VP, Product Security Architecture

Synchrony

Stamford (CT)

On-site

USD 180,000 - 260,000

Full time

6 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Synchrony in Stamford, CT seeks a VP, Product Security Architect to provide enterprise security architecture leadership across Synchrony's application and SaaS ecosystem, defining standards and driving adoption at scale.

The role partners with product and engineering leaders to embed security into product strategy and modern software delivery, leading governance, threat modeling, and security pattern development for distributed systems.

Qualifications

  • 10+ years in security architecture/engineering focusing on application/product security in modern software environments.

Responsibilities

  • Provide executive leadership for the Product Security Architecture function and multi-year roadmap.
  • Set product security direction for portfolios, aligning with technology strategy and risk.
  • Own and evolve enterprise security standards, reference architectures, and guardrails.
  • Partner with product/engineering to embed security into product strategy and delivery.

Skills

Security architecture
Threat modeling
API security
Governance
Leadership
Secure SDLC
Cloud security
Secure coding

Job description

Role Summary/Purpose:

Synchrony is seeking a VP, Product Security Architect to provide enterprise-level product security architecture leadership across Synchrony's application and SaaS ecosystem. This role operates at L13 scope-setting direction, defining standards, and driving adoption at scale-while partnering closely with product and engineering leaders to embed security into product strategy and modern software delivery.

Essential Responsibilities:
  • Provide executive leadership for the Product Security Architecture function, establishing the strategic vision, operating model, and multi-year roadmap for application and product security across the enterprise.
  • Set product security architecture direction for assigned portfolios, aligning security architecture decisions with Synchrony technology strategy, risk appetite, and regulatory expectations.
  • Own and evolve the Application Security Blueprint: enterprise application security standards, reference architectures, reusable patterns, and guardrails that enable consistent secure engineering across teams.
  • Serve as a strategic partner to product and engineering leadership, influencing roadmaps and operating models to ensure security is built-in (not bolted-on) and delivery teams can move quickly with well-defined paved roads.
  • Lead architecture governance for product/application security: establish review criteria and decision frameworks, perform design reviews and approve/drive remediation plans, manage exceptions with documented risk acceptance, compensating controls, and time-bound closure.
  • Drive threat modeling at scale by defining methodology and minimum expectations, and by facilitating modeling for high-risk initiatives-explicitly documenting trust boundaries, data flows, abuse cases, and security requirements.
  • Define and standardize API security architectures (north-south and east-west), including authentication/authorization, token strategy, schema and input validation, anti-automation protections, and rate limiting/throttling patterns.
  • Establish security architecture patterns for distributed systems, cloud-native applications, and service-to-service communications, including workload identity, authorization, mTLS, secrets management, and policy enforcement.
  • Establish security architecture patterns for service-to-service security controls in distributed systems, including workload identity, authorization, mTLS, secrets handling, and policy enforcement-ensuring controls are practical for engineering adoption.
  • Develop and report key performance indicators, risk metrics, and security maturity measures to executive leadership, demonstrating business impact and risk reduction outcomes.
  • Influence and enable secure SDLC and platform controls with engineering enablement in mind (security requirements, pipeline guardrails, dependency/supply-chain controls, secure configuration guidance), partnering with platform teams to operationalize.
  • Establish and track measurable outcomes (e.g., blueprint adoption, recurring architecture risks, API posture improvements, exception burn-down, control coverage for critical apps) and provide clear executive-level reporting.
  • Act as a coach and multiplier: mentor engineers and architects, elevate secure design skills across teams, and improve security decision-making through clear documentation and reusable assets.
  • Lead and develop a team of Security Architects, providing strategic direction, coaching, mentoring, while fostering a high-performing, security-first culture.
  • Perform other duties and/or special projects as assigned.
  • Act as a trusted partner to application owners, infrastructure teams, and oversight functions to translate regulatory requirements (PCI-DSS, GDPR, SOC 2) into clear, actionable technical security designs.
  • Perform security architecture reviews and provide hands-on guidance to developers on vulnerability remediation and secure coding practices.
Qualifications/Requirements:
  • 10 + years in security architecture/engineering, with deep focus on application/product security in modern software environments.
  • Demonstrated ability to operate at an enterprise influence level: setting standards, driving cross-team adoption, and aligning stakeholders with differing priorities.
  • Strong hands-on knowledge of application and service security fundamentals: authentication/authorization, session/token security, cryptography concepts, secrets management, secure logging/monitoring design, and secure data handling.
  • Proven experience leading threat modeling and producing strong architecture artifacts (DFDs, trust boundaries, security requirements, risk assessments).
  • Strong knowledge of API security and common web/
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

VP, Secure Product Architecture & Strategy
VP, Secure Product Architecture & Strategy

Synchrony • Chicago (IL)

Hybrid
USD 155,000 - 260,000
Senior VP, Product Security Architecture
Senior VP, Product Security Architecture

Synchrony • Olde West Chester (OH)

Hybrid
USD 155,000 - 260,000
VP Product Security Architecture: Secure-by-Design Leader
VP Product Security Architecture: Secure-by-Design Leader

Relha LLC • Stamford (CT), Northern (KY)

Hybrid
USD 192,000 - 223,000
Annual bonus
Hybrid/Remote work options
Office hubs access
Executive Product Security Architect
Executive Product Security Architect

Synchrony • Stamford (CT)

On-site
USD 180,000 - 260,000
VP of Secure Product Architecture & Strategy
VP of Secure Product Architecture & Strategy

Synchrony • Cincinnati (OH)

Hybrid
USD 155,000 - 260,000
Flexible work arrangements
VP, Product Security Architecture
VP, Product Security Architecture

Relha LLC • Stamford (CT), Northern (KY)

Hybrid
USD 192,000 - 223,000
Annual bonus
Hybrid/Remote work options
Office hubs access
VP, Product Security Architecture
VP, Product Security Architecture

Synchrony • Chicago (IL)

Hybrid
USD 155,000 - 260,000
VP, Product Security Architecture
VP, Product Security Architecture

Synchrony • Olde West Chester (OH)

Hybrid
USD 155,000 - 260,000
VP, Product Security Architecture
VP, Product Security Architecture

Synchrony • Cincinnati (OH)

Hybrid
USD 155,000 - 260,000
Flexible work arrangements
VP, Staff Cryptography Engineer
VP, Staff Cryptography Engineer

Synchrony • Rapid City (SD)

Hybrid
USD 120,000 - 180,000