About the role
Position Summary
The Architect, Product Security partners with product and engineering teams to design and deliver secure applications, APIs, and digital services. This role embeds security into product design and development by providing hands-on guidance, conducting threat modeling, and helping teams implement secure-by-design practices across the SDLC. The Architect operates as a hands-on security partner to product teams. The role focuses on secure-by-design principles, practical risk reduction, and enabling delivery teams to build resilient, scalable, and secure products without unnecessary friction.
Essential Responsibilities
Define and implement security architecture patterns for applications, APIs, cloud services, and platforms
Develop secure design standards, reference architectures, and reusable patterns
Ensure alignment with enterprise architecture and security strategy
Embed security controls into Continuous Integration/Continuous Deployment pipelines and developer workflows
Define and enforce secure coding practices and product security requirements
Enable automation of security testing and validation (Static Application Security Testing, Dynamic Application Security Testing, Secure Code Analysis)
Conduct and facilitate threat modeling sessions across product teams
Identify architectural risks and define practical mitigation strategies
Translate enterprise risk posture into product-level decisions and tradeoffs
Define and guide application security testing strategies
Partner with engineering teams to prioritize and remediate vulnerabilities
Support penetration testing and security validation activities
Architect controls for Authentication, Data protection and service security
Support adoption of Zero Trust principles
Partner with: Product Managers, Software Engineers, Platform and Cloud teams
Other duties as assigned
Minimum Experience and Qualifications
Bachelor’s Degree in a relevant field; OR demonstrated capability to perform job responsibilities with a High School Diploma/GED and at least four (4) years of previous relevant work experience
Four (4) years of experience in Application security, product security, or security a…