Maarut - 21 emplois
East York, ON
Fermé
Détails de l'emploi :
The Senior Technology Architect role requires deep knowledge, expertise, and experience in cyber security solutions, security operations (SecOps) solutions and practices, automation and artificial intelligence (AI) in cyber security, managed security services, and next-generation network security. The resource also requires hands-on experience in analyzing, configuring, implementing, and troubleshooting cyber security models, automation solutions, and threat detection, particularly within the education sector, preferably in the Ontario K–12 school board environment.
This resource is responsible for, but not limited to:
- Leading operational cyber defense guidance, incident coordination, monitoring maturity, and integration with MSS/MDR providers, including:
- Threat monitoring, detection, and analysis across network, endpoint, identity, and cloud environments
- Incident response coordination, escalation management, and root cause analysis
- Security operations centre (SOC) coordination and operational alignment
- Establishing and enhancing cyber operational readiness (playbooks, processes, response validation)
- MSS onboarding, integration, and service adoption across boards
- Delivering solution guidance, technical training, and implementation support for next-generation network and security technologies, including:
- Security Service Edge (SSE) / Secure Access Service Edge (SASE), including integration of network and security functions such as Secure Web Gateway (SWG), Cloud Access Security Broker (CASB), Zero Trust Network Architecture (ZTNA), and Firewall-as-a-Service (FWaaS)
- SD-WAN (Software-Defined Wide Area Network) and SDN (Software-Defined Networking)
- Identity and access management (passwordless, password-based, certificate-based, and multi-factor authentication (MFA))
- Endpoint security (Endpoint Protection Platforms (EPP), Endpoint Detection and Response (EDR), and Extended Detection and Response (XDR))
- Advanced threat protection (Intrusion Prevention Systems (IPS), Intrusion Detection Systems (IDS), Network Access Control (NAC), and Distributed Denial-of-Service (DDoS) protection)
- AI/ML-enabled monitoring, analytics, and automation
- Incident Response (IR) and Incident Management (IM)
- Vulnerability management and patching automation
- Penetration testing and automated red teaming
- Operational Technology (OT) security
- Providing technical guidance, solution delivery, training, and implementation support for hybrid cyber security operating models integrating internal teams and Managed Security Service Providers (MSSPs), including:
- MSS strategy, onboarding, optimization, and performance management
- Alignment and integration of Security Information and Event Management (SIEM), Security Orchestration, Automation and Response (SOAR), EDR/XDR, and threat intelligence platforms
- School board MSS readiness, transition planning, and governance models
- Security operations architecture, threat detection, incident response, and automation workflows
- Governance, risk, and compliance in hybrid (in-house and outsourced) environments
- Providing subject matter expertise in Network Operations Centre (NOC) and Security Operations Centre (SOC) technologies and tools, including SIEM, SOAR, and network monitoring and management platforms
- Managing and optimizing SecOps platforms (SIEM, SOAR, EDR/XDR, CASB, IDR, vulnerability management), including:
- Telemetry ingestion, log normalization, and real-time correlation
- Development and maintenance of detection use cases
- Integration of threat intelligence into detection workflows
- Maintenance of security content (rules, dashboards, playbooks)
- Leading incident investigation and response activities, including:
- Deep-dive analysis, root cause determination, and facilitation of cyber exercises to validate readiness
- Conducting baseline reviews, vulnerability triage, and collaborating with MSSPs to track and validate remediation efforts
- Driving MSS service optimization, including:
- Operational reporting, performance metrics, and continuous improvement initiatives
- Delivering training, operational guidance, and stakeholder engagement across boards, including:
- Threat response workflows
- Defensive posture validation
- Cross-board threat sharing
- Presenting technical findings, risk insights, and strategic recommendations to senior leadership and external stakeholders
- Providing regular status updates and reporting on assigned deliverables, milestones, and performance metrics
- Applying a collaborative approach to solution definition, development, and implementation with multiple stakeholder groups with differing needs and expectations
- Aligning with industry and legislative advancements at the federal, provincial/local level (e.g., Enhancing Digital Security and Trust Act, 2024 (EDSTA))
- Delivering on other duties as assigned
This work involves working in close partnership with various government departments, the K-12 education sector, telecommunications providers, and network and cyber security technology vendors to develop tailored approaches and implementation plans. To support various stakeholders, the resource must be available to perform hands-on configuration, troubleshooting, and training at the client site. Therefore, the resource must be available to travel same day or overnight in Ontario, as needed. The unit manager may assign other related board work for other unit or branch initiatives, as required.
Requirements Experience and Skill Set RequirementsMust Haves:
- 5+ years of experience with network infrastructure (LAN/WAN, VPN, VLAN) and network hardware (switches, routers, firewalls)
- 5+ years of experience with software-defined networking technologies (SDN/SD-WAN) (e.g., Fortinet, Meraki, Palo Alto, Aruba)
- Experience integrating networking and security architectures (e.g., SASE, ZTNA, NDR)
- 10+ years of experience in cyber security and next-generation network security
- 5+ years of experience implementing enterprise security architectures and automation workflows
- Proven experience with:
- SSE/SASE architectures (SWG, CASB, FWaaS, ZTNA)
- Endpoint security (EPP, EDR, XDR)
- Advanced threat protection (IPS, IDS, NAC, DDoS protection)
- Identity and access management (passwordless, MFA, certificate-based authentication)
- Strong understanding of layered security models and frameworks (e.g., NIST CSF v2, CIS Controls v8)
- Extensive experience managing and optimizing SecOps platforms, including SIEM, SOAR, EDR/XDR, CASB, IDR, and vulnerability management tools
- Strong experience in detection engineering
- Proven experience in incident response, including deep-dive investigations, root cause analysis, and escalation management
- Expertise in telemetry ingestion, log normalization, and real-time correlation of security events
- 5+ years of experience coordinating and leading complex, multi-stakeholder technical initiatives
- 5+ years of experience preparing technical documentation and communications (e.g., reports, briefings, recommendations)
- Experience supporting cross-organizational collaboration and knowledge sharing (e.g., threat intelligence sharing)
- Bachelor's degree in computer science, cyber security, or a related field
- Industry-recognized security certifications preferred
Nice to Have:
- 3+ years of experience supporting Ontario K–12 school board network environments (WAN, LAN, Wi-Fi, internet delivery)
- Experience supporting MSSP onboarding, transition planning, and operational readiness in multi-organization environments
- Postgraduate degree (e.g., M.Sc. and/or Ph.D.) in computer science, cyber security, or engineering is preferred
- Knowledge of Government of Ontario standards (e.g., GO-ITS) and applicable legislation (e.g., Enhancing Digital Security and Trust Act, 2024 (EDSTA))
- 5+ years of experience working in the Ontario public sector, with at least 3+ years supporting K–12 school board network and cybersecurity environments