Required Senior Product Security Architect
As a Product Security Architect, you will shape how security is built, not just review it. Youll work closely with engineering to influence architecture, guide design decisions, and ensure security is embedded across our platform from the earliest stages where decisions matter most, not just where they are validated. Youll take on complex, real-world challenges across cloud-native systems and AI-driven features, where security must evolve alongside scale and speed. This role is not about checklists or gatekeeping, but about applying strong technical judgment, making pragmatic trade-offs, and enabling teams to build secure systems by design. If youre looking to have a meaningful impact on a real product, collaborate with high-caliber engineering teams, and help define modern product security at scale, youll find this role both challenging and rewarding.
What Makes This Role Unique
A product where security decisions truly matter - processes and analyzes highly sensitive customer conversations at scale, creating unique challenges around data protection, privacy, and trust.
AI is core to the product, not a side project - Youll work in an environment where AI/ML is deeply embedded, addressing real-world security challenges that go beyond traditional application security.
A platform operating at a meaningful scale - Youll deal with high-volume data, distributed systems, and production environments where security decisions have immediate and visible impact.
The opportunity to shape a growing security domain - Product security is still evolving, giving you the ability to influence direction, introduce new ideas, and build things the right way.
A culture that values practical, engineering-driven security - Security is approached with a focus on real risk and practical solutions, not just compliance or process.
High ownership with room to grow - Youll have the autonomy to take initiative, drive changes, and expand your impact as the company and platfWhat Youll Do
Shape security architecture where it matters most, partner with engineers early in the design phase to influence system architecture, define secure patterns, and make critical decisions before code is written
Work hands-on with engineering teams to secure real systems review designs, dive into code and PRs when needed, and build small tools or proofs-of-concept to validate security assumptions
Lead threat modeling and deep design reviews identify trust boundaries, abuse cases, and high-impact attack paths, and ensure controls hold up in real production environments
Own security design for authentication, authorization, and APIs, including identity flows (OAuth/OIDC), session management, and multi-tenant access control.
Requirements: 8+ years of experience in Product Security, Application Security, or Security Architecture
Strong software engineering foundation with the ability to read code (e.g., Java, Python, JavaScript/TypeScript, React or similar), review PRs, and understand systems end-to-end.
Deep understanding of application security principles (OWASP Top 10, secure design, common vulnerability classes)
Experience securing cloud-native SaaS environments (AWS, GCP, and/or Azure), including containers and Kubernetes
Strong knowledge of authentication and authorization systems, including OAuth2, OIDC, SAML, and secure API design
Hands-on experience integrating security into CI/CD pipelines and developer workflows (SAST, DAST, SCA, secrets, IaC scanning)
Experience with threat modeling and risk assessment methodologies
Ability to analyze vulnerabilities end-to-end from code to architecture to production impact
Strong communication skills and ability to influence engineering decisions without authority
Additional strengths:
Ability to work closely with developers and influence engineering decisions
Strong communication skills with both technical and business stakeholders.
This position is open to all candidates.