Job Description
On behalf of our public-sector client, Affinity is seeking a Cloud Security Architect to provide senior cloud security architecture, governance and advisory expertise in support of a cloud security improvement program.
The consultant will define and maintain target-state cloud security architecture and roadmap; design secure identity, network, logging, data protection and resilience patterns; develop cloud security standards and governance; guide security control implementation; translate architecture into actionable work; resolve technical blockers; facilitate architecture reviews and technical decisions; and define security metrics, control validation and assurance evidence.
Architecture and Roadmap
- Define and maintain the target-state cloud security architecture and sequenced roadmap.
- Assess and document current-state Azure Landing Zone security architecture, including management groups, identity, network, data flows, logging, security tooling and resilience dependencies.
- Design secure and reusable architecture patterns for identity, privileged access, network segmentation, secure ingress and egress, logging, data protection, workload placement, resilience and cloud-native services.
- Produce clear architecture diagrams, transition states, technical standards, architecture decision records and implementation guidance.
- Identify technical debt, interdependencies, assumptions and decision points that affect delivery sequencing and risk reduction.
Standards and Governance
- Develop and publish cloud security standards, workload placement rules, secure configuration requirements and assurance criteria.
- Define risk-based exception processes, approval criteria, expiry requirements and compensating-control expectations.
- Establish practical architecture review and technical decision practices that can be sustained after the engagement.
- Align technical standards with privacy, information security, enterprise architecture and operational requirements.
Security Control Design and Implementation Guidance
- Lead Azure Policy catalog rationalization, initiative design, scope, enforcement approach, exemptions and remediation design.
- Guide the design and adoption of Microsoft Defender for Cloud, Microsoft Sentinel, Azure Monitor, Log Analytics, diagnostic settings, monitoring automation and cloud security dashboards.
- Define privileged-access, RBAC, PIM, workload identity, service principal, secrets, certificate and key-management patterns.
- Define secure network architecture, including segmentation, security zones, east-west visibility, approved ingress, forced egress, public exposure controls and network telemetry.
- Define secure DevOps and infrastructure-as-code guardrails, including policy-as-code, pipeline security, configuration-drift detection, approval and rollback requirements.
- Guide backup, recovery, ransomware resilience and control-validation architecture.
Delivery Leadership and Technical Decision-Making
- Translate architecture into actionable work packages, technical dependencies, acceptance criteria and implementation sequencing.
- Facilitate technical working groups, architecture reviews and security decision sessions.
- Provide clear, evidence-based recommendations, options and trade-offs to technical and governance stakeholders.
- Resolve or escalate technical blockers that cross organizational or technology boundaries.
- Support implementation planning while maintaining clear separation between architecture accountability and operational execution.
Independent Analysis and Knowledge Discovery
- Quickly assess unfamiliar environments with limited onboarding and minimal day-to-day direction.
- Gather and reconcile information from documents, configuration evidence, interviews, workshops and subject matter experts.
- Operate effectively where documentation maturity varies and key processes or design decisions are held as tribal or tacit knowledge.
- Elicit undocumented assumptions, dependencies, ownership boundaries and operating practices from subject matter experts.
- Validate conflicting information and clearly document confirmed facts, assumptions, gaps and items requiring technical verification.
- Convert tacit knowledge into reusable architecture artifacts, standards, decision records, process guidance and operational documentation.
Assurance, Reporting and Knowledge Transfer
- Define cloud security metrics, control-validation methods, implementation evidence and technical acceptance criteria.
- Coordinate technical assessments, control testing, attack-path review and remediation verification as required.
- Maintain traceability between identified risks, architecture decisions, implemented controls, evidence and residual risk.
- Communicate technical risk and recommendations clearly to both technical and executive audiences.
- Transfer knowledge to internal teams through documentation, walkthroughs, coaching and structured handover.
- Leave sustainable architecture and governance practices that reduce long-term dependency on external consulting support.
Mandatory Experience Requirements
- Minimum 10 years of progressive experience in information security, cybersecurity architecture or enterprise security architecture.
- Minimum five years of hands-on experience designing, assessing or securing Microsoft Azure environments, including Azure Landing Zones.
- Minimum three years of experience performing a Cloud Security Architect, Cybersecurity Architect, Security Consulting Architect or equivalent senior design role.
- Minimum three years of experience delivering security architecture or cloud security outcomes within formal projects or programs, including work planning, dependencies, risks, milestones, technical decisions, acceptance criteria and stakeholder reporting.
- Demonstrated experience defining target-state architecture, transition roadmaps, cloud standards, technical guardrails and governance practices.
- Demonstrated experience translating security assessments and risk findings into implementable architecture, prioritized remediation and measurable outcomes.
- Demonstrated experience producing executive-ready recommendations and detailed technical artifacts for implementation teams.
- Demonstrated experience influencing technical decisions across matrixed teams without direct authority.
- Demonstrated experience operating in environments with incomplete or evolving documentation and extracting tribal or tacit knowledge from subject matter experts.
- Demonstrated experience planning and completing structured knowledge transfer and handover at the conclusion of a consulting engagement.
Healthcare And Regulated-Environment Experience
- Minimum two years of experience delivering cybersecurity, cloud, architecture or technology-risk work in healthcare, preferably within a Canadian health authority, public healthcare organization or similarly complex health system.
- Demonstrated understanding of the security, privacy, availability, clinical-safety and operational-resilience considerations associated with health information and healthcare services.
- Experience collaborating with privacy, risk, security operations, infrastructure, clinical application, governance and business stakeholders in a regulated environment.
- Experience working within public-sector procurement, governance and project-delivery constraints is preferred.
Certification Requirements
Candidates that following certification, or demonstrate an equivalent current credential and directly comparable expertise will be preferred:
- Microsoft Certified: Cybersecurity Architect Expert, including Exam SC-100, or an equivalent current Microsoft cybersecurity architecture credential.
One or more of the following current certifications is strongly preferred:
- Microsoft Certified: Cloud and AI Security Engineer Associate.
- Certified Information Systems Security Professional (CISSP).
- Certified Cloud Security Professional (CCSP).
- Certified Information Security Manager (CISM).
- The Open Group Architecture Framework (TOGAF) certification or another recognized enterprise architecture credential.
- A current project-delivery credential such as Project Management Professional (PMP), PRINCE2 Practitioner or an Agile delivery certification.
Relevant certifications must be current at the time of submission. Equivalent credentials may be considered where the candidate demonstrates directly comparable Azure security architecture, cloud governance and consulting capability.
Required Technical Skills
- Microsoft Azure Landing Zones, management groups, subscriptions and resource organization.
- Azure Policy, policy initiatives, exemptions, remediation, secure configuration baselines and configuration-drift controls.
- Azure RBAC, Privileged Identity Management, Conditional Access, managed identities, service principals, Azure Key Vault and privileged-access architecture.
- Azure networking, hub-and-spoke or virtual hub patterns, network security groups, segmentation, private connectivity, secure ingress and egress, DNS and firewall integration.
- Microsoft Defender for Cloud, Microsoft Sentinel, Azure Monitor, Log Analytics, diagnostic settings, security telemetry and detection architecture.
- Data classification, workload placement, encryption, key management, sensitive-data protection and privacy-by-design principles.
- Secure DevOps, Azure DevOps, infrastructure-as-code, policy-as-code, pipeline security and automated guardrails.
- Backup, recovery, ransomware resilience, availability architecture and recovery validation.
- Cloud threat modeling, security architecture risk analysis, control assurance and residual-risk assessment.
Affinity Earn
Know someone who’s great for this, or any of our open roles? Earn up to $4,000/year for each successful referral through Affinity Earn. You can also earn up to $50,000 for helping us find new clients. Learn about our referral program at https://affinity-group.ca/earn/ or browse our jobs & follow us at https://www.linkedin.com/company/affinity-staffing/jobs/
About Affinity
Affinity Group is a technology and business consulting and services company. We believe in creating long term relationships between clients and consultants that foster a mutually beneficial partnership. Affinity is an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for all employees. All employment is decided on the basis of qualifications, merit and business need.
For more information on Affinity, please visit www.affinity-group.ca
Job Number: 13985