Director, Product Security Architecture

GitLab GitLab · Enterprise · Canada +2 · Remote · Product Security

This role leads the Product Security Architecture function, focusing on integrating security into product development and leveraging AI to enhance security practices and developer productivity within a DevSecOps environment.

What you'd actually do

  1. Lead, develop, and mentor a team of Product Security Architects and closely-aligned specialists who are dedicated to major product functional areas (e.g., Sec Section, AI, Core DevOps)
  2. Own and continuously evolve the Product Security Architecture strategy and partnership model, shifting architects from embedded consultants to accelerators of secure architecture delivery, and serve as a strategic partner to Product and Engineering Directors/VPs
  3. Oversee and mature the[Product Security Risk Register](https://handbook.gitlab.com/handbook/security/product-security/security-platforms-architecture/risk-register/), ensuring systemic product security risks are clearly articulated, prioritized with Product and Engineering, and paired with multi-quarter risk reduction plans that reduce long-term product security debt.
  4. Operate Product Security Architecture in a risk-aligned, business-enabling way that focuses Security Architects on the highest-impact, hardest-to-change architectural decisions, helping teams make clear, informed tradeoffs without slowing delivery.
  5. Define and drive security visions, standards, “paved roads,” and secure-by-default platform behaviors and configurations that enable product teams to make sound security decisions with minimal overhead, including evolving existing behaviors over time to strengthen the baseline security posture.
  6. Lead the Product Security AI strategy for scaling, including adoption of AI-assisted and platform-level investments that expand security review coverage, reduce toil, and support non-linear developer gains while enabling developer velocity.
  7. Partner with Application Security, Infrastructure Security, Security Research, Security Operations, Security Risk, and Security Compliance on end-to-end risk reduction, including security-related controls, quality standards, and integration of research and operational learnings into architectures.
  8. Define and track meaningful architecture-related metrics and Key Risk Indicators, and represent Product Security in cross-functional forums, clearly articulating risk, tradeoffs, and recommended paths forward.

Skills

Required

  • Lead, develop, and mentor a team
  • Product Security Architecture strategy
  • Product Security Risk Register management
  • Risk-aligned, business-enabling security operations
  • Define and drive security visions, standards, and secure-by-default configurations
  • Product Security AI strategy for scaling
  • Partner with cross-functional security teams
  • Define and track architecture-related metrics and KRIs
  • Significant experience (typically 10+ years) leading software, architecture, or application security initiatives
  • Strong application security and secure design literacy
  • Familiarity with common vulnerability classes, modern software architectures

Nice to have

  • experience in fintech compliance
  • HIPAA
  • FedRAMP
  • SOC2

What the JD emphasized

  • strategic security partner
  • Product Security Architects
  • risk and metrics engineer
  • Product Security
  • Product and Engineering
  • architectural guidance
  • risk reduction programs
  • feature delivery
  • platform capabilities
  • architectures and technologies
  • product goals
  • security posture
  • Maximize risk reduction
  • strategic opportunities
  • R&D work
  • material product security risks and tradeoffs
  • leadership levels
  • SPA/AppSec scaling strategies
  • developer velocity
  • minimal friction
  • product security background
  • secure, resilient systems
  • complex R&D environments
  • security outcomes
  • engineering
  • Product Security Architects
  • Product Security Architecture strategy
  • secure architecture delivery
  • Product and Engineering Directors/VPs
  • Product Security Risk Register
  • systemic product security risks
  • multi-quarter risk reduction plans
  • product security debt
  • Product Security Architecture
  • risk-aligned, business-enabling way
  • highest-impact, hardest-to-change architectural decisions
  • informed tradeoffs
  • delivery
  • security visions, standards, “paved roads,”
  • secure-by-default platform behaviors and configurations
  • sound security decisions
  • minimal overhead
  • baseline security posture
  • Product Security AI strategy
  • AI-assisted and platform-level investments
  • security review coverage
  • reduce toil
  • non-linear developer gains
  • developer velocity
  • Application Security, Infrastructure Security, Security Research, Security Operations, Security Risk, and Security Compliance
  • end-to-end risk reduction
  • security-related controls
  • quality standards
  • research and operational learnings
  • architectures
  • architecture-related metrics
  • Key Risk Indicators
  • cross-functional forums
  • risk, tradeoffs, and recommended paths forward
  • leading software, architecture, or application security initiatives
  • high-velocity R&D organizations
  • building and evolving complex software systems
  • application security and secure design literacy
  • AppSec roles
  • secure delivery of large-scale systems
  • common vulnerability classes
  • modern software architectures