Staff Product Security Architect

GitLab
Canada, Israel, Poland, United Kingdom, United States
Workplace: RemoteFull timeUSD 168,000 - 238,000 annuallyFunction: CybersecuritySkills: ["Strategic thinking","Mentoring","Cross-functional collaboration","Risk assessment","Written communication"]

Drive product security architecture for GitLab’s Security Platforms & Architecture team, embedding proactive guidance into developer and AI coding workflows. Partner with product and engineering leaders to lead security design reviews, prototype solutions, and act as Security Owner for high-priority risk register items. Threat model systems, codify reusable security standards and threat models, mentor security engineers, and work with Security Research to anticipate emerging architectural risks.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
GitLab
GitLab
1 day ago

Staff Product Security Architect

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 4 hours agoStatus: Live

Job Summary

Drive product security architecture for GitLab’s Security Platforms & Architecture team, embedding proactive guidance into developer and AI coding workflows. Partner with product and engineering leaders to lead security design reviews, prototype solutions, and act as Security Owner for high-priority risk register items. Threat model systems, codify reusable security standards and threat models, mentor security engineers, and work with Security Research to anticipate emerging architectural risks.
Location: Canada, Israel, Poland, United Kingdom, United States
Workplace: Remote
Employment Type: Full time
Job Function: Cybersecurity
Seniority: Mid level

Key Responsibilities

  • •Partner with engineering and product leadership to anticipate security problems in their domains.
  • •Lead security architecture/design for strategic initiatives and guide cross-functional delivery teams.
  • •Identify, assess, prioritize systemic security risks and serve as Security Owner for high-priority Product Security Risk Register items.
  • •Codify recurring security decisions into reusable artifacts such as guardrails, standards, design patterns, and threat models for developer and AI coding tool workflows.
  • •Build proofs of concept/prototypes, conduct architecture reviews, and coordinate with Application Security to ensure coverage and prioritization.

Pay and Benefits

Salary: USD 168,000 - 238,000 annually
Perks:Paid LeaveEquityLearning BudgetParental Leave

Key Requirements

  • •Depth in application security architecture, including authentication/authorization models, privilege escalation, multi-tenant isolation, and trust boundary analysis.
  • •Experience securing distributed systems, including service-to-service authentication and secrets handling, with understanding of cross-process security failure modes.
  • •Working knowledge of software supply chain security, including build/release integrity, artifact provenance, and dependency risk.
  • •A track record of proactive architecture work that prevents classes of security problems.
  • •Ability to define security standards/patterns teams adopt, and to communicate clear security arguments to engineering audiences.
Experience:DevSecOpsApplication securityDistributed systemsSoftware supply chain securitySecurity architecture
Skills:Strategic thinkingMentoringCross-functional collaborationRisk assessmentWritten communication

Company Brief

GitLab
Provides a single application for the complete DevSecOps lifecycle, offering source code management, CI/CD, security, and collaboration tools to help teams deliver software faster and more securely.
Industry: Developer Tools
Company Size: Enterprise (1,001+ employees)
Revenue: USD 250M to 500M
Growth: Public Company
Valuation: Public Company (Market Cap in USD)
Funding: IPO / Publicly Listed
Headquarters: San Francisco, United States
Founded: 2011
WebsiteLinkedIn