Job Description
About the Workplace Safety and Insurance Board (WSIB)
We're here to help. When an injury or illness happens on the job, we move quickly to provide wage-loss benefits, medical coverage and support to help people get back to work. Funded by businesses, we also provide no-fault collective liability insurance and access to industry-specific health and safety information. We are one of the largest insurance organizations in North America covering over five million people in more than 300,000 workplaces across Ontario. For more information, visit wsib.ca.
At the WSIB, you'll have the opportunity to:
• explore many career paths and follow your passion
• continuously learn and grow professionally
• be recognized for the great work you do
• participate in programs that support your health and wellbeing
You'll also receive a competitive salary and may be eligible to participate in our health and dental plan.
This role requires the successful applicant to commit to an in-office work arrangement up to 5 days a week beginning in 2027.
Salary Grade: N09 From: $116,000.00 To: $145,000.00
Senior Solution Architect — Cybersecurity and IT Risk
At WSIB, technology helps us serve millions of Ontarians and support recovery from workplace injury and illness. As a Senior Solution Architect, you will apply architecture, cybersecurity, and technology risk expertise to shape enterprise decisions, strengthen critical systems, and design secure, future-ready solutions for a modern public-sector organization.
We are looking for an experienced Senior Solution Architect with hands-on expertise in cybersecurity, IT security, cloud security, and technology risk to design and govern complex enterprise solutions. You will define security expectations, partner across business and technology teams, shape architecture roadmaps, evaluate emerging technologies, and embed security, privacy, risk, compliance, and architecture considerations across delivery. The role connects business strategy, enterprise architecture, technology risk, cloud platforms, and cybersecurity governance, ensuring required security controls are applied across WSIB solutions.
What You'll Be Doing
Lead Secure Enterprise Architecture
- Define and advance security architecture strategy by aligning controls, policies, technologies, business goals, risk tolerance, and enterprise technology direction.
- Design scalable, secure, and resilient enterprise solutions aligned to business priorities, enterprise architecture, and technology strategy, including architecture models and solution blueprints that support cyber resilience, operational resilience, business continuity, and disaster recovery.
- Ensure architecture decisions address security, privacy, compliance, risk management, and operational requirements across the solution lifecycle.
- Lead technology evaluations, proof-of-concepts, and architecture assessments to determine strategic fit, viability, integration considerations, enterprise alignment, risks, vulnerabilities, architectural gaps, and mitigation strategies.
- Support cloud governance, cloud operating models, FinOps principles, and cloud risk management practices.
- Develop, maintain, and promote reference architectures, security roadmaps, patterns, standards, guardrails, guidelines, and controls for enterprise maturity, emerging technologies, heterogeneous cloud platforms, application portfolio consistency, and enterprise technology standards.
Embed Security by Design
- Embed cybersecurity, IT security, and risk management principles into architecture decisions to deliver secure-by-design outcomes.
- Evaluate solution and architecture designs against security strategy, standards, policies, patterns, compliance, regulatory, quality, scalability, and maintainability expectations; identify technology risks, vulnerabilities, architectural gaps, and remediation recommendations.
- Provide practical architecture guidance to help solution architects and delivery teams translate security requirements into detailed solution designs and implementation approaches across cloud security, identity and access management, data protection, application security, and infrastructure security.
- Collaborate with security, vendor, and delivery teams to validate requirements, address design risks, and meet security objectives.
- Ensure security, privacy, responsible AI, and AI risk considerations are incorporated throughout the solution lifecycle, including risks related to data leakage, model misuse, model poisoning, prompt injection, privacy concerns, and third-party AI service exposure.
Guide Secure Adoption of Emerging Technologies
- Evaluate AI, Agentic AI, Generative AI, Machine Learning, Automation, Quantum Computing, and other emerging technologies from architecture, security, privacy, and risk perspectives; recommend adoption options; and establish standards, guardrails, guidelines, and security expectations for responsible, secure use.
- Align AI adoption with responsible use, security, privacy, enterprise architecture, and business, delivery, data, and security stakeholder needs.
- Monitor emerging technology trends and assess their impact on enterprise architecture, cybersecurity posture, technology risk, business outcomes, technology investment, modernization, and enterprise roadmap decisions.
Strengthen Architecture Governance
- Lead architecture governance, including review forums, solution checkpoints, and decision processes across initiatives, programs, and portfolios.
- Assess solution alignment with approved strategies, principles, standards, patterns, guardrails, guidelines, controls, and reference architectures; prepare and review governance artifacts such as architecture assessments, decision records, solution options, risk summaries, exception requests, and remediation plans.
- Manage governance decisions, including security deviations, exceptions, remediation actions, and risk acceptances, while presenting recommendations, options, trade-offs, and decision points to governance committees and senior leadership.
- Maintain traceability between governance decisions, architecture conditions, delivery plans, and implementation outcomes.
Partner Across Business and Technology
- Build trusted stakeholder relationships to understand priorities, shape architecture direction, and support informed decisions.
- Develop business-aligned technology roadmaps that support priorities, modernization, and reduce technology and security risk.
- Provide strategic guidance on technology strategy, architecture direction, modernization, emerging technologies, cybersecurity trends, evolving threats, regulatory developments, and technology risk.
- Partner with security, privacy, data governance, and enterprise architecture teams to advance modernization and align with standards and governance expectations.
Provide Architecture Leadership
- Lead architecture workstreams for large-scale transformation across programs and portfolios.
- Facilitate architecture workshops and design sessions to align stakeholders on solution direction, trade-offs, and implementation considerations.
- Promote architecture best practices, secure development principles, continuous improvement, knowledge sharing, advanced methods, and consistent secure architecture practices through architecture communities of practice.
- Provide architecture input to RFP evaluations, business cases, technology assessments, and strategic planning.
- Mentor architects and technical teams on secure architecture, emerging technologies, and risk-based decision-making.
What You Bring
Required Qualifications
- 7+ years of senior-level solution, enterprise, or security architecture experience designing secure, cloud-enabled enterprise solutions in complex, heterogeneous, or regulated environments.
- Experience applying cybersecurity, technology risk, and risk-based decision-making practices to balance business value, security, compliance, operational resilience, and delivery outcomes.
- Experience with cloud platforms such as Microsoft Azure, AWS, or Google Cloud Platform, including cloud security, governance, and risk considerations.
- Experience leading architecture governance, solution reviews, and executive-level discussions to support decisions, exceptions, remediation, and risk acceptance.
- Experience evaluating emerging technologies and translating security, privacy, and risk considerations into architecture standards, patterns, guardrails, and solution designs.
- Experience with enterprise architecture methods and practices, including TOGAF or similar frameworks.
Cybersecurity, Technology Risk, and Framework Expertise
Candidates should bring practical experience applying cybersecurity, cloud security, application security, DevSecOps, SSDLC, privacy, technology risk, and governance practices to enterprise architecture and solution delivery. Experience with frameworks and approaches such as NIST CSF, NIST AI RMF, ISO 27001, CIS Controls, COBIT, and Zero Trust Architecture is expected.
Preferred Certifications
- Relevant security, architecture, risk, or cloud certifications such as CISSP, CISM, CRISC, CCSP, TOGAF, Azure, AWS, or Google Cloud certifications are considered assets.
Why Join WSIB
If you are passionate about secure architecture, technology strategy, cloud transformation, and enterprise-scale problem solving, we invite you to help shape WSIB's future technology direction while advancing security, risk management, and innovation.
Our commitment to equity, diversity and inclusion
We respect and value the diversity of our people. We strive to create an environment where employees can be themselves and where our differences are celebrated. We value and celebrate diversity and are committed to creating inclusive experiences for both our employees and prospective employees. We invite all interested individuals to apply. If you require accommodations in order to apply to this position please contact [email protected]. If you are invited to participate in the interview or assessment process, you can advise our Recruiter of your accommodation needs at that time. Please visit our EDI Vision to learn more about what actions WSIB are taking to advance our commitment to equity, diversity and inclusion and to support all employees participating and contributing to their full potential
Disclosing conflicts of interest
As public servants, employees at the WSIB have a responsibility to act in an ethical way at all times to create a respectful workplace and maintain public trust. Job applicants are required to disclose any circumstance that could result in a real, potential or perceived conflict of interest. A conflict of interest is any situation where your private interests may impair or be perceived to impair the decisions you make in your official capacity. This may include: political activity, directorship, other outside employment and certain personal relationships (e.g. with current WSIB employees, customers and/or stakeholders). If you have any questions about conflict of interest obligations and/or how to make a disclosure, please contact the Talent Acquisition Centre at [email protected].
Privacy information
We collect personal information from your resume, application, cover letter and references under the authority of the Workplace Safety and Insurance Act, 1997. The Talent Acquisition Centre and WSIB hiring parties will used this information to assess/validate your qualifications, determine if you meet the requirements of vacant positions and/or gather information relevant for recruitment purposes. If you have questions or concerns regarding the collection and use of your personal information, please contact the WSIB's Privacy Office at [email protected]. The Privacy Office cannot provide information about the status of your application.
As a precondition of employment, the WSIB requires that prospective candidates undergo a criminal records name check any time before or after they are hired.
To apply for this position, please submit your application by the closing date.
Application Contact Information
| Company Name: | WSIB |
| Company Website: | https://www.wsib.ca/en/careers |
| Application URL: | Click here to apply online |

