New

Senior Application Security Architect, Enterprise Technology

Toronto, Ontario, Canada

ABOUT ONEX:

Onex is an investor and asset manager that invests capital on behalf of Onex shareholders and clients across the globe. Formed in 1984, we have a long track record of creating value for our clients and shareholders. Onex became a public company in 1987 and is listed on the Toronto Stock Exchange under the symbol ONEX. Onex’ two primary businesses are Private Equity and Credit. In Private Equity, we raise funds from third-party investors and invest them, along with Onex’ own investing capital, through the funds of our private equity platforms: Onex Partners and ONCAP. Similarly, in Credit, we raise and invest capital across several private credit, liquid credit and public equity strategies.

Our investors include a broad range of global clients, including public and private pension plans, sovereign wealth funds, insurance companies, family offices and high net worth individuals. Onex has $56 billion in assets under management, of which $9.4 billion is Onex’ own investing capital. We generate value for our shareholders through two segments: Investing and Asset Management.

To explore more opportunities at Onex, visit: https://job-boards.greenhouse.io/onexgeneral

The Opportunity:

We are seeking an experienced security professional to join our Enterprise Technology group as a Senior Application Security Architect, based in Toronto. Reporting to the Manager, IT Cloud Services, this role will strengthen how Onex assesses and secures internally developed, vendor-integrated, open-source and emerging technology solutions. The successful candidate will lead practical application security architecture reviews, threat modelling and secure software development lifecycle standards; perform targeted reviews of security-critical code and controls; and partner with technology and business teams to move solutions safely into production. The role has a strong cloud application security focus, with exposure to AI/LLM platforms and other emerging technologies, and requires someone who can balance technical depth, sound judgement and collaborative delivery.

Key Responsibilities:

  • Define and maintain practical secure software development lifecycle (SDLC), application security architecture and production-readiness standards.
  • Establish risk-based review criteria and perform security reviews of internet-facing, sensitive-data, AI-enabled and other high-risk applications and platforms.
  • Conduct threat modelling and architecture assessments covering applications, APIs, data flows, identity, cloud services, third-party dependencies and deployment topology.
  • Perform targeted source-code reviews of security-critical areas, including authentication, authorization, input handling, data access, secrets, session management and integrations.
  • Assess controls related to identity, API security, encryption, secrets management, network exposure and segmentation, logging, monitoring and data protection.
  • Document and prioritize material risks and remediation; validate that required controls are addressed, maintain review evidence and route material exceptions through formal risk acceptance.
  • Develop reusable secure reference architectures, design patterns, checklists and guidance that help teams deliver secure and supportable solutions.
  • Define and support appropriate automated security controls within CI/CD pipelines, including code, dependency, secret, container and infrastructure-as-code scanning, in partnership with the teams that own implementation and operation.
  • Assess open-source and third-party components for provenance, known vulnerabilities, patching practices and supportability, and identify licensing concerns for review with Legal or Procurement.
  • Apply established application, cloud, identity, data and software supply-chain security principles to AI/LLM applications, self-hosted models, AI coding tools and other emerging technologies.
  • Partner with cybersecurity, cloud services, infrastructure, analytics, development teams and business stakeholders to provide practical guidance and support remediation while maintaining clear ownership within accountable teams.
  • Support selected proofs of concept, validation testing and post-deployment verification where hands-on technical involvement adds value.

Candidate Profile:

  • 7+ years of relevant experience across application security, software/cloud engineering, DevSecOps or cybersecurity, with significant application security or secure architecture experience.
  • Proven experience with security architecture reviews, threat modelling and secure design assessments for modern applications, APIs and cloud services.
  • Strong knowledge of secure SDLC and application security controls, including identity and access, API security, secrets management, encryption and data protection.
  • Strong coding and code-review skills in at least one modern language, with the ability to assess unfamiliar codebases. Experience with Python, C#/.NET, JavaScript/TypeScript, Java or SQL is particularly relevant.
  • Experience securing cloud applications across identity, networking, APIs, containers, managed services and ingress.
  • Practical knowledge of DevSecOps and application security testing, including CI/CD controls, SAST, DAST, SCA, secrets scanning and container security.
  • Strong judgement and communication skills, with the ability to translate security risks into practical recommendations and influence stakeholders without direct authority.

Preferred Qualifications:

  • Experience with Microsoft Azure and Entra ID, including identity, secret management, networking and application hosting.
  • Experience assessing AI/LLM applications, self-hosted models or AI-assisted development; familiarity with Ollama, MCP, RAG, AI agents or similar technologies is an asset.
  • Experience assessing open-source software, third-party dependencies and software supply-chain risk, including vulnerability and patch management.
  • Financial services or other regulated-industry experience, and/or relevant application security or cloud certifications.

Additional information:

The expected base salary range for this position is C$115,000-130,000 on an annualized basis.

All-in compensation may vary based on several factors, such as relative experience, education level attained, professional certifications, geographical location, etc. to account for local market conditions.

This position is for a current vacancy.

#LI-DNI

Our Team & Commitment:

Onex is led by the firm’s CEO, Bobby Le Blanc, as well as experienced leaders at each of our businesses and approximately 340 employees across offices in Toronto, New York, New Jersey and London. Our culture is guided by our strong commitment to accountability, intellectual honesty and respect for all our partners and stakeholders. Onex was formed on principles of entrepreneurialism and responsible investing and our team is united in recognizing the value of collaboration, diversity of perspective and background, and an inclusive environment. Our team is a critical factor in our success, and attracting and retaining the best people is an important competitive advantage. Also important to our long-term success is the alignment of interests between the Onex management team, the Onex Board of Directors, shareholders and our limited partners. Many members of our management team and Board of Directors own Onex shares and invest meaningfully in our funds. We believe this practice creates stronger alignment with both our limited partners and shareholders.

Diversity Equity & Inclusion:

Onex recognizes that a diverse team and inclusive environment is a competitive advantage and contributes to our innovation and success as an investor and asset manager. We believe the competitive advantage offered by a multitude of perspectives enhances problem-solving and decision making and ultimately, better performance for Onex and its shareholders, investors, clients, and stakeholders, as well as the communities we serve. Onex’s commitment to diversity and inclusion includes increasing our focus on attracting and retaining employees from diverse backgrounds, creating additional awareness of diversity issues and benefits, fostering and inspiring a more supportive environment where inclusivity is expected and prioritized, and embedding accountability for diversity throughout the firm.

Onex’s Employee Resource Group (ERG) Leadership Forum is chaired by our CHRO, with participation by our CEO and ERG Team Leaders. The Forum provides a structured opportunity for ERG coordination, employee feedback, and direct dialogue with senior leadership, helping ensure that the experiences and insights of Onex’s ERG communities continue to inform broader diversity and inclusion strategy and decision-making.

Our firm is an equal opportunity employer. We are committed to providing equal employment opportunities regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity, veteran status, or any other characteristic protected by applicable law. If you require accommodations at any stage of the recruitment process, please contact careers@onex.com.

Applicants must be legally entitled to work in the country where the role is based, or eligible for any necessary work authorization or permit.

Sustainability:

Onex is committed to delivering value for all our stakeholders through responsible governance practices and by integrating sustainability-related risks and opportunities into our investment process. Onex’ approach to sustainability follows our Sustainability Policy and Climate Strategy, which is led by the Head of Sustainability and overseen by Onex’ CFO, with support from the Sustainability Committee, which includes members from each business platform and key supporting functions.

To remain aligned with emerging best practices, we participate in several industry initiatives, including the ESG Data Convergence Initiative (“EDCI”), Initiative Climat International (“iCI”), the Principles for Responsible Investment (“PRI”), and the IFRS Sustainability Alliance, among others. Further information on Onex’ Sustainability Policy and Climate Strategy can be found on our website. www.onex.com.

Apply for this job

*

indicates a required field

Phone
Resume/CV*

Accepted file types: pdf, doc, docx, txt, rtf


Employment

Select...
Select...

Education

Select...
Select...
Select...