VP, Product Security Architecture (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Location: Stamford, Connecticut, United States. Hybrid work is available from home near a Hub or from an office, with required commuting to the nearest Hub for in-person meetings, training, and culture events. Legal authorization to work in the U.S. is required.
Salary: $155,000–$260,000 USD annual, plus eligibility for an annual performance bonus.
Company
provides financial services and operates a regulated technology environment spanning applications, SaaS platforms, and distributed systems.
What you will do
- Set the strategic vision, operating model, and multi-year roadmap for enterprise product and application security architecture.
- Own the Application Security Blueprint, including reference architectures, approved patterns, reusable assets, and engineering guardrails.
- Lead architecture governance through design reviews, decision frameworks, remediation plans, risk exceptions, and executive reporting.
- Define threat-modeling practices and facilitate modeling for high-risk initiatives, documenting trust boundaries, data flows, abuse cases, and security requirements.
- Standardize API, cloud-native, SaaS, and service-to-service security patterns, including identity, authorization, mTLS, secrets management, and policy enforcement.
- Lead and develop Security Architects while partnering with product, engineering, platform, infrastructure, application ownership, and oversight teams.
Requirements
- 10+ years of experience in security architecture or engineering, with deep application or product security expertise.
- Enterprise-level experience setting standards, influencing product roadmaps, and driving cross-team adoption.
- Strong knowledge of authentication, authorization, token security, cryptography, secrets management, secure logging, and secure data handling.
- Experience with threat modeling, data-flow diagrams, trust boundaries, API security, OWASP risks, SaaS security, and service-to-service security.
- Experience with DevSecOps, CI/CD controls, vulnerability management, software supply-chain security, and regulated environments.
- Ability to travel for business as required; U.S. work authorization is required, and visa sponsorship is not available.
Nice to have
- CISSP, CCSP, CSSLP, or an equivalent certification.
- Experience with threat-modeling tools, API gateways, SSO, SAML, OIDC, SAST, DAST, SCA, secret scanning, GitHub, Jenkins, service mesh, and mTLS.
Culture & Benefits
- Flexible hybrid work with the option to work from home near a Hub or from an office.
- Inclusive workplace with employee resource groups and opportunities for learning and growth.
- Background investigation, fingerprinting, drug testing, and other onboarding eligibility checks are required.
- Reasonable accommodations are available during the application and employment process.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →