Product Security Architect
Colorwave Inc
Product Security Architect
Replit is the agentic software creation platform that enables anyone to build applications using natural language. With millions of users worldwide, Replit is democratizing software development by removing traditional barriers to application creation.
We are looking for a Product Security Architect to serve as the subject matter expert for Replit's secure product blueprint. In this critical role, you will define and implement the application security architecture for our multi-tenant SaaS platform, ensuring our platform is resilient and secure by design. You will be a key technical contributor—leading high-impact security initiatives and providing deep subject matter expertise to both the engineering organization and executive leadership.
Product Security Strategy & Mentorship
Security Mentorship: Serve as the primary security mentor and subject matter expert for engineering teams, fostering a culture of technical excellence and rigorous security design.
Product Vision: Define the product security vision, ensuring consistency across complex application architecture projects.
Project Execution: Lead the security implementation of new product features from initial design to final production deployment.
Threat Modeling: Conduct proactive threat modeling for new product features and major architectural changes.
Application Security Design: Define and enforce best practices around application security, including audit/application logging, configuration, tenant separation, encryption, customer BYOK, RBAC design, API design, and Session/cookie/token management.
Identity & Access: Define and implement secure Authentication/Authorization protocols (mTLS/OIDC/OAuth/SAML) for multi-tenant SaaS products.
Third-Party Risk: Assess and mitigate risks associated with application third-party integrations such as payment, AI models, code repositories, etc.
Code Review: Apply a strong programming background (Python/Go/JavaScript) to perform hands-on code reviews when needed to validate security controls.
Risk Management & Cross-Functional Enablement
Maintain the Source of Truth: Define and maintain (document) the authoritative "Source of Truth" for Replit's secure architecture, ensuring these patterns are consistently adopted across all engineering teams.
Contribution to Risk Register: Actively identify, document, and quantify architectural security risks. You will be responsible for ensuring these are accurately reflected in the Cybersecurity Risk Register.
Security Team Support: Support other security teams like GRC, Pentesting, Vulnerability Management, and PSIRT.
Compliance & Documentation: Partner with GRC teams to translate complex architectural designs into clear, audit-ready documentation and control frameworks.
GTM & Sales Support: Act as the technical bridge for the Sales team, addressing complex security inquiries from enterprise customers regarding Replit's architectural integrity.
Required Skills & Experience
8+ years of experience in product security engineering or architecture, specifically with Multi-tenant SaaS products.
Experience with AI Agent-based Saas products is a plus.
Deep expertise in common product security practices (e.g., tenant separation, RBAC, BYOK, secure API design, session/token management).
Expertise in Authentication/Authorization protocols (mTLS/OIDC/OAuth/SAML) in a multi-tenant SaaS environment.
Strong programming background (Python/Go/JavaScript) with proven ability to conduct code review.
Experience writing and maintaining Architecture documents.
Exceptional ability to communicate technical risk to both engineering and executive audiences.
Strong track record of contributing to Cybersecurity Risk Register.
What We Value
Systems Thinking: The ability to see the "big picture" and understand how security decisions impact the entire stack.
Technical Influence: The ability to drive technical alignment across the organization through expertise and collaboration rather than direct authority.
Autonomy: Comfortable leading major technical initiatives and driving outcomes with minimal oversight.
Problem-Solving Mindset: A passion for breaking down complex security challenges into elegant, scalable engineering solutions.
This is a full-time role that can be held from our Foster City, CA office. The role has an in-office requirement of Monday, Wednesday, and Friday.
Full-Time Employee Benefits Include:
- Competitive Salary & Equity
- 401(k) Program with a 4% match (US Only)
- Health, Dental, Vision and Life Insurance
- Short Term and Long Term Disability
- Paid Parental, Medical, Caregiver Leave
- Flexible Time Off (FTO) + Holidays
- Commuter Benefits (In-Office Only)
- Monthly Wellness Stipend
- Autonomous Work Environment
- In Office Set-Up Reimbursement (In-Office Only)
- Quarterly Team Gatherings
- In Office Amenities (In-Office Only)
Want to learn more about what we are up to?
- Meet the Replit Agent
- Replit: Make an app for that
- Replit Blog
- Amjad TED Talk
Interviewing + Culture at Replit
- Operating Principles
- Reasons not to work at Replit
To achieve our mission of making programming more accessible around the world, we need our team to be representative of the world. We welcome your unique perspective and experiences in shaping this product. We encourage people from all kinds of backgrounds to apply, including and especially candidates from underrepresented and non-traditional backgrounds.
- RingCentral is seeking an AI Product Engineer based in Belmont, California. This role emphasizes hands-on architecture and product management, focusing on building AI-powered solutions that drive productivity. You will collaborate with various business units to identify...Suggested
- ...Offensive Security Engineer, Product Security at Zoox – Foster City, CA Zoox is seeking an experienced Offensive Security Engineer with deep technical expertise in reviewing and testing Internet of Things (IoT) devices, robots, or autonomous systems. This individual will...Suggested
$137.86k - $250k
...their time - safely creating abundance for all. About the Team The Security Engineering team is responsible for protecting our robots,... ...directly into how we build and operate humanoid robotics systems. The Product Security team focuses on the end-to-end security of NEO itself,...SuggestedTemporary workLocal areaRemote workWork from homeFlexible hours$137.86k - $240k
...Product Security Engineer, Cloud & Infrastructure San Carlos, CA (on-site) About 1X We build humanoid robots that work alongside people... ...device authentication, data protection, and secure communication Architect secure cloud networks through VPC segmentation, traffic...SuggestedLocal area$180k - $235k
...Senior Cloud Security Architect, Security Engineering San Carlos, CA (on-site) About 1X We build humanoid robots that work alongside people... ...and artifact integrity controls Operationalize controls for production access, privileged actions, and break‑glass workflows Continuously...SuggestedLocal area- ...to lead the vulnerability response program for Replit’s cloud-native AI platform. You will own the lifecycle of security vulnerabilities affecting our products and services—from intake to validation, remediation coordination, and public disclosure. This role requires...Full timeTemporary workWork at officeWorldwideMonday to FridayFlexible hours
$200k - $300k
...As the Security Architect , you will be leading all aspects of Software Security for Dexterity's Robotics Product Lines. This is a very visible and "hands-on" role that requires you to write and review code, write and audit policies, and work with auditors, prospects...$127.4k - $182k
Enterprise AI Product EngineerSkip to main content#Enterprise AI Product Engineer page is... ...identify the enterprise AI opportunity, architect the solution, and then build it. This is... ...ensures company data is accessible, secure, and optimized in ways that provide maximum...Full timeLocal areaWork from homeFlexible hours$190k - $230k
...Security isn't just a checkbox at Delight.ai. It's the foundation everything else is built on. If you believe security should accelerate... ...understood and cared for. Not satisfied. Delighted. The Product Delight.ai is the AI concierge for customer experience. Most...Temporary workWork at officeRemote workFlexible hoursShift work3 days per week$293.8k - $343.34k
...shared experiences for everyone. As a Principal Enterprise Security Engineer, you will advance Roblox's Enterprise Security strategy... ...security capabilities that balance risk, compliance, and productivity. You will join the Platform, Enterprise, and Application Security...Full timeWork experience placementH1bWork at officeLocal areaVisa sponsorshipMonday to Friday- ...with code. Customer Success Engineers (CSE) are technical points of contact for JetBrains customers. They work with the JetBrains product teams and customers to ensure that the products meet the needs of our enterprise users, helping our products retain their position...Temporary workWork at officeLocal areaRemote work
$230k - $275k
...centers to serve their customers as fast as possible. Zipline’s security problems aren’t “website got pwned” problems (though those... ...sensitive data, or privileged actions. (Think: “obedient intern with production credentials.”) Industry guidance is converging on practical...InternshipWork at officeLocal area$180k - $235k
...build something that will genuinely change how humans spend their time - safely creating abundance for all. About the Team The Security Engineering team is responsible for building and scaling the security foundations that protect 1X’s people, infrastructure, robotics...Temporary workLocal areaWork from homeFlexible hours- ...in Foster City seeks a skilled Copilot Architect to design and develop AI-powered components... ...The role involves working closely with product owners and stakeholders to deliver... ...in Azure, and a strong understanding of security principles. Collaboration and a proactive...
$203k - $255k
...A leading AI technology company is seeking an AI Solutions Architect to drive the design and deployment of Generative AI and Large Language Model solutions. Responsibilities include enhancing productivity across business functions, managing AI product lifecycles, and consulting...$190k - $265k
...Zoox is seeking an AI Solutions Architect who will be the primary driver for the design... ...powered platforms and tools that enhance productivity across core business functions such as... ...deployments adhere to strict data privacy, security, and "responsible AI" standards....Contract workTemporary workRelocation package$200k - $300k
...sensitive AI-powered platform that includes solutions for video security, access control, air quality sensors, alarms, intercoms, and... ...and information sharing Partner closely with engineering and product teams to improve the security of Verkada’s products and exceed...Full timeWork visaFlexible hoursShift work- A leading IT services company in California is looking for an Info Security Analyst to operationalize security processes and work closely with IT teams. The candidate should have strong operational process expertise and experience in public cloud security solutions like...
- ...A leading security technology firm located in San Mateo seeks Technical Support Engineers to assist enterprise customers with Verkada's cloud-managed security products. This role involves troubleshooting complex technical issues, collaborating with engineering teams, and...Hourly pay
- ...development background. In this role, you will bridge the gap between security, compliance, and engineering teams. You will identify... ...welcome your unique perspective and experiences in shaping this product. We encourage people from all kinds of backgrounds to apply, including...Full timeTemporary workWork at officeImmediate startWorldwideMonday to FridayFlexible hours
- ...company in Foster City, CA is seeking an experienced Offensive Security Engineer to perform security assessments on IoT devices and embedded... ...for IoT security. This role requires collaboration across product, hardware, and software engineering teams. #J-18808-Ljbffr...
- ...Network Security Engineer Our client, a leading organization in autonomous mobility, is seeking a dedicated Network Security Engineer... ...with cross-functional teams such as Information Security, IT, Product, and Operations to enhance security measures. Manage and support...Weekly payTemporary workRemote workFlexible hours
$115k - $140k
...Senior Security Engineer – AI/ML Come work at a place where innovation and teamwork come together to support the most exciting missions... ...Qualys, mentor other engineers, and translate research into production hardening strategies. Key Responsibilities Build and...Flexible hours- ...Vulnerability Management Engineer with a strong background in Cloud Security, DevSecOps, and Infrastructure-as-Code (IaC). In this role,... ...real-time cloud or network countermeasures to protect our production ecosystem. What You'll Do Core Responsibilities Infrastructure...Full timeTemporary workWork at officeImmediate startWorldwideMonday to FridayFlexible hours
$64 - $74 per hour
...JOB TITLE: Network Security Engineer LOCATION: Foster City, CA (Onsite) PAY RANGE: $64 - $74/hr. DURATION: 6 Months TOP... ...4+ years of Network Security Engineer experience supporting production environments 4+ years of IT systems/application engineering...Hourly payFull timeRemote work$180k - $220k
...Security Engineer San Mateo, CA About Us: At Fireworks, we're building the future of generative AI infrastructure. Our platform... ...compliance and regulatory controls into infrastructure and product layers (e.g., SOC 2, ISO 27001, ISO42001, HIPAA, PCI-DSS, GDPR)...$190k - $228k
...Lead performance, load, stress, endurance, and scalability testing initiatives. Collaborate with business stakeholders, product owners, architects, developers, and DevOps teams. Support CI/CD integration and shift‑left testing practices. Establish QA metrics, dashboards...Temporary workRelocation packageShift work- ...role We are looking for a senior-level Offensive Security Engineer to serve as a high-impact "adversary-in-residence... ...depth. Partner with Engineering: Work closely with product teams and security architects to explain root causes, influence design guardrails,...Full timeTemporary workWork at officeWorldwideMonday to FridayFlexible hours
$170.6k - $390k
...Cybersecurity consulting practice – the best place in the world to grow your career in information security! The opportunity The Senior Network Security Architect is a strategic and hands‑on technical leader responsible for designing, implementing, and governing...Summer holidayRemote workFlexible hours$245k - $306.5k
...collaboration, manage the entire content lifecycle, secure critical content, and transform business... ...invoices, employee records, financials, product specs, marketing assets, and more. Our... ...of our Enterprise Security team to help architect and scale the security systems that...Live inWork at officeImmediate startShift work3 days per week
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Product Security Architect. Be the first to apply!

