SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Salary: USD 168,000 - 238,000 / annual
GitLab is hiring a Staff Product Security Architect to join the Security Platforms and Architecture organization. This is a hands-on technical role focused on embedding proactive security guidance directly into developer workflows and automated coding environments.
In this role, you will partner with engineering and product leadership across GitLab to develop deep context in their domains and anticipate security problems before they occur. You will lead security architecture and design work for strategic initiatives, identify and prioritize systemic security risks, and serve as the Security Owner for high-priority items in the Product Security Risk Register.
Key responsibilities include:
- Partnering with engineering and product leadership to anticipate security problems
- Leading security architecture and design for strategic initiatives
- Identifying, assessing, and prioritizing systemic security risks
- Codifying recurring security decisions into reusable artifacts (guardrails, standards, design patterns, threat models)
- Building proofs of concept and prototypes to unblock engineering teams
- Conducting security architecture reviews for large or strategic projects
- Threat modeling new and existing systems
- Collaborating with Security Research on proactive risk exploration
- Mentoring security engineers and representing security architecture to engineering audiences
You will be part of a team implementing a new organizational model where each architect is dedicated to a specific functional area of GitLab's product. As the Core DevOps architect, you'll collaborate with architects focused on AI and the Sec Section on cross-cutting security challenges.
REQUIREMENTS:
- Depth in application security architecture, including authentication and authorization models, privilege escalation, multi-tenant isolation, and trust boundary analysis
- Experience securing distributed systems, including service-to-service authentication, secrets handling, and failure modes of security decisions across process boundaries
- Working knowledge of software supply chain security: build and release integrity, artifact provenance, and dependency risk
- Track record of proactive architecture work—identifying risk before it becomes an incident and designing solutions that prevent classes of problems
- Demonstrated ability to build trusted relationships with engineering leadership and influence technical direction through expertise
- Experience defining security standards or patterns that teams adopted voluntarily
- Ability to operate strategically while remaining hands-on, including reading unfamiliar code, building prototypes, and contributing changes
- Clear written communication and ability to make security arguments to engineering audiences
- Perspective on how security guidance should be authored and delivered for AI coding tools, not only for humans