Senior Product Security Architect

Gong Gong · Enterprise · Tel Aviv, Israel · Information Security

Senior Product Security Architect role at Gong, an AI-powered revenue intelligence company. The role focuses on embedding security into the architecture and design of AI-driven features and cloud-native systems, working closely with engineering teams to address complex security challenges related to data protection, privacy, and trust in AI systems. Responsibilities include threat modeling, secure design, securing AI/ML features, and strengthening the software supply chain.

What you'd actually do

  1. Shape security architecture where it matters most, partner with engineers early in the design phase to influence system architecture, define secure patterns, and make critical decisions before code is written
  2. Work hands-on with engineering teams to secure real systems review designs, dive into code and PRs when needed, and build small tools or proofs-of-concept to validate security assumptions
  3. Lead threat modeling and deep design reviews identify trust boundaries, abuse cases, and high-impact attack paths, and ensure controls hold up in real production environments
  4. Own security design for authentication, authorization, and APIs, including identity flows (OAuth/OIDC), session management, and multi-tenant access control
  5. Take ownership of complex security challenges across cloud-native, distributed, and AI-driven systems, where trade-offs are not obvious and solutions require both depth and pragmatism

Skills

Required

  • 8+ years of experience in Product Security, Application Security, or Security Architecture
  • Strong software engineering foundation with the ability to read code (e.g., Java, Python, JavaScript/TypeScript, React or similar), review PRs, and understand systems end-to-end.
  • Deep understanding of application security principles (OWASP Top 10, secure design, common vulnerability classes)
  • Experience securing cloud-native SaaS environments (AWS, GCP, and/or Azure), including containers and Kubernetes
  • Strong knowledge of authentication and authorization systems, including OAuth2, OIDC, SAML, and secure API design

What the JD emphasized

  • security decisions truly matter
  • AI is core to the product
  • AI-driven features
  • Secure AI/ML features in production
  • complex security challenges across cloud-native, distributed, and AI-driven systems

Other signals

  • AI is core to the product
  • AI-driven features
  • Secure AI/ML features in production