Cyber Security Architect
Aviva is hiring a Cyber Security Architect. It pays $140k-$190k a year and Level rates it ; you can apply on Level.
AI in this role
Individually we are people, but together we are Aviva. Individually these are just words, but together they are our Values – Care, Commitment, Community, and Confidence.
At Aviva Canada, we put people first, our employees, our customers, and our communities. We’re proud of a culture built on care, inclusion, and collaboration, where your voice matters and your growth is supported. We’re not just about insurance; we’re about making a real difference by protecting what matters most.
The Cyber Security Architect is responsible for defining, designing, and assuring security architecture across the organization’s on-premises and hybrid technology estate. The role will work closely with Infrastructure, Cyber Security, Engineering, Risk, and delivery teams to ensure security is embedded by design and that solutions meet enterprise security, resilience, privacy, and regulatory requirements.
What you'll do
- Work with the Cybersecurity team to define and maintain security architecture, standards, reference patterns, and roadmaps for on-premise, cloud, and hybrid infrastructure.
- Embed cybersecurity requirements (‘security by design’) early in initiatives during the early design phases and subsequently assist the Security Advisory team on later stage cybersecurity assessments of initiatives.
- Provide security architecture leadership for data centres, cloud, networks, servers, storage, virtualization platforms, databases, middleware, end-user computing, and infrastructure management services.
- Design and assure security controls across core infrastructure, including network services, servers, Active Directory, virtualization, storage, backup and recovery, cyber vault, endpoint protection, encryption, key management and third-party connectivity.
- Perform security design reviews, and technical guidance to engineering, data science, and platform teams.
- Partner with Cyber Operations to ensure infrastructure designs support effective monitoring, logging, detection, incident response, and recovery using SIEM, SOAR, XDR, EDR, NDR, IDS/IPS, and related security capabilities.
- Support cyber resilience initiatives, including immutable backup, privileged recovery, infrastructure recovery, ransomware containment, and recovery testing.
- Assess and guide the security of the organization’s growing AI footprint, including AI platforms, AI-assisted development tools, and their integrations with enterprise infrastructure.
- Define appropriate AI security guardrails covering identity and access, data protection, prompt and context security, model and tool integration, logging, monitoring, human oversight, and incident response.
- Evaluate AI-related threats such as prompt injection, sensitive-data leakage, model or knowledge-source poisoning, excessive agent privileges, insecure tool use, rogue agent behaviour, and unsafe AI-generated code.
- Stay on the forefront of cyber – keep up-to-date with the latest trends and technologies to evaluate how they would address the evolving threat landscape.
- Provide technical leadership, coaching, and guidance to architects, engineers, project teams, and external delivery partners.
- Monitor emerging infrastructure and AI security threats, assess their relevance to the organization, and recommend pragmatic changes to security architecture and controls.
What you'll bring
- Extensive experience (5+ years) in Cyber Security Architecture with strong and demonstrable focus on hybrid infrastructure ecosystem in a large/complex enterprise.
- Work experience (2+ years) in cloud and hybrid security, particularly AWS, including IAM, KMS, GuardDuty, Security Hub, Private Link, WAF, CloudTrail, and network security controls.
- Strong hands-on knowledge of on-premises infrastructure security across enterprise networking, identity and access services, Windows/Linux servers, virtualization platforms, storage, backup, cyber recovery, endpoint security, vulnerability management, patching, certificates, encryption, and key management.
- Solid understanding of Zero Trust, Defense-in-Depth, network isolation, least privilege, secure administration, and privileged-access controls.
- Exposure to security operations technologies and processes, including SIEM, SOAR, XDR, EDR, NDR, logging, detection engineering, threat hunting, and incident-response playbooks.
- Good understanding of cyber resilience and recovery architecture, including ransomware containment, backup integrity, clean-room recovery, identity recovery, and recovery validation.
- Knowledge of AI and Generative AI security, including LLMs, RAG, vector databases, embeddings, AI agents, tool use, AI-assisted code generation, prompt injection, data leakage, model and RAG poisoning, agent privilege escalation, insecure tool integration, AI supply-chain risk, and security controls for prompts, context, embeddings, memory, outputs, knowledge sources, models, plugins, tools, and supporting infrastructure.
- Familiarity with AI security guidance such as the OWASP Top 10 for LLM Applications, OWASP Agentic AI guidance, MITRE ATLAS, and the NIST AI Risk Management Framework.
- Ability to assess AI solutions from an enterprise infrastructure perspective, including hosting, network connectivity, identity, data flows, isolation, monitoring, resilience, and integration dependencies.
- Ability to balance strategic target-state architecture with practical short-term delivery needs and infrastructure constraints. Strong analytical and problem-solving skills, with the ability to translate complex cyber risks into clear design decisions and actionable recommendations.
- Excellent written and verbal communication skills, with the ability to influence engineers, architects, delivery leaders, risk partners, and executive stakeholders.
What makes you stand out
- Experience working within financial services, insurance, or another highly regulated industry is preferred.
- Relevant certifications an asset: CISSP (or CISSP-ISSAP), SABSA, AWS Certified Security – Specialty, CCSP, and emerging AI/GenAI security certifications.
- Proven ability to design and govern enterprise security architectures, champion security-by-design, and collaborate across business and technology teams to deliver secure solutions aligned with cybersecurity strategy, governance, and Aviva security standards.
What you’ll get
- The salary band for this position ranges from $140,000 to $190,000. Please note that individual salary is determined by factors such as job-related knowledge, skills and experience, as well as internal equity.
- Compelling rewards package including base compensation, eligibility for annual bonus, retirement savings, share plan, health benefits, personal wellness, and volunteer opportunities.
- Outstanding Career Development opportunities.
- We’ll support your professional development education.
- Competitive vacation package with the option to purchase 5 extra days off per year.
- Employee driven programs focused on gender, LGBTQ+, origins, diversity, and inclusion.
- Corporate wellness programs to support our employees’ physical and mental health.
- Employee discount on home and auto insurance (where applicable).
- Hybrid flexible work model.
This job advertisement is for a new vacancy which has been posted both internally & externally.
Aviva Canada may use AI (Artificial Intelligence) tools to assist us throughout the recruitment process to screen, assess or select applicants for a position.
Aviva Canada welcomes applications from all qualified individuals and has a process in place to provide accommodations for persons with disabilities at all stages of the hiring process and during employment. If you require an accommodation during the interview or hiring process, please contact your Aviva Talent Acquisition Partner so that an appropriate accommodation can be arranged.
#LI-PS1
#LI-Hybrid
How we rate this
Cyber Security Architect at Aviva rates 18 out of 100 for how much of the daily work is AI. That makes it Little AI (AI Level 1 of 4). The level is about AI in the job, not seniority.
Little AI. AI is not part of the work.
- ●●●● Builds AI80 to 100
- ●●●○ Works on AI60 to 79
- ●●○○ Uses AI40 to 59
- ●○○○ Little AI0 to 39
Levels come from how often the tools, models and workflows of the role are named in the posting itself. Open the description and count.
Prepare for this job
A free preview built only from this posting: what it asks for, what you could be asked in an interview, and how to adjust your resume.
Skills and AI tools this role asks for
Questions you could be asked
- How would you design a retrieval step so the model answers from real data instead of guessing?
- How do you decide when an AI agent can act on its own versus asking for approval first?
Adapt your resume
- List these exact terms on your resume: RAG and AI agents. An applicant tracking system matches the wording, not the idea.
- Attach one line of real, concrete experience to at least one of them — a tool named with nothing behind it rarely survives a human read.
Want an expert to read your CV for this job?
Free. Send your CV and the role you want next. We reply by email within 2 to 4 business days.
Get a free CV reviewGet new cybersecurity jobs by email
One email a week with the new cybersecurity jobs, each rated for how much AI is in the work. No recruiter spam, unsubscribe in one click.
Free. One email a week. Unsubscribe in one click.
Similar roles
Security roles that involve little AI, at other companies.
What kind of AI work fits you?
Answer 12 practical questions in about three minutes. Get a simple profile, the work it points to, and live roles to explore next.
Find my next step