Architect Security
Skills
About the role
The Opportunity
Chartwell Retirement Residences is seeking a Security Architect to join the Information Security team as a senior technical leader. In this role, you will define and drive enterprise security architecture strategy in support of Chartwell's multi-year information security roadmap and Zero Trust Architecture vision. You will translate business and risk objectives into secure, scalable technical designs across our identity, cloud, network, and endpoint environments - and act as the trusted security design authority for technology and business initiatives across the organization.
This is a hands-on architecture role: you will set standards and reference architectures, but you will also work directly in the platforms you design for, partnering with other members of the security, infrastructure, and application teams to see designs through to implementation.
Key Accountabilities
Own and evolve Chartwell's enterprise security architecture, reference architectures, and design standards in alignment with the information security strategy and Zero Trust Architecture principles.
Lead security design for identity and access management, including authentication, authorization, federation, privileged access, and conditional access design across Active Directory, ADFS and Entra ID environments.
Mature network security architecture, including secure access (SSE/SASE), network segmentation, and least-privilege access models.
Define and continuously improve the security posture of Microsoft 365 and Azure, including Purview (DLP, sensitivity labels, retention), Exchange Online, SharePoint Online, and Entra ID configuration baselines.
Provide security design review and consultation for new projects, applications, cloud services, and infrastructure changes, embedding security requirements early in the lifecycle.
Lead design of Agentic AI security strategy
Develop and maintain security standards, patterns, and hardening baselines
Partner with security operations on detection and response architecture, ensuring telemetry, logging, and control coverage across endpoints, identity, email, and network layers.
Assess and advise on the security of third-party and SaaS solutions, including AI-enabled platforms, as part of vendor risk and technology intake processes.
Contribute to incident response as a senior technical escalation point, and translate lessons learned into architectural improvements.
Communicate architecture decisions, risks, and trade-offs clearly to technical teams and executive stakeholders, including contributions to board- and committee-level reporting.
Qualifications
Education:
University/College degree in Computer Science
Certificate in (or working towards) information security (CISSP, CISA, CSIM, CRISC)
Skills & Abilities:
10+ years of progressive experience in information security, with 5+ years in a security architecture or senior security engineering role.
Deep expertise in identity and authorization: Entra ID / Azure AD, Active Directory, ADFS or modern federation (SAML, OIDC, WS-Federation), conditional access, MFA, and privileged access management.
Strong working knowledge of zero trust network architecture and its practical application to networks, identity, endpoints, and data.
Proven experience securing Microsoft 365 and Azure at enterprise scale, including Purview, and cloud security posture management.
Experience designing and operating email security, web security, and endpoint detection and response controls in a layered defence model.
Ability to produce clear architecture artifacts: reference architectures, design documents, standards, and threat models.
Good understanding of evolving AI tools, MCPs and associated risks
Strong communication skills, with the ability to influence stakeholders from engineers to executives.
Preferred Product Experience
Cisco Umbrella / Cisco Secure Access (SWG, DNS security, secure client)
Microsoft 365 security and compliance stack (Defender, Purview, Entra ID)
Proofpoint (email protection, targeted attack protection)
CrowdStrike Falcon (EDR, identity protection, exposure management, NG-SIEM)
Preferred background
Relevant certifications such as CISSP, CISSP-ISSAP, SABSA, CCSP, or equivalent.
Experience with security frameworks and risk methodologies (CIS Controls, NIST CSF, CIS RAM).
Exposure to AI governance and securing AI-enabled or agentic platforms.
University Degree in Computer Science or related discipline
Working Conditions
Hybrid working arrangements with a minimum of 2 days in the office per week
Occasional need to work outside of office hours
At Chartwell, we’re all about Making People’s Lives BETTER: the lives of our residents and their families, and the lives of our employees. Join an exceptional group of diverse, inspiring, and caring people who are empowered to provide personalized, human experiences for our residents and staff through the connections they make every day within our communities.
Chartwell may use artificial intelligence to assist in screening and assessing applicants for this position.
We thank all applicants for their interest, however, only those selected for further consideration will be contacted.
Questions about this role
Want AI Applyd to auto-apply to roles like this?
We tailor your resume per posting, fill the forms, and track replies for you.