Staff Product Security Architect

at GitLab
📍 Canada
📍 United Kingdom
📍 Israel
📍 Poland
📍 United States
USD 168,000-238,000 per year
SENIOR
✅ Remote

Tech Stack

AI @ 6 Communication @ 6 Design Patterns DevOps Distributed Systems @ 4 Leadership @ 6 Security @ 7

Details

GitLab is hiring a Staff Product Security Architect to join the Security Platforms and Architecture organization. Security Architecture at GitLab is a hands-on technical function focused on embedding proactive security guidance into developer workflows and automated coding environments. The role enables engineering teams to deliver secure, resilient software while reducing reliance on manual security gates.

Responsibilities

  • Partner with engineering and product leadership across GitLab to anticipate security problems in their domains.
  • Lead security architecture and design work for strategic initiatives and provide direction to cross-functional delivery teams.
  • Identify, assess, and prioritize systemic security risks, acting as Security Owner for high-priority items in the Product Security Risk Register and co-executing remediation with the teams that own the code.
  • Codify recurring security decisions into reusable guardrails, standards, design patterns, skills, and reference threat models for developer and AI coding tool workflows.
  • Build proofs of concept and prototypes to help engineering teams implement security requirements.
  • Conduct security architecture reviews for large or strategic projects and coordinate with Application Security to ensure comprehensive, prioritized review coverage.
  • Threat model new and existing systems and establish patterns that enable teams to threat model their own work.
  • Work with Security Research on proactive exploration of unknown risks in GitLab's architecture.
  • Anticipate emerging security challenges and propose architectural responses before implementation.
  • Mentor security engineers and represent security architecture to engineering audiences.

Requirements

  • Deep experience in application security architecture, including authentication and authorization models, privilege escalation, multi-tenant isolation, and trust boundary analysis.
  • Experience securing distributed systems, including service-to-service authentication, secrets handling, and security decision failure modes across process boundaries.
  • Working knowledge of software supply chain security, including build and release integrity, artifact provenance, and dependency risk.
  • A track record of proactive architecture work that identifies risks before incidents and prevents classes of problems rather than individual instances.
  • Ability to build trusted relationships with engineering leadership and influence technical direction through expertise rather than gatekeeping.
  • Experience defining security standards or patterns that engineering teams adopted voluntarily.
  • Ability to operate strategically while remaining hands-on, including reading unfamiliar code, building prototypes, and contributing changes.
  • Clear written communication and the ability to explain security considerations to engineering audiences.
  • A perspective on how security guidance should be authored and delivered for AI coding tools as well as human developers.

Team

Security Architects are part of GitLab's Security Platforms and Architecture team, which includes Security Architecture, Security Research, and Application Security. The team addresses complex product security challenges, focuses on systemic product security risks, and works cross-functionally to maintain engineering velocity.

In FY27, GitLab is implementing an organizational model in which each architect is dedicated to a specific functional area of the product. As the Core DevOps architect, this role will work alongside architects focused on AI and the Sec Section, collaborating on cross-cutting security challenges while maintaining specialized expertise.

Benefits

  • Benefits supporting health, finances, and well-being
  • Flexible paid time off
  • Team Member Resource Groups
  • Equity Compensation and Employee Stock Purchase Plan
  • Growth and Development Fund
  • Parental Leave

GitLab is an equal opportunity workplace and welcomes candidates with varying levels of experience.

More jobs at GitLab

Similar jobs