Director, Security Architecture & Threat Modeling
Company Name
**
Toronto, Canada
Basic
Posted 3 days ago
At Varicent, we’re not just transforming the Sales Performance Management (SPM) market—we’re redefining how organizations achieve revenue success. Our cutting-edge SaaS solutions empower revenue leaders globally to design smarter go-to-market strategies, maximize seller performance, and unlock untapped potential. Varicent stands at the forefront of innovation, celebrated as a market leader in the 2025 Forrester Wave Report for SPM , 2023 Ventana Research Revenue Performance Management (RPM) Value Index , Gartner Peer Insights , 2024 Gartner SPM Market Guide , and G2. Our solutions are trusted by a diverse range of global industry leaders like T-Mobile, ServiceNow, Wawanesa Bank, Shaw Industries, Moody's, Stryker and hundreds more. Here’s why you’ll thrive at Varicent:
Innovate with Purpose: Build impactful solutions for customers worldwide.
Join Excellence: Work in a diverse, collaborative, and innovative team.
Shape the Future: Lead in redefining revenue optimization.
Grow Together: Unlock your potential in a supportive environment.
Join us at Varicent—where your talent and ambition meet limitless opportunities for success! About the Role
We're looking for a hands-on and strategic Director, Application Security Architecture & Threat Modeling to help shape secure-by-design principles across our SaaS platforms, cloud environments, and AI-enabled products.
In this role, you'll partner closely with Engineering, Product, Cloud Operations, Architecture, AI, and Security teams to embed security early in the development lifecycle. You'll lead application security architecture, threat modeling, secure design reviews, and AI security initiatives while helping teams build scalable, resilient, and secure solutions.
This is a highly visible leadership role reporting directly to the VP & Chief Information Security Officer.
What You'll Do
Lead Security Architecture & Secure-by-Design
Define and execute the Security Architecture and Security-by-Design strategy and roadmap.
Establish secure reference architectures, design standards, and security patterns for cloud-native and AI-enabled solutions.
Partner with Engineering and Product teams to embed security into development workflows and system design decisions.
Drive adoption of secure-by-design best practices by embedding security requirements in epics, user stories and the AI SLDC.
Drive Threat Modeling & Risk Analysis
Produce actionable threat modeling artifacts including data flow diagrams, trust boundary analysis, abuse cases, attack paths, security requirements, technical specifications, design risks, remediation actions, and residual risk documentation.
Analyze recurring vulnerabilities, penetration test results, incident learnings, and security assessment findings to identify systemic design flaws and improve secure architecture standards.
Lead threat modeling activities across critical applications, platforms, and AI-enabled systems.
Identify architectural risks, attack paths, abuse cases, and trust boundary concerns.
Translate threats into actionable security requirements and remediation guidance.
Build reusable threat models, security patterns, and design libraries that scale across engineering teams.
Partner with Engineering Teams
Guide teams on secure design principles, risk-based decision making, and security tradeoffs.
Review distributed systems, microservices, cloud-native architectures, APIs, mobile applications, and identity solutions.
Support remediation efforts and validate architectural fixes for security findings.
Secure Cloud & AI Platforms
Conduct architecture reviews across AWS, Azure, and IBM Cloud environments.
Assess containerized, Kubernetes, serverless, and AI-enabled architectures.
Define cloud security guardrails, governance models, and secure deployment patterns.
Partner with AI teams to evaluate security risks within LLM-enabled products and agentic workflows.
Influence Across the Organization
Collaborate with Security, Engineering, Architecture, Legal, Compliance, and Product stakeholders.
Develop security standards, training, and architecture guidance.
Communicate architectural risk and security recommendations to technical and executive audiences.
What You'll Bring
10+ years of Information Security experience.
3+ years of Application Security Architecture and Threat Modeling experience.
3–5 years of Software Development or Software Engineering experience.
Strong understanding of secure application design, cloud security, and modern software architectures.
Experience with DevSecOps, secure SDLC practices, and AI-enabled development environments.
Expertise in threat modeling methodologies such as STRIDE, CAPEC, and MITRE ATT&CK.
Experience securing web, API, mobile, cloud-native, and AI-enabled applications.
Knowledge of AWS, Azure, or IBM Cloud security architectures.
Strong communication skills with the ability to influence stakeholders at all levels.
Certifications such as CISSP, CSSLP, ISSAP, CISM, CRISC, OSCP, or cloud security certifications are considered an asset.
What Success Looks Like
First 90 Days
Assess current architecture, development processes, and security maturity.
Build relationships across engineering, architecture, cloud, and security teams.
Identify high-priority risks and opportunities to improve secure-by-design adoption.
Establish a roadmap for threat modeling and AI SDLC security initiatives.
6+ Months
Standardize threat modeling and architecture review processes.
Embed security requirements into engineering and AI development workflows.
Expand automated security architecture and design validation capabilities.
Long-Term
Scale secure-by-design practices across all products and platforms.
Mature architecture risk management and AI security governance.
Enable measurable reductions in security risk through proactive design and engineering practices.
For this role, the estimated annual base salary range is between $138,200.00 - $181,400.00 (CAD). In addition to base salary, our compensation package may include bonuses, commissions for eligible sales roles, and a comprehensive benefits package. The actual base salary will vary based on factors including individual qualifications and market data, as objectively assessed during the interview process.
This posting is for a new vacancy.
This hiring process utilizes artificial intelligence tools to assist in candidate screening and assessment. Our AI tools are designed to complement — not replace — human decision-making.
Overview of Benefits:
Health & Wellness — Comprehensive medical, dental, and vision coverage tailored to your local needs
Time Off — PTO and public holidays to rest, recharge, and do what matters most
Volunteer Days — Dedicated time to give back and support the communities that matter to you
Ignite Days — Dedicated learning days to support continuous growth, skill development, and professional learning
Financial — Compensation that reflects your market and your value
Retirement — Retirement plans designed to help you build long-term financial security
Tuition Assistance — Invest in your growth with support for continuing education and professional development
Flexibility — Work where you thrive, with remote and hybrid options available across most regions
Varicent is committed to creating a diverse environment and is proud to be an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability, age, or veteran status. If you require accommodation at any time during the recruitment process please email accomodations@varicent.com
Varicent is also committed to compliance with all fair employment practices regarding citizenship and immigration status. By applying for a position at Varicent and/or by using this portal, you declare and confirm that you have read and agree to our Job Applicant Privacy Notice and that the information provided by you as part of your application is true and complete and includes no misrepresentation or material omission of fact
Director, Offensive Security
Company Name
**
Toronto, Canada
Basic
Posted 3 days ago
At Varicent, we’re not just transforming the Sales Performance Management (SPM) market—we’re redefining how organizations achieve revenue success. Our cutting-edge SaaS solutions empower revenue leaders globally to design smarter go-to-market strategies, maximize seller performance, and unlock untapped potential. Varicent stands at the forefront of innovation, celebrated as a market leader in the 2025 Forrester Wave Report for SPM , 2023 Ventana Research Revenue Performance Management (RPM) Value Index , Gartner Peer Insights , 2024 Gartner SPM Market Guide , and G2. Our solutions are trusted by a diverse range of global industry leaders like T-Mobile, ServiceNow, Wawanesa Bank, Shaw Industries, Moody's, Stryker and hundreds more. Here’s why you’ll thrive at Varicent:
Innovate with Purpose: Build impactful solutions for customers worldwide.
Join Excellence: Work in a diverse, collaborative, and innovative team.
Shape the Future: Lead in redefining revenue optimization.
Grow Together: Unlock your potential in a supportive environment.
Join us at Varicent—where your talent and ambition meet limitless opportunities for success! About the Role
We're looking for a hands-on Director of Offensive Security to lead and evolve our offensive security program across applications, cloud environments, enterprise systems, and AI-enabled products.
This role combines technical expertise, strategic leadership, and cross-functional partnership to help identify, prioritize, and reduce security risk at scale. You'll lead offensive security initiatives including penetration testing, red teaming, AI security validation, vulnerability management, and bug bounty programs while partnering closely with Engineering, Product, Security, Compliance, and Legal teams.
What You'll Do
Lead the Offensive Security Program
Define and execute the offensive security strategy and roadmap.
Lead internal and external teams across penetration testing, red teaming, AI security testing, and vulnerability research.
Establish standards, reporting, and metrics that drive measurable risk reduction.
Drive Security Testing & Validation
Oversee web, API, mobile, cloud, and AI-enabled security testing.
Lead red team operations, adversary simulations, and purple team exercises.
Manage external penetration testing engagements and testing vendors.
Mature attack surface management and continuous security validation programs.
Secure AI-Enabled Products
Design and execute AI red teaming activities for LLM-enabled products and agentic workflows.
Partner with AI and engineering teams to integrate security throughout the AI development lifecycle.
Build scalable approaches for AI security testing, validation, and risk assessment.
Improve Vulnerability Management
Drive vulnerability triage, prioritization, remediation, and retesting.
Partner with engineering teams to implement risk-based remediation practices.
Mature bug bounty and vulnerability disclosure programs.
Influence Across the Business
Partner with Engineering, Product, Security Operations, Compliance, and Legal teams.
Communicate security risks, trends, and recommendations to senior leadership.
Help shape the future of AI-enabled offensive security across the organization.
What You'll Bring
10+ years of Information Security experience, including 5+ years in Offensive Security and 3+ years in Development or Engineering.
Experience leading offensive security programs in SaaS and cloud environments.
Hands-on expertise in penetration testing, red teaming, vulnerability management, and security testing of AI-enabled products.
Strong understanding of application security, cloud security, attack surface management, and secure development practices.
Experience working with modern cloud environments, APIs, web applications, containers, and AI/LLM technologies.
Ability to translate technical findings into business risk and influence stakeholders at all levels.
Relevant certifications such as OSCP, OSWE, GXPN, GPEN, CISSP, CCSP, or cloud security certifications are considered an asset.
What Success Looks Like
First 90 Days
Assess the current offensive security landscape and identify key opportunities for improvement.
Build relationships across engineering, security, and business teams.
Establish priorities and define a roadmap for continuous security validation.
6+ Months
Scale AI-enabled offensive security capabilities.
Improve vulnerability management effectiveness and remediation outcomes.
Deliver measurable reductions in organizational security risk.
Long-term (7+ months): Mature, Measure & Reduce Risk
Scale autonomous vulnerability management across critical assets and environments.
Mature AI-enabled red team capabilities and continuous threat-informed security validation.
Drive measurable reductions in organizational risk through AI-enabled offensive security capabilities.
For this role, the estimated annual base salary range is between $138,200.00 - $181,400.00 (CAD). In addition to base salary, our compensation package may include bonuses, commissions for eligible sales roles, and a comprehensive benefits package. The actual base salary will vary based on factors including individual qualifications and market data, as objectively assessed during the interview process.
This posting is for a new vacancy.
This hiring process utilizes artificial intelligence tools to assist in candidate screening and assessment. Our AI tools are designed to complement — not replace — human decision-making.
Overview of Benefits:
Health & Wellness — Comprehensive medical, dental, and vision coverage tailored to your local needs
Time Off — PTO and public holidays to rest, recharge, and do what matters most
Volunteer Days — Dedicated time to give back and support the communities that matter to you
Ignite Days — Dedicated learning days to support continuous growth, skill development, and professional learning
Financial — Compensation that reflects your market and your value
Retirement — Retirement plans designed to help you build long-term financial security
Tuition Assistance — Invest in your growth with support for continuing education and professional development
Flexibility — Work where you thrive, with remote and hybrid options available across most regions
Varicent is committed to creating a diverse environment and is proud to be an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability, age, or veteran status. If you require accommodation at any time during the recruitment process please email accomodations@varicent.com
Varicent is also committed to compliance with all fair employment practices regarding citizenship and immigration status. By applying for a position at Varicent and/or by using this portal, you declare and confirm that you have read and agree to our Job Applicant Privacy Notice and that the information provided by you as part of your application is true and complete and includes no misrepresentation or material omission of fact