At Manulife, we are changing the way we unlock value and secure the enterprise through technology and we want you to be part of it! We are growing our cybersecurity program with the vision to deliver quality applications using AI that add value to our customers, faster and securely, at scale. The customer is at the focus of everything we do, and millions of end users rely on our products daily. We are building a stateoftheart cybersecurity program to better protect the firms critical assets. Work arrangement Hybrid (3 days in office, 2 days from home); Remote working option is not available. Travel Flexibility Willingness and ability to travel within Canada and USA to support business operations and stakeholder engagement. Position Responsibilities Architectural Design : Lead the design and development of robust security frameworks, standards, and best practices for global systems, data, and networks. This includes creating reference architectures and implementation patterns for security solutions. Strategic Planning : Translate business, technology, and threat drivers into practical security roadmaps. Ensure the security strategy is aligned with broader organizational goals. Financial Analysis : Conduct financial evaluations of security technologies, including quantifying purchasing and licensing options, estimating labor costs, and calculating the total cost of ownership (TCO), return on investment (ROI), or payback period. Project Management : Draft project plans for security service and technology deployments and coordinate with stakeholders across the organization to ensure successful implementation. Collaboration & Integration : Work closely with various teams across Manulifes business and IT unitsincluding enterprise architecture, development, and risk managementto seamlessly integrate security throughout the entire project lifecycle. Risk Management : Conduct comprehensive risk assessments to identify vulnerabilities and define necessary controls. Partner with global information risk management teams to prioritize and mitigate risks effectively. Security Evaluation : Continuously evaluate the security of new and emerging technologies and potential solutions. Stay ahead of the curve on cybersecurity trends to recommend and implement innovative solutions. Mentorship & Communication : Act as a security subject matter expert, coaching and mentoring development teams. Communicate complex security standards and strategies to both technical staff and senior management with clarity and influence. AI Security : Design and implement security frameworks for Machine Learning (ML), Generative AI (GenAI), and Agentic AI systems. Evaluate AIpowered security tools and integrate artificial intelligence capabilities into security operations and threat detection. DomainSpecific Accountabilities Application Security : Assess solution architectures for compliance with security standards, define secure service interfaces, and provide guidance to application security engineers on threat modelling and secure software development methodologies. Cloud Security : Provide deep expertise in securing multicloud computing environments (SaaS, IaaS, PaaS), with a strong focus on platforms like Microsoft Azure and AWS . Required Qualifications Education & Certifications Bachelors or masters degree in computer science, information systems, cybersecurity, or a related field. Relevant industry certifications such as CISSP (Certified Information Systems Security Professional) or CCSP (Certified Cloud Security Professional) are required. Experience At least 10 years of experience specifically in senior information security architecture roles, with demonstrated progression in responsibility and complexity. Proven experience in the financial services industry, with understanding of regulatory requirements, compliance frameworks, and industryspecific security challenges. Experience in using architecture methodologies such as SABSA, Zachman, and/or TOGAF. Direct, handson experience or strong working knowledge of managing security infrastructuree.g., firewalls, intrusion prevention systems (IPSs), web application firewalls (WAFs), endpoint protection, SIEM, and log management technology. Verifiable experience reviewing application code for security vulnerabilities. Experience securing CI/CD pipelines. Direct, handson experience or a strong working knowledge of vulnerability management tools. Documented experience and a strong working knowledge of the methodologies to conduct threatmodelling exercises on new applications and services. Experience designing the deployment of applications and infrastructure into public cloud services. Direct experience designing IAM technologies and services, including Active Directory, Lightweight Directory Access Protocol (LDAP), and Amazon Web Service (AWS) IAM. Extensive knowledge of fullstack IT infrastructure, including applications, databases, operating systems (Windows, Unix, and Linux), hypervisors, IP networks (WAN and LAN), storage networks (Fibre Channel, iSCSI, and NAS), backup networks and media, containers/Kubernetes. Soft Skills Communication : Excellent verbal and written communication skills are crucial for articulating complex technical concepts and influencing stakeholders at all levels. Translate complex security matters into business terms that are easily understood by colleagues and senior management. ProblemSolving : Strong analytical, problemsolving, and decisionmaking abilities. Collaboration : The capacity to balance competing priorities and maintain a collaborative and positive attitude. Preferred Qualifications Experience from large complex environment is highly preferred but not a must. Experience from large financial Orgs is a definite plus but not a must. When you join our team Well empower you to learn and grow the career you want. Well recognize and support you in a flexible environment where wellbeing and inclusion are more than just words. As part of our global team, well support you in shaping the future you want to see. Manulife is an equalopportunity employer. We value diversity and are committed to fair and inclusive hiring practices across all applicable laws and regulations. #J-18808-Ljbffr
Job Title
Lead cybersecurity architect