> Markdown version of [/jobs/ext/480283-product-security-architect](https://www.wearedevelopers.com/jobs/ext/480283-product-security-architect). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Product Security Architect - **Company:** BeyondTrust Corporation - **Location:** United States (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Adobe InDesign, Application Programming Interfaces (APIs), Artificial Intelligence, Amazon Web Services, Microsoft Azure, Software as a Service, Cloud Computing, Cloud Computing Security, Cyber Security, Programming Tools, Systems Development Life Cycle, Large Language Models, Software Security, Kubernetes, Automation Anywhere, Serverless Computing, Vulnerability Analysis - **Published:** June 3, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=45304419dcce3c8f ## About the Role Do you have experience in Tooling?, * 7+ years in Product Security, Application Security, Security Architecture, or Software Security Engineering * Deep, practical experience with threat modeling, attack surface analysis, secure design reviews, and architecture risk analysis at scale, not just in theory * Strong understanding of cloud-native systems, APIs, endpoint agents, thick clients, and identity/security platforms * Hands-on experience using LLM platforms (Claude, OpenAI, or similar) in engineering or security workflows. We'll ask you how you've used them and what you've learned about where they work and where they don't * Ability to influence engineering and product teams. You should not have a mindset to block releases but to be persuasive, credible, and practical * Builder mindset, you've created scalable security workflows, frameworks, or enablement programs, not just consumed them * Experience building AI-native security workflows, plugins, agents, or developer tooling * Background in securing endpoint technologies, identity systems, or enterprise security platforms * Offensive security experience or adversarial testing background, understanding how attackers think sharpens everything else * Cloud security experience across AWS, Azure, or Kubernetes environments How We'll Measure Success * Measurable reduction in product attack surface and recurring architecture risks and not findings produced, but risk eliminated. * Increased scale and consistency of secure design reviews through AI-first workflows * Faster identification and remediation of design-level and architecture-level risks * Engineering teams actively using self-service security capabilities you've built * Expansion of AI-first Product Security Architecture capabilities across the SDLC ## Description We're hiring a Product Security Architect to join a team that operates AI-first. We don't mean we're planning to adopt AI or "exploring" it; we mean Claude and LLM-driven workflows are how we do threat modeling, secure design reviews, vulnerability analysis, and developer enablement today. This role is for someone who can walk in and operate at that level from day one, then help us push further. You'll work across BeyondTrust's product suite, including endpoint agents, thick clients, SaaS platforms, APIs, identity systems, and cloud-native services, partnering directly with engineering, architecture, and product management to find and eliminate architectural risk before it ships. What You'll Do * Threat Modeling & Attack Surface Reduction Lead threat modeling, attack surface analysis, and secure design reviews across products, platform services, endpoint agents, and cloud-native systems. The goal isn't producing threat model documents but recommending architectural decisions that eliminate unnecessary exposure and working with engineering to change them. * AI-Native Security Engineering Use LLM platforms (Claude, OpenAI) as core tools to scale threat analysis, abuse-case generation, architecture review, and remediation guidance. Build and refine prompts, plugins, skills, and agent workflows that make the team faster and more consistent. You'll be extending an existing AI-first practice, not building one from scratch. * Engineering Partnership Work directly with engineering teams to embed secure-by-default patterns into product development. This means being present in design reviews, proposing concrete alternatives when you identify risk, and building self-service security capabilities (playbooks, reusable patterns, automated workflows) that let engineers make secure decisions without waiting on us. * Standards & Knowledge Own and expand the Product Security handbook that inferences product context from multiple sources and leverage it for enforcing secure design standards, architecture guidance, and engineering best practices. The handbook is a living system that feeds our AI workflows, not a static wiki nobody reads. * Mentorship Mentor Product Security Engineers and Security Champions on secure design, attack surface reduction, and AI-first security workflows. Help engineers across the org develop a security-focused mindset, not just follow checklists. * Strategy Help evolve BeyondTrust's AI-first Product Security Architecture strategy by identifying where AI workflows can replace manual processes, where they need human oversight, and where the next capability gaps are. ## Related Videos - [Why Security-First Development Helps You Ship Better Software Faster](https://www.wearedevelopers.com/videos/1568-why-security-first-development-helps-you-ship-better-software-faster) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Understanding Kubernetes in a visual way](https://www.wearedevelopers.com/videos/100085-understanding-kubernetes-in-a-visual-way) - [Automated Security for the Entire SDLC](https://www.wearedevelopers.com/videos/100323-automated-security-for-the-entire-sdlc) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Instant KAI Sandboxes with vCluster: Multi-Tenant, Multi-Scheduler GPU Sharing](https://www.wearedevelopers.com/videos/100333-instant-kai-sandboxes-with-vcluster-multi-tenant-multi-scheduler-gpu-sharing) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Now is the time for industrialized software development](https://www.wearedevelopers.com/magazine/601-now-is-the-time-for-industrialized-software-development) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Navigating the AI Shift](https://www.wearedevelopers.com/magazine/629-navigating-the-ai-shift)