Join our Engineering Security Architecture team as a Senior Product Security Architect and help shape the future of secure product this role youll partner directly with Development and SRE teams to embed security into every stage of the SSDLCensuring our cloud-native platform is resilient scalable and built with secure architecture at its foundation.
If youre passionate about influencing engineering decisions guiding secure design and driving security maturity across R&D this is your opportunity.
What Youll Do:
Embed security throughout the SSDLC
Partner with engineering teams to integrate secure design into microservices APIs and distributed systems
Lead threat modeling secure design reviews and architecture conversations
Drive secure coding expectations and secure defaults across multiple teams
Strengthen engineering practices
Guide teams through OWASP reasoning protocol-level topics (TLS mTLS token flows) and secure design patterns
Improve SSDLC processes tooling and CI/CD security
Support architecture reviews and influence long-term technology strategy
Container & cloud-native security
Evaluate and help onboard container/K8s security tooling
Provide guidance on runtime risks image vulnerabilities supply chain exposure and K8s posture
Define what good looks like for cloud-native workloads
Cross-R&D leadership
Build trust quickly with Development SRE and Product
Communicate risk clearly and guide engineering tradeoffs
Lead cross-team security initiatives that raise maturity across the organization
Additional responsibilities
Deliver training mentorship and awareness programs
Support incident response and drive post-incident improvements
Continuously research emerging threats and technologies
Update security policies standards and architecture principles as the product evolves
#LI-HA1
Qualifications :
What You Bring
Were looking for someone with significant experience in:
Product Application Security
Secure design for microservices and APIs
Threat modeling and vulnerability analysis
Understanding how OWASP categories behave in distributed systems
Strong comfort with code-adjacent conversations (flows architecture data paths)
Secure SDLC inside engineering
Embedded partnership with dev teams
Experience shaping secure coding patterns code review workflows and CI/CD expectations
Ability to balance security with engineering velocity
Container / Cloud-Native Security
Familiarity with container/K8s security concepts and tooling
Understanding of workload identity runtime protections and image integrity
Architecture Leadership
Ability to influence engineering decisions and drive secure architecture across teams
Strong communication skills with developers and engineering leaders
Preferred (Not Required)
FedRAMP understanding at the architecture level
Awareness of secure AI/ML development patterns and emerging LLM/ML risks
Who Thrives in This Role
Product security architects from SaaS or cloud-native companies
Senior AppSec engineers with strong architecture exposure
Security engineers who have partnered directly with development teams
Staff-level AppSec leads who enjoy influencing and guiding engineering
Additional Information :
CyberArk is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race color religion creed sex sexual orientation gender identity national origin disability or protected Veteran status.
We are unable to sponsor or take over sponsorship of employment Visa at this time.
The salary range for this position is $176000 $220000/year plus annual discretionary bonus which will be based on the employees performance as well as equity Base pay may also vary considerably depending on job-related knowledge skills and experience. The compensation package includes a wide range of medical dental vision financial and other benefits.
Remote Work :
Yes
Employment Type :
Full-time
CyberArk (NASDAQ: CYBR), is the global leader in Identity Security. Centered on privileged access management, CyberArk provides the most comprehensive security offering for any identity human or machine across business applications, distributed workforces, hybrid cloud workloads a ... View more