VP, Product Security Architecture

Synchrony

Confirmed live yesterday High trust

Quick summary

Work type
On-site
Location
Stamford, CT
Salary
$155,000–$260,000 / yr
Posted
3 days ago
Freshness
Confirmed live yesterday

Market check

Salary context

Competitive pay

How this pay compares to similar roles

Similar $204k
This role $208k
$142k most similar roles pay here $273k

This role pays more than 52% of similar roles. Most pay $172,935–$235,500 — the shaded band above. At the midpoint, this role pays about $208k versus about $204k for comparable roles.

Based on 240 similar postings.

Employer

About Synchrony

Synchrony is a premier consumer financial services company and one of the nation’s largest providers of private-label and co-branded credit cards, alongside promotional financing and FDIC-insured savings products.

Synchrony currently has 3 open roles on FindRole.

Most-posted roles

View all roles at Synchrony

At a glance

TL;DR · VP, Product Security Architecture

As a VP, Product Security Architecture, you will provide enterprise-level leadership for the product security architecture function across an application and SaaS ecosystem. You will lead the definition of an Application Security Blueprint, establishing reference architectures, approved patterns, and engineering guardrails to ensure software is secure-by-design. Your daily responsibilities include managing architecture governance, performing design reviews, conducting threat modeling at scale, and standardizing API security for distributed systems and cloud-native applications. You will also manage a team of architects while partnering with product leaders to integrate security into the SDLC. Key technical requirements include expertise in authentication, authorization, cryptography, mTLS, secrets management, and identity federation via SAML/OIDC. The role addresses complex challenges in regulated environments, translating requirements like PCI-DSS, GDPR, and SOC 2 into actionable designs for high-risk initiatives and service-to-service communications.

What you'll do

  • Establish the strategic vision, operating model, and multi-year roadmap for enterprise application and product security.
  • Develop and maintain the Application Security Blueprint including reference architectures, reusable patterns, and engineering guardrails.
  • Lead architecture governance by performing design reviews, establishing review criteria, and managing risk acceptance for exceptions.
  • Drive threat modeling at scale by defining methodologies and facilitating sessions for high-risk initiatives to identify trust boundaries and data flows.
  • Standardize security architectures for APIs and distributed systems, including authentication, authorization, mTLS, and secrets management.
  • Translate regulatory requirements like PCI-DSS and GDPR into actionable technical security designs for infrastructure and application teams.
  • Manage a team of Security Architects by providing strategic direction, coaching, and mentoring to foster a security-first culture.
  • Develop and report key performance indicators and risk metrics to executive leadership to demonstrate business impact and security maturity.

What we're looking for

  • 10+ years of experience in security architecture and engineering with a focus on application and product security.
  • Proven ability to provide enterprise-level leadership by setting standards, driving adoption, and aligning stakeholders.
  • Strong hands-on knowledge of authentication, authorization, cryptography, secrets management, and secure data handling.
  • Experience leading threat modeling and producing high-quality architecture artifacts like DFDs and risk assessments.
  • Expertise in API security, including common web risks such as OWASP Top 10 and API Security Top 10.
  • Experience securing SaaS applications using SSO/federation (SAML/OIDC) and managing tenant isolation.
  • Proficiency in DevSecOps practices, CI/CD controls, and software supply chain security.
  • CISSP, CCSP, or CSSLP certifications are preferred.

More like this

Similar roles

Principal Product Manager, Agentic Security

Microsoft

6 days ago $142,800$274,800
Artificial Intelligence Cybersecurity Cloud Services Knowledge Graphs Distributed Systems Release Governance Incident Management Service Health Reviews Data Science
8+ yrs exp Hybrid

Principal Security Architect

LPL Financial

Fort Mill, NC +5 2 days ago $153,470$255,749
API Security OAuth JWT AWS Terraform Cloud Formation Ansible Python Java C# .Net Ruby Microservices SIEM zero-trust Machine Learning OWASP NIST ISO27000
8+ yrs exp Hybrid

Principal Security Architect

LPL Financial

Fort Mill, NC +5 2 days ago $153,470$255,749
API Security OAuth JWT AWS Terraform Cloud Formation Ansible Python Java C# .Net Ruby Microservices SIEM zero-trust Machine Learning OWASP NIST ISO27000
8+ yrs exp Hybrid

Product Security Architect

JPMorgan Chase

Plano, TX 23 days ago
Cybersecurity Software Architecture Java Python C# Cloud-native AWS Azure System Design Application Development Artificial Intelligence Machine Learning Mobile Technologies Compliance Standards
5+ yrs exp

Principal Product Security Engineer

Johnson & Johnson

Remote (Santa Clara, CA) 23 days ago $118,000$203,550
Threat Modeling Vulnerability Management Penetration Testing CVSS SBOM Cloud Security AWS Azure C C++ C# Java Python Cryptography Secure Boot ISO 14971 AAMI TIR57 IEC 62304 IEC 81001-5-1 HIPAA GDPR HITRUST ISO 27001 OWASP Top 10 SOC 2 FedRAMP
8+ yrs exp Remote

VP, Global Head of Product Security and Risk

Circle

Remote (San Francisco, CA) +14 28 days ago $317,500$365,000
Blockchain Web3 Cloud-native APIs AWS GCP ISO 27001 NIST Cybersecurity Framework CISSP CCSP CEH CCSK Cybersecurity Fintech AML Product Security Risk Management Governance
10+ yrs exp Remote