Overview
Senior security architect role within GitLab’s Security Platforms and Architecture group. You will drive proactive security guidance embedded into developer workflows, shaping secure design for strategic initiatives. You’ll collaborate with product and engineering leaders, codify reusable guardrails and patterns, and mentor security engineers. The role blends architecture work with hands-on prototyping to accelerate secure delivery at scale.
Pay / Benefits
- Flexible Paid Time Off
- Equity Compensation & Employee Stock Purchase Plan
- Growth and Development Fund
- Parental Leave
- Team Member Resource Groups
Responsibilities
- Lead security architecture and design for strategic initiatives with cross-functional teams
- Act as Security Owner for high-priority items in the Product Security Risk Register and coordinate remediation
- Codify recurring security decisions into reusable guardrails, patterns, and threat models for development/tooling workflows
- Build proofs of concept and prototypes to unblock engineering teams and shorten security-to-implementation distance
- Conduct security architecture reviews for large/strategic projects and ensure proper prioritization with Application Security
- Threat model new and existing systems and establish patterns for teams to threat model their own work
- Mentor security engineers and represent security architecture to engineering audiences
- Collaborate with Security Research on proactive exploration of unknown risks and emerging challenges
- Define and deliver AI-coding tool security guidance for both humans and AI-driven workflows
- Maintain strategic and hands-on balance, reading unfamiliar code and contributing changes
Key requirements
- Depth in application security architecture including authentication/authorization, privilege escalation, multi-tenant isolation, trust boundary analysis
- Experience securing distributed systems and service-to-service authentication
- Knowledge of software supply chain security, build/release integrity, artifact provenance, dependency risk
- Proactive architecture track record—preventive design to avoid incidents
- Ability to influence technical direction through expertise and relationship-building with engineering leadership
- Experience defining security standards or patterns adopted by teams
- Strong written communication and ability to argue security with non-aligned engineering audiences
- Perspective on security guidance for AI coding tools beyond traditional humans
- ability to build trusted relationships with engineering leadership
- excellent communication and influencing skills
- hands-on and strategic thinker
- application security architecture
- authentication and authorization models
- service-to-service authentication
…
