Technology Architect
Overview
The Ministry of Public and Business Service Delivery and Procurement is seeking a Senior Technology Architect to support the Cloud Access Security Platforms and Proactive Risk Management pillars of the Ontario Government's Cyber Security Strategy. Working within the I&IT Strategy and Cyber Security team, the successful consultant will provide lead architecture and strategy guidance for Security Service Edge (SSE) and network security modernization initiatives across multiple environments. This is a senior-level engagement requiring deep expertise in modern SASE security technologies and enterprise network security architecture.
Key Responsibilities
- Provide lead architecture and strategy guidance for Ontario Government SSE and network security modernization projects, including implementation and support across multiple environments and OS types
- Deliver operational support, deployment coordination, change management, and documentation for new and existing SASE security technologies
- Engineer and operationally support network-security platforms including Palo Alto Prisma Access, Radware Web Application Firewall (WAF), and Cloud Access Security Broker (CASB)
- Collaborate with internal Security teams and external partners to engineer and support SASE platforms aligned with organizational and strategic goals
- Manage vendor relationships for supported products, including issue reporting, research assistance, and resolution tracking
- Create and maintain operational process documentation and procedures for business-impacting incidents and issues
- Provide integration support and development effort for design changes and new business requirements related to network-security technology platforms
- Develop, recommend, implement, and manage technical architecture (hardware, software, database, and communications) in a large, distributed cross-platform environment
- Translate business requirements into solution needs and prepare conceptual, logical, and physical process and data models
- Apply ITIL-based processes in designing and guiding operational workflows and procedures
- Identify relevant environmental requirements and determine development environments appropriate to project needs
Must-Have Requirements
- Advanced hands-on experience with Palo Alto Prisma Access, including configuration, deployment, and operational support
- Advanced hands-on experience with Radware Web Application Firewall (WAF)
- Advanced hands-on experience with Cloud Access Security Broker (CASB) platforms
- Strong expertise in Firewall Policy Management across enterprise environments
- Strong knowledge of Cloud Infrastructure network architecture, including cloud security groups and network access control lists
- Leadership experience in the development and implementation of technical security architectures at a senior level
- Extensive experience with enterprise security services, identity and database technologies, and network access protocols
- Experience with structured methodologies for the design, development, and implementation of cloud applications
- Extensive experience in systems analysis and design within large, secure solution environments
- Strong knowledge and experience with MITRE frameworks and SSE development and configuration
- Security clearance eligibility at the CRJMC level
Nice-to-Have Skills
- Experience working on Agile project delivery teams, including Backlogs, User Stories, Scrum, and Sprints
- TOGAF Architectural Framework knowledge and experience
- Experience producing Solution Design Framework documentation, including requirements gathering, conceptual design, detailed design, and engineering implementation support
- Previous public sector work experience, particularly within Ontario Government or broader OPS environment
Work Environment
This is a hybrid role requiring the consultant to be on-site at 222 Jarvis St, Toronto, Ontario a minimum of 3 days per week. The engagement requires a CRJMC security clearance. The team operates using Agile delivery practices including Scrum ceremonies and sprint-based delivery cycles.