Director, Product Security Architect

Varicent

Toronto

On-site

CAD 138,000 - 181,000

Full time

42 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Health coverage
PTO & holidays
Volunteer days
Learning days
Competitive pay
Retirement plans
Tuition assistance
Remote & hybrid options

Job summary

Varicent is seeking a highly technical Director, Product Security Architect to shape secure-by-design principles across our SaaS products, cloud platforms, and AI-enabled offerings. This role sits with Product and Engineering, focusing on identifying and eliminating architectural risk before it reaches production.

You'll collaborate with Engineering, Product, Cloud Operations, Architecture, AI, and Security teams to embed security early in the software development lifecycle, lead threat

Qualifications

  • 10+ years of Information Security experience, with hands-on Product/ Application/ Security Architecture.
  • 3+ years of Application Security Architecture and Threat Modeling experience.
  • 3–5 years of Software Development or Software Engineering experience.
  • Strong understanding of secure application design and cloud security.
  • Experience with DevSecOps and AI-enabled development environments.
  • Expertise in threat modeling methodologies such as STRIDE, CAPEC, MITRE ATT&CK.
  • Experience securing web, API, mobile, cloud-native, and AI-enabled apps.
  • Certifications such as ISC2 ISSAP, CISSP, CSSLP, OSCP are assets.

Responsibilities

  • Define and execute the Product Security Architecture strategy.
  • Establish secure reference architectures and patterns for cloud-native and AI-enabled solutions.
  • Partner with Engineering and Product teams to embed security into development workflows and design decisions.
  • Drive secure-by-design adoption by embedding security requirements in epics, user stories, and the AI SDLC.
  • Produce threat modeling artifacts including data flow diagrams, abuse cases, attack paths, security requirements and remediation actions.
  • Analyze vulnerabilities and security assessments to identify systemic design flaws and improve standards.
  • Lead threat modeling activities across critical applications, platforms, and AI-enabled systems.
  • Translate threats into actionable security requirements and remediation guidance with engineering teams.
  • Build reusable threat models, security patterns, and design libraries.

Skills

Security architecture
Threat modeling
Product security
Application security
DevSecOps
Cloud security
Security governance
Communication skills
AWS/Azure/IBM Cloud

Tools

Kubernetes
CI/CD tooling
Threat modeling tools

Job description

At Varicent, we’re not just transforming the Sales Performance Management (SPM) market—we’re redefining how organizations achieve revenue success. Our cutting-edge SaaS solutions empower revenue leaders globally to design smarter go-to-market strategies, maximize seller performance, and unlock untapped potential. Varicent stands at the forefront of innovation, celebrated as a market leader in the 2025 Forrester Wave Report for SPM, 2023 Ventana Research Revenue Performance Management (RPM) Value Index, Gartner Peer Insights, 2024 Gartner SPM Market Guide, and G2. Our solutions are trusted by a diverse range of global industry leaders like T-Mobile, ServiceNow, Wawanesa Bank, Shaw Industries, Moody's, Stryker and hundreds more. Here’s why you’ll thrive at Varicent:

  • Innovate with Purpose: Build impactful solutions for customers worldwide.
  • Join Excellence: Work in a diverse, collaborative, and innovative team.
  • Shape the Future: Lead in redefining revenue optimization.
  • Grow Together: Unlock your potential in a supportive environment.

Join us at Varicent—where your talent and ambition meet limitless opportunities for success!

About the Role

We're looking for a highly technical and hands-on Director, Product Security Architectto help shape secure-by-design principles across our SaaS products, cloud platforms, and AI-enabled products. This role is deeply embedded in Product and Engineering, with a focus on identifying and eliminating architectural risk before it reaches production.

In this role, you'll partner closely with Engineering, Product, Cloud Operations, Architecture, AI, and Security teams to embed security early in the software development lifecycle. You'll lead product and application security architecture, threat modeling, secure design reviews, and AI security initiatives while helping teams build scalable, resilient, and secure solutions.

This is a highly technical product security role requiring deep hands-on experience with software architecture, threat modeling, and secure design, as well as the ability to translate security risks into practical engineering solutions.

This is a highly visible leadership role reporting directly to the VP & Chief Information Security Officer.

What You'll Do
Lead Product Security Architecture & Secure-by-Design
  • Define and execute the Product Security Architecture and Secure-by-Design strategy and roadmap.
  • Establish secure reference architectures, design standards, and secure patterns for cloud-native and AI-enabled solutions.
  • Partner with Engineering and Product teams to embed security into development workflows and system design decisions.
  • Drive adoption of secure-by-design best practices by embedding security requirements in epics, user stories, and the AI SDLC.
  • Produce actionable threat modeling artifacts including data flow diagrams, trust boundary analysis, abuse cases, attack paths, security requirements, technical specifications, design risks, remediation actions, and residual risk documentation.
  • Analyze recurring vulnerabilities, penetration test results, incident learnings, and security assessment findings to identify systemic design flaws and improve secure architecture standards.
  • Lead threat modeling activities across critical applications, platforms, and AI-enabled systems.
  • Identify architectural risks, attack paths, abuse cases, and trust boundary concerns.
  • Translate threats into actionable security requirements, architectural recommendations, and remediation guidance, partnering directly with engineering teams to implement and validate design changes.
  • Build reusable threat models, security patterns, and design libraries that scale across engineering teams.
Partner with Engineering Teams
  • Guide teams on secure design principles, risk-based decision making, and security tradeoffs.
  • Review distributed systems, microservices, cloud-native architectures, APIs, mobile applications, and identity solutions.
  • Support remediation efforts and validate architectural fixes for security findings and design flaws.
  • Conduct architecture reviews across AWS, Azure, and IBM Cloud environments.
  • Assess containerized, Kubernetes, serverless, and AI-enabled architectures.
  • Define cloud security and AI guardrails, governance models, and secure deployment patterns.
  • Partner with AI teams to evaluate security risks within LLM-enabled products and agentic workflows.
Influence Across the Organization
  • Represent Security while collaborating with Product, Engineering, Software Architecture, Cloud, andLegal stakeholders.
  • Develop security standards, training, and architecture guidance.
  • Communicate architectural risk and security recommendations to technical and executive audiences.
What You'll Bring
  • 10+ years of Information Security experience, with significant hands-on experience in Product Security, Application Security, Security Architecture, or Software Security Engineering.
  • 3+ years of hands-on Application Security Architecture and Threat Modeling experience.
  • 3–5 years of Software Development or Software Engineering experience.
  • Strong understanding of secure application design, cloud security, and modern software architectures.
  • Experience with DevSecOps, secure SDLC practices, and AI-enabled development environments.
  • Expertise in threat modeling methodologies such as STRIDE, CAPEC, and MITRE ATT&CK.
  • Experience securing web, API, mobile, cloud-native, and AI-enabled applications.
  • Knowledge of AWS, Azure, or IBM Cloud security architectures.
  • Strong communication skills with the ability to influence stakeholders at all levels.
  • Certifications such as ISC2 ISSAP (Information Systems Security Architecture Professional), CISSP, CSSLP, OSCP, or relevant cloud security certifications are considered an asset.
What Success Looks Like
First 90 Days
  • Assess current architecture, development processes, and secure design maturity.
  • Build relationships across Product, Engineering, Architecture, Cloud, and Security stakeholder teams.
  • Identify high-priority risks and opportunities to improve secure-by-design adoption.
  • Establish a roadmap for threat modeling and to embed secure design requirements in the AI SDLC workflow.
6+ Months
  • Standardize and embed threat modeling and architecture review processes within the AI SDLC.
  • Embed security requirements into engineering and AI development workflows.
  • Expand automated security architecture and design validation capabilities.
Long-Term
  • Scale secure-by-design practices across all products and platforms.
  • Mature security architecture risk management and AI security governance.
  • Enable measurable reductions in security risk through proactive secure design and engineering practices.

For this role, the estimated annual base salary range is between $138,200.00 - $181,400.00 CAD. In addition to base salary, our compensation package may include bonuses, commissions for eligible sales roles, and a comprehensive benefits package. The actual base salary will vary based on factors including individual qualifications and market data, as objectively assessed during the interview process.

This posting is for a new vacancy.

This hiring process utilizes artificial intelligence tools to assist in candidate screening and assessment. Our AI tools are designed to complement — not replace — human decision-making.

Overview of Benefits
  • Health & Wellness — Comprehensive medical, dental, and vision coverage tailored to your local needs
  • Time Off — PTO and public holidays to rest, recharge, and do what matters most
  • Volunteer Days — Dedicated time to give back and support the communities that matter to you
  • Ignite Days — Dedicated learning days to support continuous growth, skill development, and professional learning
  • Financial — Compensation that reflects your market and your value
  • Retirement — Retirement plans designed to help you build long-term financial security
  • Tuition Assistance — Invest in your growth with support for continuing education and professional development
  • Flexibility — Work where you thrive, with remote and hybrid options available across most regions

Varicent is committed to creating a diverse environment and is proud to be an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability, age, or veteran status. If you require accommodation at any time during the recruitment process please email accomodations@varicent.com

Varicent is also committed to compliance with all fair employment practices regarding citizenship and immigration status. By applying for a position at Varicent and/or by using this portal, you declare and confirm that you have read and agree to ourJob Applicant Privacy Notice and that the information provided by you as part of your application is true and complete and includes no misrepresentation or material omission of fact

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Director, Product Security Architect
Director, Product Security Architect

Doist • Toronto

Hybrid
CAD 138,000 - 181,000
Health & Wellness
Time Off
Volunteer Days
+5
Senior Product Manager - AI
Senior Product Manager - AI

FunnelCake • Vancouver

On-site
CAD 125,000 - 165,000
Senior Product Manager - AI
Senior Product Manager - AI

FunnelCake • Toronto

On-site
CAD 121,000 - 159,000
Senior Product Manager - AI
Senior Product Manager - AI

Varicent • Toronto

On-site
CAD 121,200 - 159,000
Senior IT Technical Support Specialist
Senior IT Technical Support Specialist

FunnelCake • Toronto

On-site
CAD 92,000 - 116,000
Health & Wellness
Time Off
Volunteer Days
+4
Senior Talent Acquisition Advisor
Senior Talent Acquisition Advisor

Varicent Corporation • Toronto

Hybrid
CAD 80,000 - 105,000
Health & Wellness
Time Off
Volunteer Days
+5
Senior Talent Acquisition Advisor
Senior Talent Acquisition Advisor

Varicent • Toronto

On-site
CAD 80,000 - 105,000
Health & Wellness
Time Off
Volunteer Days
+5
Staff Software Engineer – Backend (Typescript / .Nodejs / AWS )
Staff Software Engineer – Backend (Typescript / .Nodejs / AWS )

Doist • Calgary

Hybrid
CAD 121,000 - 159,000
Health & Wellness
Time Off
Volunteer Days
+5
Staff Software Engineer – Backend (Typescript / .Nodejs / AWS )
Staff Software Engineer – Backend (Typescript / .Nodejs / AWS )

Varicent • Calgary

On-site
CAD 121,000 - 159,000
Health & Wellness
Time Off
Volunteer Days
+5
Senior Talent Acquisition Advisor
Senior Talent Acquisition Advisor

FunnelCake • Toronto

Hybrid
CAD 80,000 - 105,000
Health & Wellness
Time Off
Volunteer Days
+5