Staff Product Security Architect

Posted 2 days ago

Apply Now

Resume Score

Check how well your resume matches this job before you apply.

Sign in to check score

About the role

  • Staff Product Security Architect securing GitLab’s DevSecOps orchestration platform. Driving architecture, threat modeling, prototypes, and systemic risk reduction across engineering.

Responsibilities

  • Partner with engineering and product leadership across GitLab to anticipate security problems
  • Lead security architecture and design work for strategic initiatives and direct cross-functional delivery teams
  • Identify, assess, and prioritize systemic security risks
  • Act as Security Owner for high-priority Product Security Risk Register items and co-execute remediation
  • Codify security decisions into reusable guardrails, standards, design patterns, skills, and threat models for developer and AI coding workflows
  • Build proofs of concept and prototypes to unblock engineering teams
  • Conduct security architecture reviews for large or strategic projects
  • Coordinate with Application Security to prioritize comprehensive review coverage
  • Threat model new and existing systems and establish reusable threat-modeling patterns
  • Work with Security Research to explore unknown architectural risks
  • Anticipate emerging security challenges and propose architectural responses
  • Mentor security engineers and represent security architecture to engineering audiences

Requirements

  • Depth in application security architecture, including authentication and authorization models, privilege escalation, multi-tenant isolation, and trust boundary analysis
  • Experience securing distributed systems, including service-to-service authentication, secrets handling, and security decisions across process boundaries
  • Working knowledge of software supply chain security: build and release integrity, artifact provenance, and dependency risk
  • Track record of proactive architecture work identifying risk before incidents and designing preventative solutions
  • Ability to build trusted relationships with engineering leadership and influence technical direction through expertise
  • Experience defining security standards or patterns adopted by teams
  • Ability to operate strategically while remaining hands-on, including reading unfamiliar code, building prototypes, and contributing changes
  • Clear written communication and ability to make security arguments to engineering audiences
  • Perspective on authoring and delivering security guidance for AI coding tools
  • Ability to incorporate AI into daily workflows

Benefits

  • Benefits to support your health, finances, and well-being
  • Flexible Paid Time Off
  • Team Member Resource Groups
  • Equity Compensation & Employee Stock Purchase Plan
  • Growth and Development Fund
  • Parental Leave

Job type

Full Time

Experience level

Lead

Salary

$168,000 - $238,000 per year

Degree requirement

No Education Requirement

Tech skills

Distributed Systems

Location requirements

RemoteUnited States

Report this job

Found something wrong with the page? Please let us know by submitting a report below.