Director, Product Security Architect

Doist

Toronto

On-site

CAD 138,000 - 181,000

Full time

3 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Health & Wellness
Time Off
Volunteer Days
Ignite Days
Financial
Retirement
Tuition Assistance
Flexibility

Job summary

Varicent is seeking a highly technical Director, Product Security Architect to embed secure-by-design principles across our SaaS products, cloud platforms, and AI-enabled offerings. This role sits at the intersection of Product and Engineering, identifying architectural risks before they reach production and partnering with Engineering, Product, Cloud Operations, Architecture, AI, and Security teams.

You will lead product security architecture, threat modelling, secure design reviews, and AI

Qualifications

  • 10+ years of Information Security experience, with hands-on product/security architecture expertise.
  • 3+ years of hands-on Application Security Architecture and Threat Modelling experience.
  • 3–5 years of Software Development or Software Engineering experience.
  • Strong understanding of secure application design, cloud security, and modern architectures.
  • Experience with DevSecOps, secure SDLC, and AI-enabled development environments.
  • Knowledge of STRIDE, CAPEC, MITRE ATT&CK threat modelling methods.
  • Experience securing web, API, mobile, cloud-native, and AI-enabled applications.
  • Knowledge of AWS, Azure, or IBM Cloud security architectures.
  • Strong communication skills to influence stakeholders at all levels.
  • Certifications in security are considered an asset.

Responsibilities

  • Define and execute the Product Security Architecture and Secure-by-design strategy and roadmap.
  • Establish secure reference architectures, design standards, and patterns for cloud-native and AI-enabled solutions.
  • Embed security requirements in epics, user stories, and the AI SDLC with engineering partners.
  • Lead threat modelling activities across critical applications, platforms, and AI-enabled systems.
  • Translate threats into actionable security requirements and remediation guidance for engineering teams.
  • Develop reusable threat models, security patterns, and design libraries.

Skills

Info security
Threat Modelling
Software Development
Security Architecture
DevSecOps
Cloud Security
AI Security
Communication
Certifications

Job description

At Varicent, we’re not just transforming the Sales Performance Management (SPM) market—we’re redefining how organizations achieve revenue success. Our cutting‑edge SaaS solutions empower revenue leaders globally to design smarter go‑to‑market strategies, maximize seller performance, and unlock untapped potential. Varicent stands at the forefront of innovation, celebrated as a market leader in the 2025 Forrester Wave Report for SPM , 2023 Ventana Research Revenue Performance Management (RPM) Value Index , Gartner Peer Insights , 2024 Gartner SPM Market Guide , and G2. Our solutions are trusted by a diverse range of global industry leaders like T‑Mobile, ServiceNow, Wawanesa Bank, Shaw Industries, Moody’s, Stryker and hundreds more. Here’s why you’ll thrive at Varicent: Innovate with Purpose: Build impactful solutions for customers worldwide. Join Excellence: Work in a diverse, collaborative, and innovative team. Shape the Future: Lead in redefining revenue optimization. Grow Together: Unlock your potential in a supportive environment. Join us at Varicent—where your talent and ambition meet limitless opportunities for success!

About the Role

We’re looking for a highly technical and hands‑on Director, Product Security Architect to help shape secure‑by‑design principles across our SaaS products, cloud platforms, and AI‑enabled products. This role is deeply embedded in Product and Engineering, with a focus on identifying and eliminating architectural risk before it reaches production.

In this role, you’ll partner closely with Engineering, Product, Cloud Operations, Architecture, AI, and Security teams to embed security early in the software development lifecycle. You’ll lead product and application security architecture, threat modelling, secure design reviews, and AI security initiatives while helping teams build scalable, resilient, and secure solutions. This is a highly technical product security role requiring deep hands‑on experience with software architecture, threat modelling, and secure design, as well as the ability to translate security risks into practical engineering solutions. This is a highly visible leadership role reporting directly to the VP & Chief Information Security Officer.

What You’ll Do
Lead Product Security Architecture & Secure‑by‑Design

Define and execute the Product Security Architecture and Secure‑by‑design strategy and roadmap. Establish secure reference architectures, design standards, and secure patterns for cloud‑native and AI‑enabled solutions. Partner with Engineering and Product teams to embed security into development workflows and system design decisions. Drive adoption of secure‑by‑design best practices by embedding security requirements in epics, user stories, and the AI SDLC.

Drive Threat Modelling & Risk Analysis

Produce actionable threat modelling artifacts including data flow diagrams, trust boundary analysis, abuse cases, attack paths, security requirements, technical specifications, design risks, remediation actions, and residual risk documentation. Analyse recurring vulnerabilities, penetration test results, incident learnings, and security assessment findings to identify systemic design flaws and improve secure architecture standards. Lead threat modelling activities across critical applications, platforms, and AI‑enabled systems. Identify architectural risks, attack paths, abuse cases, and trust boundary concerns. Translate threats into actionable security requirements, architectural recommendations, and remediation guidance, partnering directly with engineering teams to implement and validate design changes. Build reusable threat models, security patterns, and design libraries that scale across engineering teams.

Partner with Engineering Teams

Guide teams on secure design principles, risk‑based decision making, and security trade‑offs. Review distributed systems, microservices, cloud‑native architectures, APIs, mobile applications, and identity solutions. Support remediation efforts and validate architectural fixes for security findings and design flaws.

Secure Cloud & AI Platforms

Conduct architecture reviews across AWS, Azure, and IBM Cloud environments. Assess containerised, Kubernetes, serverless, and AI‑enabled architectures. Define cloud security and AI guardrails, governance models, and secure deployment patterns. Partner with AI teams to evaluate security risks within LLM‑enabled products and agentic workflows. Influence Across the Organization Represent Security while collaborating with Product, Engineering, Software Architecture, Cloud, and Legal stakeholders. Develop security standards, training, and architecture guidance. Communicate architectural risk and security recommendations to technical and executive audiences.

What You’ll Bring
  • 10+ years of Information Security experience, with significant hands‑on experience in Product Security, Application Security, Security Architecture, or Software Security Engineering.
  • 3+ years of hands‑on Application Security Architecture and Threat Modelling experience.
  • 3–5 years of Software Development or Software Engineering experience.
  • Strong understanding of secure application design, cloud security, and modern software architectures.
  • Experience with DevSecOps, secure SDLC practices, and AI‑enabled development environments.
  • Expertise in threat modelling methodologies such as STRIDE, CAPEC, and MITRE ATT&CK.
  • Experience securing web, API, mobile, cloud‑native, and AI‑enabled applications.
  • Knowledge of AWS, Azure, or IBM Cloud security architectures.
  • Strong communication skills with the ability to influence stakeholders at all levels.
  • Certifications such as ISC2 ISSAP (Information Systems Security Architecture Professional), CISSP, CSSLP, OSCP, or relevant cloud security certifications are considered an asset.
What Success Looks Like
First 90 Days

Assess current architecture, development processes, and secure design maturity. Build relationships across Product, Engineering, Architecture, Cloud, and Security stakeholder teams. Identify high‑priority risks and opportunities to improve secure‑by‑design adoption. Establish a roadmap for threat modelling and to embed secure design requirements in the AI SDLC workflow.

6+ Months

Standardise and embed threat modelling and architecture review processes within the AI SDLC. Embed security requirements into engineering and AI development workflows. Expand automated security architecture and design validation capabilities.

Long‑Term

Scale secure‑by‑design practices across all products and platforms. Mature security architecture risk management and AI security governance. Enable measurable reductions in security risk through proactive secure design and engineering practices.

Estimated Compensation

For this role, the estimated annual base salary range is between $138,200.00 - $181,400.00 CAD . In addition to base salary, our compensation package may include bonuses, commissions for eligible sales roles, and a comprehensive benefits package. The actual base salary will vary based on factors including individual qualifications and market data, as objectively assessed during the interview process.

Overview of Benefits
  • Health & Wellness — Comprehensive medical, dental, and vision coverage tailored to your local needs
  • Time Off — PTO and public holidays to rest, recharge, and do what matters most
  • Volunteer Days — Dedicated time to give back and support the communities that matter to you
  • Ignite Days — Dedicated learning days to support continuous growth, skill development, and professional learning
  • Financial — Compensation that reflects your market and your value
  • Retirement — Retirement plans designed to help you build long‑term financial security
  • Tuition Assistance — Invest in your growth with support for continuing education and professional development
  • Flexibility — Work where you thrive, with remote and hybrid options available across most regions
Equal Opportunity Statement

Varicent is committed to creating a diverse environment and is proud to be an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability, age, or veteran status. If you require accommodation at any time during the recruitment process please email accomodations@varicent.com.

Notice & Privacy

Varicent is also committed to compliance with all fair employment practices regarding citizenship and immigration status. By applying for a position at Varicent and/or by using this portal, you declare and confirm that you have read and agree to our Job Applicant Privacy Notice and that the information provided by you as part of your application is true and complete and includes no misrepresentation or material omission of fact.

AI Recruiting Note

This hiring process utilizes artificial intelligence tools to assist in candidate screening and assessment. Our AI tools are designed to complement — not replace — human decision‑making.

Posting Type

This posting is for a new vacancy.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Director, Product Security Architect
Director, Product Security Architect

Varicent • Toronto

Hybrid
CAD 138,000 - 181,000
Health coverage
PTO & holidays
Volunteer days
+5
Senior Product Manager - AI
Senior Product Manager - AI

FunnelCake • Vancouver

On-site
CAD 125,000 - 165,000
Senior Product Manager - AI
Senior Product Manager - AI

Varicent • Toronto

On-site
CAD 121,200 - 159,000
Senior Product Manager - AI
Senior Product Manager - AI

FunnelCake • Toronto

On-site
CAD 121,000 - 159,000
Senior Talent Acquisition Advisor
Senior Talent Acquisition Advisor

FunnelCake • Toronto

Hybrid
CAD 80,000 - 105,000
Health & Wellness
Time Off
Volunteer Days
+5
Staff Software Engineer – Backend (Typescript / .Nodejs / AWS )
Staff Software Engineer – Backend (Typescript / .Nodejs / AWS )

Doist • Calgary

Hybrid
CAD 121,000 - 159,000
Health & Wellness
Time Off
Volunteer Days
+5
Senior Talent Acquisition Advisor
Senior Talent Acquisition Advisor

Varicent Corporation • Toronto

Hybrid
CAD 80,000 - 105,000
Health & Wellness
Time Off
Volunteer Days
+5
Senior Talent Acquisition Advisor
Senior Talent Acquisition Advisor

Varicent • Toronto

On-site
CAD 80,000 - 105,000
Health & Wellness
Time Off
Volunteer Days
+5
Director of Product Security Architecture & Secure-by-Design
Director of Product Security Architecture & Secure-by-Design

Varicent • Toronto

Hybrid
CAD 138,000 - 181,000
Health coverage
PTO & holidays
Volunteer days
+5
Senior IT Technical Support Specialist
Senior IT Technical Support Specialist

FunnelCake • Toronto

On-site
CAD 92,000 - 116,000
Health & Wellness
Time Off
Volunteer Days
+4