Base Career helps you apply smarter for this job.
Key skills for this role
We are currently seeking a skilled Information Technology (IT) Security Architect at our facility located in Brooklyn, Queens County, NS to perform both technical and administrative tasks to ensure functionality and efficiency of our computer and telecommunications systems.
Develop and execute the company's IT roadmap in alignment with operational priorities, business goals, regulatory compliance requirements, and enterprise cybersecurity strategy.
Lead enterprise-wide cybersecurity architecture planning for on-premise and cloud-based infrastructure (Microsoft Azure and hybrid environments), ensuring secure system design aligned with ISO 27001, NIST, and GMP/EU-GMP standards.
Plan and design scalable, secure IT infrastructures for future facilities, lab expansions, or process upgrades.
Provide timely and strategic input to executive leadership regarding current system performance, cybersecurity posture, opportunities for consolidation, and enterprise risk exposure.
Prepare executive-level security and risk reports outlining vulnerabilities, mitigation strategies, compliance status, and long-term resilience planning.
Conduct security architecture reviews for new applications and infrastructure initiatives to ensure compliance with corporate, regulatory, and industry standards.
Collaborate with all departments to align IT and security initiatives with company-wide objectives, including cost control, automation, regulatory readiness, and operational efficiency.
Lead and maintain enterprise platforms including:
NetSuite CRM – Canada-specific CRM for sales, customer relations, and business development.
Skip the repetitive application forms
Install the Base Career Chrome Extension and autofill job applications across major job boards with your profile.
Trusted by over 500,000 job seekers on Base Career
Ample Organics – Seed-to-sale software for traceability and regulatory compliance.
ADP – Attendance and HR management platform.
Isolocity – Cloud-based Quality Management System (QMS) for document control, training, CAPA, and audit trails.
Hippo/Eptura – Maintenance Management Systems for preventive maintenance and equipment tracking.
Monday.com – Work OS for project management and cross-departmental workflows.
Evaluate, recommend, and oversee the future implementation of an Inventory Management System integrated with ERP and compliance platforms.
Perform security assessments and architecture validation for all newly implemented systems.
Apply encryption standards (TLS 1.2+, AES-256) and manage Public Key Infrastructure (PKI) to ensure secure data transmission and storage across enterprise platforms.
Develop and enforce Identity and Access Management (IAM) frameworks using Active Directory, Azure AD, and Multi-Factor Authentication (MFA).
Manage on-premise and cloud-based infrastructure, virtual environments, endpoints, and hybrid Azure deployments across multiple sites.
Design and implement network security controls including next-generation firewalls (Fortinet / Palo Alto), IDS/IPS systems, VPN configurations, and zero-trust access models.
Configure and manage SIEM platforms such as Microsoft Sentinel or Splunk for real-time security monitoring and anomaly detection.
Conduct threat modeling, vulnerability assessments, and risk analysis using tools such as Nessus, Qualys, and Microsoft Defender for Endpoint.
Administer and monitor Fortinet-based IDS/IDP systems for network intrusion detection and prevention.
Lead incident response investigations including malware analysis, forensic review, root-cause analysis, and implementation of corrective security measures.
Develop, document, and test cybersecurity policies, disaster recovery procedures, business continuity plans, and incident response playbooks.
Ensure cybersecurity protections are enforced across Microsoft 365, Datto, Azure, and other cloud services.
Oversee biometric access control systems, CCTV, and physical security technologies in coordination with Facilities and Security teams.
Manage VoIP communications (Telus) and dedicated internet connectivity (Bell).
Proactively notify management of downtime, security incidents, or vulnerabilities, providing mitigation strategies.
Develop and maintain IT and cybersecurity-related SOPs aligned with GMP, EU-GMP, ISO 27001, NIST, and Health Canada compliance frameworks.
Support internal and external audits by Health Canada and other regulatory bodies, ensuring data integrity, audit readiness, and documented security controls.
Act as liaison to Canadian Radio Spectrum Management for licensing and communications compliance.
Ensure all third-party systems and integrations meet internal IT governance and regulatory security standards.
Deliver cybersecurity awareness training (phishing prevention, data protection, access control best practices).
Provide technical leadership to IT teams, promoting secure coding practices, system hardening, and vulnerability management.
Train employees on proper usage of ERP, seed-to-sale, and collaboration platforms.
Promote a culture of cybersecurity accountability and digital maturity organization wide.
Support Business Development Managers in optimizing marketing and social media operations through secure digital tools and automation platforms.
Identify and implement analytics and digital tools to enhance brand presence and ROI.
Coordinate with vendors and internal teams for structured cabling, hardware deployment, and infrastructure upgrades.
Build and maintain strong relationships with technology providers including IBM, Microsoft, Adobe, Datto, and other vendors.
Oversee SLAs, renewals, licensing, hardware procurement, and vendor risk assessments.
Ensure third-party systems comply with enterprise cybersecurity standards and regulatory requirements.
ITIL, PMP, or TOGAF (Enterprise Architecture / Project Governance)
CISM, CISSP, CEH (Cybersecurity Leadership)
ISO 27001 Lead Implementer / Lead Auditor
Microsoft Azure Security Engineer (AZ-500)
AWS, Azure, or Google Cloud security certifications
Familiarity with Ample Organics, NetSuite, or cannabis regulatory ERP systems is a strong asset
Location: Brooklyn, NS (Required)
Compensation: To be determined based on skills and experience
Status and Hours: Permanent,40 hrs per week to start; hours may increase as ongoing needs are assessed
Successful applicants must provide satisfactory background and reference checks.
Aqualitas welcomes and encourages diversity. Should you require accommodation in any aspect of our selection process, please let us know.
We appreciate the interest of all candidates; however, we will only be contacting those that best fit our requirements. Resumes will be kept for consideration for six months.
Cultivates and processes certified organic medical cannabis products.
Visit company websiteJobs and hiring trendsFull-time
Senior · 8+ years experience
Onsite
Apply faster on company sites with our extension.