Product Security Architect
Remote • Foster City, CA • FullTime
Posted 2mo ago
Remote Work Policy
Fully remote
Employment Type
FullTime
Categories
Applied AI Engineer
About the job
Replit is seeking a Product Security Architect to be the subject matter expert for the company's secure product blueprint. This role involves defining and implementing the application security architecture for a multi-tenant SaaS platform, ensuring resilience and security by design. The architect will be a key technical contributor, leading high-impact security initiatives and providing expertise to engineering teams and executive leadership. The position focuses on defining the product security vision, leading security implementation for new features, conducting threat modeling, and enforcing application security best practices.
Responsibilities
- Serve as the primary security mentor and subject matter expert for engineering teams.
- Define the product security vision and ensure consistency across application architecture projects.
- Lead the security implementation of new product features from design to production.
- Conduct proactive threat modeling for new product features and architectural changes.
- Define and enforce application security best practices, including logging, configuration, tenant separation, encryption, BYOK, RBAC, API design, and session/cookie/token management.
- Define and implement secure Authentication/Authorization protocols (mTLS/OIDC/OAuth/SAML) for multi-tenant SaaS products.
- Assess and mitigate risks associated with third-party application integrations.
- Perform hands-on code reviews using Python/Go/JavaScript to validate security controls.
- Define and maintain the authoritative "Source of Truth" for Replit’s secure architecture.
- Identify, document, and quantify architectural security risks for the Cybersecurity Risk Register.
- Support other security teams such as GRC, Pentesting, Vulnerability Management, and PSIRT.
- Translate complex architectural designs into clear, audit-ready documentation and control frameworks.
- Act as a technical bridge for the Sales team to address complex security inquiries from enterprise customers.
Requirements
- 8+ years of experience in product security engineering or architecture, specifically with Multi-tenant SaaS products.
- Experience with AI Agent-based SaaS products is a plus.
- Deep expertise in common product security practices (e.g., tenant separation, RBAC, BYOK, secure API design, session/token management).
- Expertise in Authentication/Authorization protocols (mTLS/OIDC/OAuth/SAML) in a multi-tenant SaaS environment.
- Strong programming background (Python/Go/JavaScript) with proven ability to conduct code review.
- Experience writing and maintaining Architecture documents.
- Exceptional ability to communicate technical risk to both engineering and executive audiences.
- Strong track record of contributing to Cybersecurity Risk Register.
- Systems Thinking: Ability to see the "big picture" and understand how security decisions impact the entire stack.
- Technical Influence: Ability to drive technical alignment across the organization through expertise and collaboration.
- Autonomy: Comfortable leading major technical initiatives and driving outcomes with minimal oversight.
- Problem-Solving Mindset: Passion for breaking down complex security challenges into elegant, scalable engineering solutions.
Benefits
- Competitive Salary & Equity
- 401(k) Program with a 4% match (US Only)
- Health, Dental, Vision and Life Insurance
- Short Term and Long Term Disability
- Paid Parental, Medical, Caregiver Leave
- Flexible Time Off (FTO) + Holidays
- Commuter Benefits (In-Office Only)
- Monthly Wellness Stipend
- Autonomous Work Environment
- In Office Set-Up Reimbursement (In-Office Only)
- Quarterly Team Gatherings
- In Office Amenities (In-Office Only)