FREE ACCESS
5,000–10,000 jobs/day
See all jobs on Scoutfield
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.
Tech Stack
Tools & technologiesDistributed Systems
About the role
Key responsibilities & impact- Partner with engineering and product leadership across GitLab to anticipate security problems
- Lead security architecture and design work for strategic initiatives and direct cross-functional delivery teams
- Identify, assess, and prioritize systemic security risks
- Act as Security Owner for high-priority Product Security Risk Register items and co-execute remediation
- Codify security decisions into reusable guardrails, standards, design patterns, skills, and threat models for developer and AI coding workflows
- Build proofs of concept and prototypes to unblock engineering teams
- Conduct security architecture reviews for large or strategic projects
- Coordinate with Application Security to prioritize comprehensive review coverage
- Threat model new and existing systems and establish reusable threat-modeling patterns
- Work with Security Research to explore unknown architectural risks
- Anticipate emerging security challenges and propose architectural responses
- Mentor security engineers and represent security architecture to engineering audiences
Requirements
What you’ll need- Depth in application security architecture, including authentication and authorization models, privilege escalation, multi-tenant isolation, and trust boundary analysis
- Experience securing distributed systems, including service-to-service authentication, secrets handling, and security decisions across process boundaries
- Working knowledge of software supply chain security: build and release integrity, artifact provenance, and dependency risk
- Track record of proactive architecture work identifying risk before incidents and designing preventative solutions
- Ability to build trusted relationships with engineering leadership and influence technical direction through expertise
- Experience defining security standards or patterns adopted by teams
- Ability to operate strategically while remaining hands-on, including reading unfamiliar code, building prototypes, and contributing changes
- Clear written communication and ability to make security arguments to engineering audiences
- Perspective on authoring and delivering security guidance for AI coding tools
- Ability to incorporate AI into daily workflows
Benefits
Comp & perks- Benefits to support your health, finances, and well-being
- Flexible Paid Time Off
- Team Member Resource Groups
- Equity Compensation & Employee Stock Purchase Plan
- Growth and Development Fund
- Parental Leave
