Назад
Company hidden
5 дней назад

Staff Product Security Architect

168 000 - 238 000$
Формат работы
remote (только Europe)
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
UK/US/Poland +2 еще
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Staff Product Security Architect (DevSecOps and AI): Driving security architecture for GitLab’s product engineering organization, embedding proactive security guidance into developer and AI coding workflows with an accent on application security, distributed systems, and software supply chain integrity. Focus on threat modeling, prototyping reusable security patterns, reducing systemic product risks, and influencing engineering direction without manual security gates.

Location: Remote in Canada, Israel, Poland, the United Kingdom, or the United States

United States base salary: $168,000–$238,000 USD per year

Company

hirify.global provides an intelligent orchestration platform for DevSecOps that helps organizations improve developer productivity, operational efficiency, security, compliance, and software delivery.

What you will do

  • Partner with engineering and product leadership to anticipate security problems and guide technical direction.
  • Lead security architecture and design for strategic initiatives and act as Security Owner for high-priority product security risks.
  • Codify security decisions into guardrails, standards, design patterns, skills, and threat models for developer and AI coding workflows.
  • Build proofs of concept and prototypes that help engineering teams implement security requirements.
  • Conduct architecture reviews, threat model systems, and coordinate comprehensive application security coverage.
  • Explore emerging risks with Security Research, mentor security engineers, and represent security architecture to engineering audiences.

Requirements

  • Deep experience in application security architecture, including authentication, authorization, privilege escalation, multi-tenant isolation, and trust boundaries.
  • Experience securing distributed systems, including service-to-service authentication, secrets handling, and cross-process security failure modes.
  • Working knowledge of software supply chain security, build and release integrity, artifact provenance, and dependency risk.
  • Ability to identify systemic risks proactively, define security patterns, and influence engineering leadership through expertise.
  • Hands-on ability to read unfamiliar code, build prototypes, and contribute changes while operating strategically.
  • Ability to develop security guidance for AI coding tools and communicate security arguments clearly to engineering audiences.

Culture & Benefits

  • Fully remote work with location-based eligibility for the listed countries.
  • Flexible paid time off and parental leave.
  • Health, financial, and well-being benefits.
  • Equity compensation and an employee stock purchase plan.
  • Growth and development funding and team member resource groups.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →