via Smartrecruiters
$176K - 220K a year
Embed security into the software development lifecycle by partnering with engineering teams to ensure secure design, lead threat modeling and architecture reviews, improve security practices, and guide container and cloud-native security efforts.
Significant experience in product application security, secure SDLC, container and cloud-native security, and architecture leadership, with strong communication and ability to influence engineering teams.
Company Description About CyberArk: CyberArk (NASDAQ: CYBR), is the global leader in Identity Security. Centered on privileged access management, CyberArk provides the most comprehensive security offering for any identity – human or machine – across business applications, distributed workforces, hybrid cloud workloads and throughout the DevOps lifecycle. The world’s leading organizations trust CyberArk to help secure their most critical assets. To learn more about CyberArk, visit our CyberArk blogs or follow us on X, LinkedIn or Facebook. Job Description Join our Engineering Security Architecture team as a Senior Product Security Architect and help shape the future of secure product development. In this role, you’ll partner directly with Development and SRE teams to embed security into every stage of the SSDLC—ensuring our cloud-native platform is resilient, scalable, and built with secure architecture at its foundation. If you’re passionate about influencing engineering decisions, guiding secure design, and driving security maturity across R&D, this is your opportunity. What You’ll Do: Embed security throughout the SSDLC • Partner with engineering teams to integrate secure design into microservices, APIs, and distributed systems • Lead threat modeling, secure design reviews, and architecture conversations • Drive secure coding expectations and secure defaults across multiple teams Strengthen engineering practices • Guide teams through OWASP reasoning, protocol-level topics (TLS, mTLS, token flows), and secure design patterns • Improve SSDLC processes, tooling, and CI/CD security • Support architecture reviews and influence long-term technology strategy Container & cloud-native security • Evaluate and help onboard container/K8s security tooling • Provide guidance on runtime risks, image vulnerabilities, supply chain exposure, and K8s posture • Define “what good looks like” for cloud-native workloads Cross-R&D leadership • Build trust quickly with Development, SRE, and Product • Communicate risk clearly and guide engineering tradeoffs • Lead cross-team security initiatives that raise maturity across the organization Additional responsibilities • Deliver training, mentorship, and awareness programs • Support incident response and drive post-incident improvements • Continuously research emerging threats and technologies • Update security policies, standards, and architecture principles as the product evolves #LI-HA1 Qualifications What You Bring We’re looking for someone with significant experience in: Product Application Security • Secure design for microservices and APIs • Threat modeling and vulnerability analysis • Understanding how OWASP categories behave in distributed systems • Strong comfort with code-adjacent conversations (flows, architecture, data paths) Secure SDLC inside engineering • Embedded partnership with dev teams • Experience shaping secure coding patterns, code review workflows, and CI/CD expectations • Ability to balance security with engineering velocity Container / Cloud-Native Security • Familiarity with container/K8s security concepts and tooling • Understanding of workload identity, runtime protections, and image integrity Architecture Leadership • Ability to influence engineering decisions and drive secure architecture across teams • Strong communication skills with developers and engineering leaders Preferred (Not Required) • FedRAMP understanding at the architecture level • Awareness of secure AI/ML development patterns and emerging LLM/ML risks Who Thrives in This Role • Product security architects from SaaS or cloud-native companies • Senior AppSec engineers with strong architecture exposure • Security engineers who have partnered directly with development teams • Staff-level AppSec leads who enjoy influencing and guiding engineering Additional Information CyberArk is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, creed, sex, sexual orientation, gender identity, national origin, disability, or protected Veteran status. We are unable to sponsor or take over sponsorship of employment Visa at this time. The salary range for this position is $176,000 – $220,000/year, plus annual discretionary bonus, which will be based on the employee’s performance, as well as equity Base pay may also vary considerably depending on job-related knowledge, skills, and experience. The compensation package includes a wide range of medical, dental, vision, financial, and other benefits.
This job posting was last updated on 11/26/2025