
Staff Product Security Architect
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in United States, +3 more countries.
• Collaborate with engineering and product leadership throughout GitLab to foresee security challenges.
• Spearhead security architecture and design initiatives while guiding cross-functional delivery teams.
• Identify, evaluate, and prioritize systemic security vulnerabilities.
• Serve as the Security Owner for high-priority items in the Product Security Risk Register and jointly execute remediation efforts.
• Formalize security decisions into reusable guidelines, standards, design patterns, capabilities, and threat models applicable to developer and AI coding workflows.
• Create proofs of concept and prototypes to facilitate engineering teams' progress.
• Perform security architecture reviews on significant or strategic projects.
• Collaborate with Application Security to ensure comprehensive review coverage is prioritized.
• Threat model both new and existing systems while establishing reusable threat-modeling frameworks.
• Partner with Security Research to investigate unknown architectural vulnerabilities.
• Predict emerging security issues and suggest architectural solutions.
• Guide and mentor security engineers while representing security architecture to engineering teams.
• Extensive knowledge of application security architecture, including authentication and authorization frameworks, privilege escalation, multi-tenant isolation, and trust boundary assessments.
• Experience in securing distributed systems, focusing on service-to-service authentication, secrets management, and security protocols across process boundaries.
• Proficient understanding of software supply chain security: build and release integrity, artifact provenance, and dependency risks.
• Proven history of proactive architectural initiatives that identify risks preemptively and design preventative measures.
• Capacity to establish trusted relationships with engineering leadership and influence technical strategy through expertise.
• Experience in defining security standards or patterns adopted by development teams.
• Ability to operate strategically while remaining hands-on, which includes reading unfamiliar code, developing prototypes, and making contributions.
• Strong written communication skills with the capability to present security arguments to engineering audiences.
• Insight into creating and delivering security guidance for AI coding tools.
• Ability to integrate AI into everyday workflows.
• Comprehensive benefits to enhance your health, finances, and overall well-being.
• Flexible Paid Time Off.
• Team Member Resource Groups.
• Equity Compensation & Employee Stock Purchase Plan.
• Growth and Development Fund.
• Parental Leave.
Sony Interactive Entertainment
Squads
Neo4j
PingWind Inc. (SDVOSB)
Get handpicked remote jobs straight to your inbox weekly.