Senior Product Security Architect – Overview
We are seeking an experienced Senior Product Security Architect to embed security throughout the product lifecycle—from design to deployment—while enabling secure innovation at scale. In this senior leadership role, you will define product security strategy, influence engineering practices, and ensure security is a core pillar of product development.
Key Responsibilities
- Security Architecture & Strategy: Define and implement product security architecture frameworks and standards. Integrate Security-by-Design and Privacy-by-Design into all products, lead threat modeling and risk assessments, and drive adoption of NIST SSDF, OWASP SAMM, and other frameworks.
- Secure SDLC: Design and implement a Secure SDLC (SSDLC) framework across teams. Embed security controls across design, development, testing, and deployment, enforce secure coding standards, and ensure adoption of SAST, DAST, SCA, and penetration testing tools.
- Engineering & DevSecOps Enablement: Partner with engineering teams to shift security left, drive DevSecOps practices, provide security training, conduct architecture reviews, and govern CI/CD security controls.
- Vulnerability & Risk Management: Oversee vulnerability management lifecycle, define prioritization frameworks, conduct penetration testing reviews, and interpret findings from SAST, DAST, SCA, and penetration testing activities.
- Cloud & Infrastructure Security: Provide architecture for AWS, Azure, GCP environments; define controls for IAM, data protection, network security, and container security.
- Regulatory Compliance & Governance: Ensure compliance with ISO 27001, SOC 2, GDPR, and data privacy regulations; partner with risk teams for audits and compliance assessments.
- Leadership & Stakeholder Management: Lead and mentor a team of Product Security Engineers and Architects, collaborate with engineering, product, and cybersecurity leadership, and influence senior stakeholders on security investments and risk posture.
- Incident Readiness & Response: Support security incident handling related to product vulnerabilities, define incident response playbooks, and conduct post‑incident reviews.
Required Qualifications
- Education: Bachelor’s or Master’s degree in Computer Science, Information Security, Engineering, or related field.
- Experience: 12–18+ years in Application Security, Product Security, Security Architecture, or DevSecOps, with proven leadership at Senior Manager or Architect level.
- Technical Skills: Expertise in OWASP Top10, secure coding standards, API security, NIST SSDF, OWASPSAMM, cloud security (AWS/Azure/GCP), container/Kubernetes security, CI/CD pipelines, SAST, DAST, SCA, and penetration testing methodologies.
- Certifications (Preferred): CISSP, CSSLP, CISM, CISA, AWS Security Specialty, Microsoft Azure Security Engineer, or other relevant DevSecOps/Cloud Security certificates.
Leadership Competencies
- Strategic thinking with strong execution focus.
- Ability to influence without authority and manage senior stakeholder relationships.
- Problem‑solving and risk‑based decision making.
- Strong communication and executive presentation skills.
Success Metrics (KPIs)
- Reduction in critical vulnerabilities across products.
- Adoption rate of Secure SDLC practices.
- Improvement in security posture and audit outcomes.
- Reduction in time‑to‑remediation and increased secure coding adoption.
- Enhanced SSDLC maturity and DevSecOps adoption.
Why This Role Is Critical
This role is central to ensuring that security scales with innovation. It embeds security into design, proactively manages risks, enables engineering teams without slowing delivery, and embeds secure development practices into the organizational culture.
We are committed to creating an inclusive workplace and welcome applications from people of all backgrounds. We do not discriminate based on any protected characteristic under applicable law. We are an Equal Opportunity/Affirmative Action Employer.