freehire launches on Product Hunt on 26 August.

Follow →

Director, Product Security Architect

Summary

Leads product security architecture for SaaS, cloud, and AI solutions, embedding security into design and development while collaborating with cross-functional teams to mitigate risks and establish scalable security standards.

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Director, Product Security Architect based in Canada.

This is a highly technical leadership role focused on embedding security into products from the earliest stages of design and development.
You will shape secure-by-design practices across SaaS products, cloud platforms, and AI-enabled solutions.
The role partners closely with Product, Engineering, Architecture, Cloud Operations, AI, Legal, and Security teams.
You will lead threat modeling, security architecture reviews, and risk analysis for complex modern technologies.
The position combines deep hands-on technical expertise with organizational influence and strategic leadership.
You will help establish scalable security standards, patterns, and governance while reducing architectural risk before production.
Reporting to the VP & Chief Information Security Officer, you will play a highly visible role in advancing product security maturity across the organization.

Accountabilities:

  • Define and execute the Product Security Architecture and Secure-by-Design strategy, roadmap, standards, and reference architectures for cloud-native and AI-enabled products.
  • Partner with Product and Engineering teams to integrate security requirements into development workflows, epics, user stories, and AI software development lifecycle processes.
  • Lead threat modeling and security architecture reviews, producing data flow diagrams, trust boundary analysis, abuse cases, attack paths, security requirements, remediation plans, and residual risk documentation.
  • Assess recurring vulnerabilities, penetration testing results, security incidents, and assessment findings to identify systemic architectural weaknesses and improve security standards.
  • Review distributed systems, microservices, APIs, mobile applications, identity solutions, cloud-native platforms, containers, Kubernetes, serverless environments, and AI-enabled architectures.
  • Translate security risks into practical architectural recommendations and work directly with engineering teams to implement and validate remediation.
  • Establish reusable threat models, secure design patterns, security requirements, and architecture libraries that can be adopted across engineering teams.
  • Conduct security architecture reviews across AWS, Azure, and IBM Cloud environments and define appropriate cloud security guardrails and secure deployment patterns.
  • Partner with AI teams to assess security risks associated with LLM-enabled products, AI development environments, and agentic workflows.
  • Develop security standards, training materials, architecture guidance, and governance practices while communicating risks and recommendations effectively to both technical and executive audiences.
  • Identify opportunities to automate security architecture and design validation and continuously improve secure development processes.
  • Build strong relationships across Product, Engineering, Architecture, Cloud, Security, and Legal teams while influencing risk-based decision-making and security trade-offs.
  • Requirements:

    • 10+ years of information security experience, including substantial hands-on experience in Product Security, Application Security, Security Architecture, or Software Security Engineering.
    • 3+ years of hands-on experience in Application Security Architecture and Threat Modeling.
    • 3–5 years of software development or software engineering experience.
    • Strong knowledge of secure application design, cloud security, modern software architectures, DevSecOps, and secure SDLC practices.
    • Demonstrated experience securing web, API, mobile, cloud-native, and AI-enabled applications.
    • Expertise with threat modeling methodologies such as STRIDE, CAPEC, and MITRE ATT&CK.
    • Practical knowledge of AWS, Azure, or IBM Cloud security architectures.
    • Experience with AI-enabled development environments, LLM security, or agentic architectures is highly relevant.
    • Strong analytical and problem-solving abilities, with the capacity to identify architectural risks and translate them into actionable engineering solutions.
    • Excellent communication and stakeholder management skills, with the ability to influence senior technical and business leaders.
    • Ability to operate effectively in a highly collaborative, cross-functional environment and balance technical depth with pragmatic risk management.
    • Relevant certifications such as ISC2 ISSAP, CISSP, CSSLP, OSCP, or cloud security certifications are considered an asset.
    • Benefits:

      • Estimated annual base salary of $138,200–$181,400 CAD, with actual compensation determined by qualifications, experience, market data, and other job-related factors.
      • Potential additional compensation through bonuses and other applicable incentive programs.
      • Comprehensive medical, dental, and vision coverage tailored to local needs.
      • Paid time off and public holidays.
      • Dedicated volunteer days to support causes and communities that matter to you.
      • Ignite Days dedicated to learning, professional development, and continuous skill growth.
      • Retirement plans designed to support long-term financial security.
      • Tuition assistance for continuing education and professional development.
      • Remote and hybrid work options available across most regions, providing flexibility to work where you thrive.
      • A collaborative and inclusive environment focused on innovation, learning, and meaningful professional growth.
      • Opportunities to influence security strategy across SaaS, cloud, and emerging AI technologies.
      • This posting represents a new vacancy.
How Jobgether works:
We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.
We appreciate your interest and wish you the best!
Why Apply Through Jobgether?
Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.
#LI-CL1

What this application asks

lever

Resume/CV, Full name, Email, Phone, Current location, Current company

See also

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available