Product Security Architect

Replit Replit · Enterprise · Foster City, CA · IT

The Product Security Architect will be the subject matter expert for Replit's secure product blueprint, defining and implementing application security architecture for a multi-tenant SaaS platform. This role involves leading security initiatives, providing expertise to engineering and executive leadership, conducting threat modeling, defining security best practices, and assessing risks associated with third-party integrations including AI models.

What you'd actually do

  1. Serve as the primary security mentor and subject matter expert for engineering teams, fostering a culture of technical excellence and rigorous security design.
  2. Define the product security vision, ensuring consistency across complex application architecture projects.
  3. Lead the security implementation of new product features from initial design to final production deployment.
  4. Conduct proactive threat modeling for new product features and major architectural changes.
  5. Define and enforce best practices around application security, including audit/application logging, configuration, tenant separation, encryption, customer BYOK, RBAC design, API design, and Session/cookie/token management.

Skills

Required

  • 8+ years of experience in product security engineering or architecture, specifically with Multi-tenant SaaS products.
  • Deep expertise in common product security practices (e.g., tenant separation, RBAC, BYOK, secure API design, session/token management).
  • Expertise in Authentication/Authorization protocols (mTLS/OIDC/OAuth/SAML) in a multi-tenant SaaS environment.
  • Strong programming background (Python/Go/JavaScript) with proven ability to conduct code review.
  • Experience writing and maintaining Architecture documents.
  • Exceptional ability to communicate technical risk to both engineering and executive audiences.
  • Strong track record of contributing to Cybersecurity Risk Register.

Nice to have

  • Experience with AI Agent-based Saas products is a plus.

What the JD emphasized

  • multi-tenant SaaS
  • Cybersecurity Risk Register