Director, Product Security Architecture

3 hours, 27 minutes ago
Full-time
Lead
Software Development
GitLab

GitLab

GitLab: The comprehensive DevOps platform revolutionizing software development with automation, AI workflows, and essential tools for efficient collaboration.

Internet Software & Services
1K-5K
Founded 2014

Description

  • Lead, develop, and mentor a team of Product Security Architects and aligned specialists across major product areas.
  • Own and evolve the Product Security Architecture strategy and partnership model with Product and Engineering leadership.
  • Oversee and mature the Product Security Risk Register and drive multi-quarter risk reduction plans.
  • Focus architecture efforts on the highest-impact security decisions while enabling delivery with minimal friction.
  • Define and drive security visions, standards, paved roads, and secure-by-default platform behaviors and configurations.
  • Lead the Product Security AI strategy to expand review coverage, reduce toil, and support developer velocity.
  • Partner with Application Security, Infrastructure Security, Security Research, Security Operations, Security Risk, and Security Compliance on end-to-end risk reduction.
  • Define and track architecture metrics and Key Risk Indicators, and represent Product Security in cross-functional forums.
  • Support teams in making informed security tradeoffs and escalating material risks to the right leadership levels.

Requirements

  • Typically 10+ years of experience leading software, architecture, or application security initiatives in high-velocity R&D organizations.
  • Strong application security and secure design literacy, including familiarity with common vulnerability classes, modern software architectures, and mitigation patterns.
  • Deep understanding of systemic product security risks in large-scale platforms, with experience in one or more of CI/CD and pipeline security, software supply chain security, identity and access management (AuthN/Z), AI/ML security, or multi-tenant SaaS architectures.
  • Proven ability to balance business goals and risk reduction in constrained environments.
  • Demonstrated success building trust with Product and Engineering Directors/VPs and influencing multi-quarter roadmaps.
  • Experience designing and rolling out scalable security patterns, standards, paved roads, and secure-by-default configurations.
  • Experience collaborating with Compliance, Audit, and Security Operations on security controls and quality standards.
  • Experience supporting major technology and architectural change while maintaining or improving security posture.
  • Excellent written and verbal communication skills and the ability to operate effectively in an all-remote, asynchronous environment.
  • Comfort with AI-augmented workflows, including tools like GitLab Duo, and alignment with GitLab’s values.
  • Nice to have: experience with FedRAMP, ISO 27001, SOC 2, or PCI-DSS; and experience in organizations undergoing scaling, reorganization, or operating model transformation.

Benefits

  • Base salary range of $205,900 to $289,600 USD for the listed U.S. level.
  • Benefits to support your health, finances, and well-being.
  • Flexible Paid Time Off.
  • Equity Compensation and Employee Stock Purchase Plan.
  • Growth and Development Fund.
  • Parental leave.
  • Home office support.
  • Remote-first work with country-based hiring flexibility.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Principal Systems Programmer, Healthcare Innovations

American Institutes for Research 1K-5K Professional Services

AIR is seeking a Principal Systems Programmer to lead scalable data systems and programming solutions for health research, translating evidence into actionable insights across its healthcare innovations portfolio.

Databricks Git HIPAA Python R SQL
12 minutes ago

Staff Engineer (Product Architecture, JetBrains Cloud Platform)

JetBrains 1K-5K Internet Software & Services

JetBrains is hiring a Software Architect (Product Architecture) to own the end-to-end architecture of a product domain within its AI-native Cloud Platform and ensure it evolves coherently with platform capabilities and long-term product needs.

System Design
27 minutes ago

Salesforce Technical Architect, AI and Agentforce

NeuraFlash 251-1K IT Services

NeuraFlash, Part of Accenture is hiring a Salesforce Technical Architect to design and deliver Agentforce-powered AI solutions that improve client workflows and customer experiences.

C# CI/CD CSS Generative AI HTML Java JavaScript Python Salesforce Salesforce Apex Salesforce Lightning
1 hour, 27 minutes ago

Staff Product Security Engineer

Affirm 1K-5K Diversified Financial Services

Affirm is hiring a Staff Product Security Engineer to work with product and engineering teams to improve the security of its consumer financial products across the product development lifecycle.

AWS Azure CI/CD Java Kotlin OAuth OWASP Python SAML
2 hours, 27 minutes ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers