← Back to list
Job · Principal

Staff Product Security Architect

Security Engineer • Principal • Remote • Full-time • Poland Poland

Hands-on security architecture in GitLab's Security Platforms and Architecture organization: designing for strategic initiatives, driving risk reduction and embedding security patterns into developer and AI coding workflows. Fully remote role.

Stack

Responsibilities

  • ▹Partner with engineering and product leadership across GitLab to anticipate security problems rather than react to them
  • ▹Lead security architecture and design work for strategic initiatives and provide direction to the cross-functional teams delivering them
  • ▹Identify, assess and prioritise systemic security risks, and act as Security Owner for high-priority items in the Product Security Risk Register, co-executing remediation with the teams who own the code
  • ▹Codify recurring security decisions into reusable artifacts (guardrails, standards, design patterns, skills, reference threat models) delivered into developer and AI coding tool workflows
  • ▹Build proofs of concept and prototypes to unblock engineering teams and shorten the distance between a security requirement and a working implementation
  • ▹Conduct security architecture reviews for large or strategic projects, and coordinate with Application Security so review coverage is comprehensive and correctly prioritised
  • ▹Threat model new and existing systems, and establish patterns that let teams threat model their own work
  • ▹Work with Security Research on proactive exploration of unknown risks in GitLab's architecture
  • ▹Anticipate emerging security challenges and propose architectural responses before they reach implementation
  • ▹Mentor security engineers across the division and represent security architecture to engineering audiences

Requirements

  • ▹Depth in application security architecture, including authentication and authorization models, privilege escalation, multi-tenant isolation and trust boundary analysis
  • ▹Experience securing distributed systems, including service-to-service authentication, secrets handling and the failure modes of security decisions made across process boundaries
  • ▹Working knowledge of software supply chain security: build and release integrity, artifact provenance and dependency risk
  • ▹A track record of proactive architecture work: identifying risk before it becomes an incident and designing something that prevents a class of problem rather than an instance
  • ▹Demonstrated ability to build trusted relationships with engineering leadership and influence technical direction through expertise rather than gatekeeping
  • ▹Experience defining security standards or patterns that teams adopted without being compelled to
  • ▹The ability to operate strategically while remaining hands-on, including reading unfamiliar code, building prototypes and contributing changes
  • ▹Clear written communication, and the ability to make a security argument to an engineering audience that does not already agree with it
  • ▹A view on how security guidance should be authored and delivered for AI coding tools, not only for humans

Soft skills

Building trust with engineering leadershipInfluence through expertiseClear written communicationMentoringProactive mindset

What we offer

  • ▹Base salary range for US residents only: USD 168,000 - 238,000
  • ▹Flexible paid time off
  • ▹Team Member Resource Groups
  • ▹Equity compensation and Employee Stock Purchase Plan
  • ▹Growth and Development Fund
  • ▹Parental leave
  • ▹Benefits supporting health, finances and well-being
  • ▹Fully remote work (some roles carry location-based eligibility requirements)

About the company

GitLab is the intelligent orchestration platform for DevSecOps, trusted by more than 50 million registered users and more than half of the Fortune 100. All of its roles are remote, and team members are expected to use AI in their daily workflows.

Similar jobs