Назад
Company hidden
5 дней назад

AVP, Product Security Architect (Cybersecurity)

115 000 - 200 000$
Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/

TL;DR

AVP, Product Security Architect (Cybersecurity): Providing enterprise-level product security architecture leadership across application and SaaS ecosystems with an accent on secure-by-design standards and engineering guardrails. Focus on defining the Application Security Blueprint, driving threat modeling at scale, and standardizing API security architectures.

Location: Hybrid; must be based in the US and able to commute to a hirify.global Hub

Salary: $115,000 - $200,000 Annual

Company

hirify.global is a leading financial services company providing consumer finance solutions.

What you will do

  • Define the enterprise Application Security Blueprint, including reference architectures and reusable patterns.
  • Lead architecture governance, performing design reviews and managing risk exceptions.
  • Drive threat modeling at scale, documenting trust boundaries and security requirements.
  • Standardize API security architectures and service-to-service security controls, such as mTLS and workload identity.
  • Partner with product and engineering leadership to embed security into roadmaps and the SDLC.
  • Mentor engineers and architects to elevate secure design skills across the organization.

Requirements

  • 7+ years of experience in security architecture/engineering with a focus on application security.
  • Legal authorization to work in the U.S. is required (no sponsorship provided).
  • Deep knowledge of authentication/authorization, cryptography, and secrets management.
  • Expertise in threat modeling, DFDs, and OWASP Top 10 / API Security Top 10.
  • Experience securing SaaS applications (SAML/OIDC) and implementing service-to-service security.
  • Ability to operate at an enterprise level and influence cross-functional stakeholders.

Nice to have

  • Certifications: CISSP, CCSP, or CSSLP.
  • Experience with threat modeling tools, API gateways, and service mesh patterns.
  • Familiarity with CI/CD security tooling (SAST/DAST/SCA).

Culture & Benefits

  • Hybrid work flexibility: option to work from home near a Hub or in-office.
  • Inclusive culture with active Employee Resource Groups (ERGs).
  • Annual performance-based bonus.
  • Commitment to diversity, equity, and inclusion.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →