Staff Product Security Architect

Posted 1 day ago

This is a fully remote position, open to applicants in United States, +3 more countries.

📋 Description

• Collaborate with engineering and product leadership throughout GitLab to foresee security challenges.

• Spearhead security architecture and design initiatives while guiding cross-functional delivery teams.

• Identify, evaluate, and prioritize systemic security vulnerabilities.

• Serve as the Security Owner for high-priority items in the Product Security Risk Register and jointly execute remediation efforts.

• Formalize security decisions into reusable guidelines, standards, design patterns, capabilities, and threat models applicable to developer and AI coding workflows.

• Create proofs of concept and prototypes to facilitate engineering teams' progress.

• Perform security architecture reviews on significant or strategic projects.

• Collaborate with Application Security to ensure comprehensive review coverage is prioritized.

• Threat model both new and existing systems while establishing reusable threat-modeling frameworks.

• Partner with Security Research to investigate unknown architectural vulnerabilities.

• Predict emerging security issues and suggest architectural solutions.

• Guide and mentor security engineers while representing security architecture to engineering teams.


⛳️ Requirements

• Extensive knowledge of application security architecture, including authentication and authorization frameworks, privilege escalation, multi-tenant isolation, and trust boundary assessments.

• Experience in securing distributed systems, focusing on service-to-service authentication, secrets management, and security protocols across process boundaries.

• Proficient understanding of software supply chain security: build and release integrity, artifact provenance, and dependency risks.

• Proven history of proactive architectural initiatives that identify risks preemptively and design preventative measures.

• Capacity to establish trusted relationships with engineering leadership and influence technical strategy through expertise.

• Experience in defining security standards or patterns adopted by development teams.

• Ability to operate strategically while remaining hands-on, which includes reading unfamiliar code, developing prototypes, and making contributions.

• Strong written communication skills with the capability to present security arguments to engineering audiences.

• Insight into creating and delivering security guidance for AI coding tools.

• Ability to integrate AI into everyday workflows.


🏝️ Benefits

• Comprehensive benefits to enhance your health, finances, and overall well-being.

• Flexible Paid Time Off.

• Team Member Resource Groups.

• Equity Compensation & Employee Stock Purchase Plan.

• Growth and Development Fund.

• Parental Leave.

People also viewed

Sony Interactive Entertainment13 hours ago

Senior Security AI Risk Analyst

US flagCalifornia OnlyFull-timeCybersecurity / Security Engineer$167.5k – $251.3k/year
ApplyView job
Squads13 hours ago

Security Engineer

North AmericaFull-timeCybersecurity / Security Engineer$175k – $220k/year
ApplyView job
Neo4j13 hours ago

Senior Director, Product, Security and Privacy

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$260k – $300k/year
ApplyView job
PingWind Inc. (SDVOSB)14 hours ago

Cloud Security Architect – Engineer

US flagAlabama, +1 more stateFull-timeCybersecurity / Security Engineer
ApplyView job
CSCI Consulting14 hours ago

SAP S/4HANA Defense & Security Functional Lead

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
Strategic Systems International15 hours ago

AI Security Engineer – AI, Agentic Security

MX flagMexico, +4 more countriesFreelanceCybersecurity / Security Engineer
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers