifications
- Experience from large complex environment is highly preferred but not a must.
- Experience from large financial Org’s is a definite plus but not a must.
Benefits & Working Conditions
- We’ll empower you to learn and grow the career you want.
- We’ll recognize and support you in a flexible environment where well‑being and inclusion are more than just words.
- As part of our global team, we’ll support you in shaping the future you want to see.
The role being advertised is an existing vacancy.
EEO Statement (Japan)
マニュライフ・ファイナンシャル・コーポレーションは、「あなたの未来に、わかりやすさを」を提供する、国際的な大手金融サービスプロバイダーです。当社について詳しくは https://www.manulife.co.jp/ をご覧ください。
マニュライフは機会均等を是とする雇用主です。マニュライフ/ジョン・ハンコックでは、多様性を受け入れます。私たちは、サービス提供先であるお客さまと同様に、多様な人材を引きつけ、育成し、定着させ、文化や個人の力を受け入れる包括的な職場環境を促進するよう努めています。当社は公正な採用、定着、昇進、報酬に努めています。当社のすべての慣行およびプログラムは、人種、祖先、出身地、肌の色、民族的出自、市民権、宗教または宗教的信念、信条、性別(妊娠および妊娠関連の状態を含む)、性的指向、遺伝的特徴、退役軍人としての地位、性自認、性に関する表明、年齢、婚姻状況、家族状況、障害、または適用法で保護されるその他の要因に対する一切の差別を行うことなく管理されます。
雇用への平等なアクセスを提供するために、障壁を取り除くことが当社の優先事項です。人事担当者は、応募者が応募プロセス中に合理的配慮を要求する場合に協力します。配慮要求のプロセス中に共有されるすべての情報は、適用される法律およびマニュライフ/ジョン・ハンコックのポリシーに準拠した方法で保存および使用されます。申請プロセスにおいて合理的配慮を要求するには [email protected] までご連絡をお願いします。
Salary
Toronto, Ontario.
Salary range: $113,260.00 CAD - $210,340.00 CAD
Employees also have the opportunity to participate in incentive programs and earn incentive compensation tied to business and individual performance. The actual salary will vary depending on local market conditions, geography and relevant job‑related factors such as knowledge, skills, qualifications, experience, and education/training. If you are applying for this role outside of the primary location, please contact [email protected] for the salary range for your location.
Manulife offers eligible employees a wide array of customizable benefits, including health, dental, mental health, vision, short‑ and long‑term disability, life and AD&D insurance coverage, adoption/surrogacy and wellness benefits, and employee/family assistance plans. We also offer eligible employees various retirement savings plans (including pension and a global share ownership plan with employer matching contributions) and financial education and counseling resources. Our generous paid time off program in Canada includes holidays, vacation, personal, and sick days, and we offer the full range of statutory leaves of absence.
If you are applying for this role in the U.S., please contact [email protected] for more information about U.S.-specific paid time off provisions.
We use data and analytics technologies, such as artificial intelligence (AI), and automated processing tools, to analyze and process the information you provide to us or third parties in the application process. For more information, please refer to our personal information collection statement.
#J-18808-Ljbffr