
Senior Product Security Architect
Early Warning Services2 hours ago
Tokyo, JapanSenior
Base Salary
$160k - $240k/yr
Responsibilities
- Identify, measure, control, and minimize security risks across application, host, network, operating-system, and database environments.
- Develop threat models, security architectures, reference architectures, and reusable security patterns for products.
- Review product business cases, functional designs, technical architectures, and changes for security compliance and risk.
- Partner with Product Development and Engineering to perform security analysis on internally developed products and services.
- Scope and manage product penetration testing with internal and external testing organizations.
- Advise customer banks on security requirements, penetration-test findings, mitigating controls, and remediation projects.
- Drive cloud-native and microservices security practices and integrate security controls into development pipelines.
- Support security incident response, policy and procedure development, risk documentation, and mitigation tracking.
- Lead product security efforts and mentor others while serving as the security point of contact for assigned areas.
Requirements
- Bachelor’s degree in Computer Science, Engineering, Math, or Physical Science.
- Typically 10 or more years of engineering, IT, or information security experience, including a combined six years in application security, security architecture, consulting, or related information security work.
- Advanced knowledge of relational databases, Windows, Linux, operating-system security, application security, network security, and database security architectures.
- Application development or software security background and experience with threat modeling, control design, cloud-hosted products, and security architecture.
- Experience integrating security into development pipelines and analyzing technical issues to recommend corrective actions.
- Advanced understanding of information security concepts, vulnerability exploitation chaining, and security architecture.
- Preferred certifications include CEH/CPT, CISSP, CSSLP, GWEB, Secure Development Certification, CISA, or related credentials.
- Preferred experience includes GCP, AWS, Azure, Kubernetes, VMware, OpenStack, cryptography, authentication, authorization, DevOps automation, security frameworks, SAST tools, composition analysis, and BSIMM.
Benefits
- Hybrid work model for positions in Scottsdale, San Francisco, Chicago, or New York.
- Medical, dental, and vision coverage, with HSA contributions and flexible spending accounts.
- 401(k) plan with a 100% company safe-harbor match on the first 6% deferred, immediately upon eligibility.
- Flexible Time Off for exempt employees or generous PTO for non-exempt employees, plus 11 paid holidays and a paid volunteer day.
- 12 weeks of paid parental leave and Maven Family Planning support.
- Normal office environment with primarily sedentary computer work and occasional standing, walking, kneeling, and reaching.