A live role

Staff Product Security Architect

from GitLab · read the original and apply on their site

Remote, Canada; Remote, Israel; Remote, Poland; Remote, United Kingdom; Remote, United States

Our take: The real work here is designing security architecture and prototypes that let engineering teams build secure software themselves, driving risk down through trusted influence rather than gates.

If you would rather prevent a whole class of security problems than chase one incident at a time, this is your kind of work. You get to design real architecture, build the prototypes that unblock engineers, and win teams over through expertise instead of gatekeeping, all fully remote. It suits someone who loves being both strategic and hands-on, and who cares that security shows up naturally in developer and AI coding workflows rather than as a manual gate.

Needs

  • security architecture design
  • prototyping proofs of concept
  • threat modelling
  • reading unfamiliar code
  • quiet influence
  • persuading skeptics
  • clear writing

Rewards

  • catching risk early
  • setting direction
  • mentoring engineers
  • preventing whole problem classes
  • visible working impact

Demands

  • operating strategically hands-on
  • anticipating problems early
  • building trust
  • owning risk outcomes
  • ruthless prioritising

Grows

  • new product domains
  • presenting to engineers
  • teaching teams to self-serve
  • proactive risk research

Values

  • expertise over gatekeeping
  • pragmatic velocity
  • mission driven security
  • learning culture
  • remote working
  • long-term thinking

Drains

  • cross-team coordination
  • risk register upkeep
  • review coverage grind

Would you love this work?

See how what you love doing lines up with this role - it takes about ten minutes to find out.

Find what I'd love to do next