Staff Product Security Architect securing GitLab’s DevSecOps orchestration platform. Driving architecture, threat modeling, prototypes, and systemic risk reduction across engineering.
Responsibilities
Partner with engineering and product leadership across GitLab to anticipate security problems
Lead security architecture and design work for strategic initiatives and direct cross-functional delivery teams
Identify, assess, and prioritize systemic security risks
Act as Security Owner for high-priority Product Security Risk Register items and co-execute remediation
Codify security decisions into reusable guardrails, standards, design patterns, skills, and threat models for developer and AI coding workflows
Build proofs of concept and prototypes to unblock engineering teams
Conduct security architecture reviews for large or strategic projects
Coordinate with Application Security to prioritize comprehensive review coverage
Threat model new and existing systems and establish reusable threat-modeling patterns
Work with Security Research to explore unknown architectural risks
Anticipate emerging security challenges and propose architectural responses
Mentor security engineers and represent security architecture to engineering audiences
Requirements
Depth in application security architecture, including authentication and authorization models, privilege escalation, multi-tenant isolation, and trust boundary analysis
Experience securing distributed systems, including service-to-service authentication, secrets handling, and security decisions across process boundaries
Working knowledge of software supply chain security: build and release integrity, artifact provenance, and dependency risk
Track record of proactive architecture work identifying risk before incidents and designing preventative solutions
Ability to build trusted relationships with engineering leadership and influence technical direction through expertise
Experience defining security standards or patterns adopted by teams
Ability to operate strategically while remaining hands-on, including reading unfamiliar code, building prototypes, and contributing changes
Clear written communication and ability to make security arguments to engineering audiences
Perspective on authoring and delivering security guidance for AI coding tools
Ability to incorporate AI into daily workflows
Benefits
Benefits to support your health, finances, and well-being
Flexible Paid Time Off
Team Member Resource Groups
Equity Compensation & Employee Stock Purchase Plan
Information Security Manager leading enterprise EUC governance technology deployment and product roadmaps at TD, a global financial institution. Driving risk controls, adoption, delivery and assurance across business segments.
Principal Cloud Security Engineer securing Pax8’s cloud marketplace, infrastructure, and AI - enabled platforms. Establishing cloud, Kubernetes, identity, and software - delivery security standards across USA and Canada.
Cyber Security Engineer auditing diverse codebases, fixing vulnerabilities, and optimizing backend software. Contributing security insights and improvements to AI training datasets for a technology company.
Senior Associate designing cloud, application, and AI security solutions for PwC Canada’s consulting clients. Leading technical delivery pods and embedding DevSecOps across client environments.
Application Security Researcher building autonomous application - security capabilities for OX Security. Researching attack paths, AI models, and detection engines from prototype through production.
Managing Norfolk County’s cybersecurity, disaster recovery, incident response, and security projects. Supervising IT security staff and protecting municipal systems, services, and information.
IT Security Officer overseeing information security for Desjardins’ property and casualty insurance sector. Managing risks, vulnerabilities, suppliers, complex projects, and executive security reporting.
Azure SA&A Specialist supporting Government of Canada security assessments, controls, evidence, and testing. PLATO delivers Indigenous - owned software testing and technology services across Canada.