Staff Product Security Architect

GitLab

Confirmed live yesterday High trust
Remote

Quick summary

Work type
Remote
Location
CanadaIsraelPolandUnited Kingdom
Salary
$168,000–$238,000 / yr
Posted
16 days ago
Freshness
Confirmed live yesterday

Market check

Salary context

Competitive pay

How this pay compares to similar roles

Similar $209k
This role $203k
$155k $267k
below market most similar roles pay here above market

This role pays less than 58% of similar roles. Most pay $176,193–$241,750 — the blue band above. At the midpoint, this role pays about $203k versus about $209k for comparable roles.

Based on 240 similar postings.

Employer

About GitLab

GitLab is an all-remote software company that develops an AI-powered DevSecOps platform combining source code management, CI/CD, security scanning, and project planning in a single application.

GitLab currently has 55 open roles on FindRole.

Listed pay typically runs $152,800–$235,600 across 49 roles with salary data.

Most-posted roles

View all roles at GitLab

At a glance

TL;DR · Staff Product Security Architect

The Staff Product Security Architect joins the Security Platforms and Architecture team to serve as a hands-on technical driver for the Core DevOps functional area. This role involves spearheading architectural strategy for critical capabilities, conducting design reviews, and performing technical prototyping to unblock engineering teams. You will identify systemic risks, act as a Security Owner for high-priority items in the Product Security Risk Register, and codify security decisions into reusable artifacts like guardrails and threat models. Key responsibilities include securing distributed systems, managing software supply chain integrity, and analyzing authentication, authorization, and multi-tenant isolation. You will build proofs of concept and provide proactive guidance to ensure security standards are embedded directly into modern developer workflows and automated coding environments.

What you'll do

  • Lead security architecture and design for strategic initiatives and provide direction to cross-functional delivery teams.
  • Identify and prioritize systemic security risks and act as the Security Owner for high-priority items in the risk register.
  • Codify recurring security decisions into reusable artifacts like guardrails, standards, design patterns, and reference threat models.
  • Build proofs of concept and prototypes to unblock engineering teams and shorten the distance between requirements and implementation.
  • Conduct security architecture reviews for large or strategic projects to ensure comprehensive coverage and correct prioritization.
  • Threat model new and existing systems while establishing patterns that allow teams to threat model their own work.
  • Anticipate emerging security challenges and propose architectural responses before they reach the implementation phase.
  • Mentor security engineers across the division and represent security architecture to engineering audiences.

What we're looking for

  • Depth in application security architecture, including authentication, authorization, privilege escalation, multi-tenant isolation, and trust boundary analysis.
  • Experience securing distributed systems, including service-to-service authentication, secrets handling, and security failure modes across process boundaries.
  • Working knowledge of software supply chain security, including build and release integrity, artifact provenance, and dependency risk.
  • Track record of proactive architecture work to identify risks before they become incidents and design solutions that prevent entire classes of problems.
  • Demonstrated ability to build trusted relationships with engineering leadership and influence technical direction through expertise.
  • Experience defining security standards or patterns that teams adopted voluntarily.
  • Ability to operate strategically while remaining hands-on, including reading unfamiliar code and building prototypes.
  • Clear written communication skills and the ability to make security arguments to engineering audiences that may disagree.

More like this

Similar roles

Security Architect, Product Security

Humana

Remote (Atlanta, GA) +10 18 days ago
Application Security SAST SCA Secrets Scanning Secure SDLC Vulnerability Management Cloud Security Container Security API Security DAST SaaS Security Product Security Security Architecture CISSP Security+ CSSLP GSEC GWAPT
2+ yrs exp Remote

Senior Product Security Architect

Early Warning Services

Scottsdale, AZ +3 73 days ago
Application Security Security Architecture Threat Modeling CI/CD Cloud Security Microservices SAST Veracode Fortify AWS GCP Azure Kubernetes VMware OpenStack ISO PCI OWASP NIST 800-53 Linux Windows Relational Databases Cryptography Agile SDLC BSIMM Penetration Testing DevOps
10+ yrs exp Hybrid

Staff Product Security Engineer

Reddit

Remote (San Francisco, CA) 165 days ago $217,000–$303,900
Go Python CI/CD AI LLM Authentication Authorization Cloud-native Application Security Product Security
8+ yrs exp Remote

VP, Product Security Architecture

Synchrony

Stamford, CT +6 33 days ago
Application Security Threat Modeling API Security SAML OIDC mTLS Secrets Management CI/CD SAST DAST SCA DevSecOps PCI-DSS GDPR SOC 2 GitHub Jenkins Service Mesh Cryptography OWASP Top 10
10+ yrs exp

Product Security Architect

JPMorgan Chase

Plano, TX +2 17 days ago
System Design Java Python C# Cloud-native Architecture AWS Azure Software Development Life Cycle Artificial Intelligence Machine Learning Mobile Technologies
5+ yrs exp

Staff Product Security Engineer

Abbott

St. Paul, MN 52 days ago $99,300–$198,700
C/C++ Python Linux Embedded Systems Firmware Secure Boot PKI Threat Modeling STRIDE OWASP SBOM CVE Penetration Testing Fuzz Testing TPM ARM RTOS NXP i.MX VxWorks ISO 27001 NIST Cybersecurity Framework
8+ yrs exp