Posted on: 24/07/2026
We are seeking a highly experienced Senior Product Security Architect who will be responsible for embedding security into the entire product lifecycle, from design to deployment while enabling secure innovation at scale.
Key Responsibilities:
1. Security Architecture & Strategy:
- Define and implement product security architecture frameworks and standards.
- Integrate Security-by-Design and Privacy-by-Design principles into all products.
- Establish a long-term product security roadmap aligned with business strategy.
- Lead threat modeling and risk assessments for critical products and platforms.
- Provide architectural guidance for: 1. Cloud-native applications 2. Microservices and APIs 3. SaaS and enterprise platforms.
- Drive adoption of security frameworks including: 1. NIST Secure Software Development Framework (SSDF) NIST SP 800-218 2. OWASP SAMM (Software Assurance Maturity Model).
2. Secure SDLC (Software Development Lifecycle):
- Design and implement a Secure SDLC (SSDLC) framework across teams.
- Embed security controls across: 1. Design 2. Development 3. Testing 4. Deployment.
- Define and enforce: 1. Secure coding standards 2. Secure coding practices 3. DevSecOps integration.
- Ensure adoption of: 1. SAST (Static Application Security Testing) 2. DAST (Dynamic Application Security Testing) 3. SCA (Software Composition Analysis) 4. Penetration Testing frameworks.
- Establish security maturity metrics and SSDLC governance aligned with NIST SSDF and OWASP SAMM.
3. Engineering & DevSecOps Enablement:
- Partner with engineering teams to shift security left.
- Drive adoption of DevSecOps practices and automation.
- Enable teams through: 1. Security training and awareness 2. Secure coding guidelines 3. Architecture reviews.
- Implement and govern CI/CD security controls and secure pipeline configurations.
- Act as a trusted advisor to engineering leadership.
4. Vulnerability & Risk Management:
- Oversee application and product vulnerability management lifecycle.
- Define prioritization frameworks based on: 1. Risk severity 2. Business impact.
- Drive remediation programs and SLAs.
- Conduct: 1. Penetration testing reviews 2. Security assessments.
- Interpret and prioritize findings from SAST, DAST, SCA, and penetration testing activities.
5. Cloud & Infrastructure Security:
- Provide security architecture for: 1. AWS / Azure / GCP environments 2. Container security (Docker, Kubernetes).
- Define controls for: 1. Identity & Access Management (IAM) 2. Data protection (encryption, key management) 3. Network security.
6. Regulatory Compliance & Governance:
- Ensure compliance with industry standards: 1. ISO 27001 2. SOC 2 3. GDPR and Data Privacy regulations.
- Implement audit-ready processes and controls.
- Partner with risk teams for: 1. Security audits 2. Compliance assessments.
7. Leadership & Stakeholder Management:
- Lead and mentor a team of Product Security Engineers and Architects.
- Collaborate with: 1. Engineering leadership 2. Product management 3. Cybersecurity teams 4. External vendors and partners.
- Influence senior stakeholders on: 1. Security investments 2. Risk posture 3. Strategic priorities.
8. Incident Readiness & Response:
- Support security incident handling related to product vulnerabilities.
- Define incident response playbooks for product security risks.
- Conduct post-incident reviews and improve controls.
Experience:
- 1218+ years of experience in: 1. Application Security 2. Product Security 3. Security Architecture 4. DevSecOps.
- Proven experience in a leadership role (Senior Manager / Architect level).
- Hands-on expertise in: 1. Secure application design 2. Threat modeling 3. Security architecture 4. Secure SDLC implementation.
Technical Skills:
- Strong knowledge of: 1. OWASP Top 10 2. Secure coding standards 3. API security 4. NIST Secure Software Development Framework (SSDF) SP 800-218 5. OWASP SAMM (Software Assurance Maturity Model).
- Experience with: 1. Cloud security (AWS / Azure / GCP) 2. Container and Kubernetes security 3. CI/CD pipelines and DevOps tools 4. Implementation of CI/CD security controls and secure pipeline configurations 5. DevSecOps frameworks and automation.
- Strong understanding of: 1. SAST (Static Application Security Testing) 2. DAST (Dynamic Application Security Testing) 3. SCA (Software Composition Analysis) 4. Penetration Testing methodologies and frameworks 5. Security testing and vulnerability remediation workflows.
- Familiarity with: 1. SIEM and monitoring tools 2. Security orchestration and automation tools.
Certifications (Preferred):
- CISSP (Certified Information Systems Security Professional)
- CSSLP (Certified Secure Software Lifecycle Professional)
- CISM / CISA
- AWS Security Specialty
- Microsoft Azure Security Engineer
- Relevant DevSecOps or Cloud Security certifications.
Leadership Competencies:
- Strategic thinking with strong execution focus.
- Ability to influence without authority.
- Strong stakeholder management at the leadership level.
- Problem-solving and risk-based decision making.
- Ability to translate technical risks into business impact.
- Strong communication and executive presentation skills.
Success Metrics (KPIs):
- Reduction in critical vulnerabilities across products.
- Adoption rate of Secure SDLC practices.
- Improvement in security posture and audit outcomes.
- Reduction in time-to-remediation.
- Increased awareness and secure coding adoption across teams.
- Improvement in SSDLC maturity and DevSecOps adoption.
Did you find something suspicious?
Posted by
Posted in
CyberSecurity
Functional Area
IT Security
Job Code
1657586