Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy, and consent to receive emails from Rise
Jobs / Job page
Product Security Lead Architect image - Rise Careers
Job details

Product Security Lead Architect

Job Description

As the Product Security Lead Architect, you will play a pivotal role in shaping the security landscape of our organization. Your primary responsibilities will include:

  • Designing Security Controls: Lead the design and implementation of innovative and robust security controls across various domains (Cloud, AI, DevSecOps,...), ensuring alignment with industry best practices and regulatory requirements

  • Collaborating with Cross-Functional Teams: Work closely with engineering, product management, IT, and other relevant teams to integrate security controls seamlessly into existing and new systems

  • Conducting Security Assessments: Perform security assessments and threat modeling to identify potential vulnerabilities and recommend appropriate mitigation strategies

  • Developing Security Architectures & Patterns: Create and maintain comprehensive security architectures that address the unique needs of different projects and initiatives

  • Providing Technical Guidance: Serve as a subject matter expert, offering technical guidance and support to engineering teams during the development and deployment of security solutions

  • Mentoring and Leadership: Mentor junior team members, fostering a culture of continuous learning and professional development within the security design team

We are looking for a passionate and skilled security professional with demonstrated experience in at least one of the following domains:

Cloud Security

  • Hands-on experience with securing workloads and architectures in AWS, Azure, or Google Cloud Platform (GCP)

  • Familiarity with native cloud security controls and cloud governance frameworks

DevSecOps & Secure Software Development

  • Practical experience integrating security into the DevOps lifecycle

  • Infrastructure as Code (IaC) scanning and policy enforcement (e.g., Terraform, CloudFormation)

  • Secure CI/CD pipeline design

  • Use of SAST (Static Application Security Testing) and DAST (Dynamic Application Security Testing) tools

  • Integration of security gates into the Secure Software Development Lifecycle (SSDLC)

AI/ML Security

  • Understanding of AI/ML security risks such as:

  • Model poisoning, adversarial inputs, data leakage, and model theft

  • Experience securing ML pipelines, training data governance, or runtime protection

  • Familiarity with AI Security Posture Management (AI-SPM) or relevant AI risk frameworks (e.g., NIST AI RMF, EU AI Act)

Identity and Access Management (IAM)

  • Knowledge of identity governance, authentication, authorization, role-based access control (RBAC), and federated identity systems (e.g., SAML, OAuth, OIDC)

Data Security

  • Understanding of data classification, data loss prevention (DLP), encryption at rest/in transit, and secure data storage

  • Experience implementing access controls, tokenization, and data protection in cloud-native environments

On top of that, we also expect you to match following boxes:

  • Fast learner with the ability to grasp new security domains and emerging technologies

  • Skilled in translating complex technical concepts for diverse audiences, including stakeholders and leadership

  • Proven ability to design security solutions and guide implementation by engineering teams

  • Strong interpersonal and collaboration skills across global and cross-functional teams

  • Demonstrated passion for continuous learning and driving product security maturity

Preferred Experience and Skills

  • Solid understanding of the OWASP Top Ten and best-practice mitigations (e.g., XSS, SQLi, CSRF).

  • Familiarity with Agile methodologies and secure development practices in iterative environments.

  • Experience implementing secrets management, key management, and cryptographic controls following industry standards (e.g., NIST, ISO).

  • Awareness of containerization technologies (Docker, Kubernetes) and associated security risks and hardening techniques.

  • Working knowledge of networking and web technologies (e.g., TCP/IP, HTTP/HTTPS, TLS, DNS, SSH, REST APIs).

  • Ability to read and understand code in one or more languages (e.g., Python, Java, JavaScript, .NET) and apply secure coding principles.

Our Offer

The primary location is Czechia, benefits in the US may vary.

  • Exciting work in a great team, global projects, international environment

  • Opportunity to learn and grow professionally within the company globally

  • Hybrid working model, flexible role pattern

  • Pension and health insurance contributions

  • Internal reward system plus referral program

  • 5 weeks annual leave, 5 sick days, 15 days of certified sick leave paid above statutory requirements annually, 40 paid hours annually for volunteering activities, 12 weeks of parental contribution

  • Cafeteria for tax free benefits according to your choice (meal vouchers, Lítačka, sport, culture, health, travel, etc.), Multisport Card

  • Vodafone, Raiffeisen Bank, Foodora, and Mall.cz discount programs

  • Up-to-date laptop and iPhone

  • Parking in the garage for drivers or showers for bikers

  • Competitive salary, incentive pay, and many more


Ready to take up the challenge? Apply now!
Know anybody who might be interested? Refer this job!

Current Employees apply HERE

Current Contingent Workers apply HERE

Search Firm Representatives Please Read Carefully 
Merck & Co., Inc., Rahway, NJ, USA, also known as Merck Sharp & Dohme LLC, Rahway, NJ, USA, does not accept unsolicited assistance from search firms for employment opportunities. All CVs / resumes submitted by search firms to any employee at our company without a valid written search agreement in place for this position will be deemed the sole property of our company.  No fee will be paid in the event a candidate is hired by our company as a result of an agency referral where no pre-existing agreement is in place. Where agency agreements are in place, introductions are position specific. Please, no phone calls or emails. 

Employee Status:

Regular

Relocation:

VISA Sponsorship:

Travel Requirements:

Flexible Work Arrangements:

Remote

Shift:

Valid Driving License:

Hazardous Material(s):

Required Skills:

Agile Application Development, Agile Methodology, AWS Architecture, Business, Cloud Governance, Data Loss Prevention (DLP), Design Applications, Dynamic Application Security Testing (DAST), Information Security, Kubernetes, Management Process, OWASP Top 10, Python (Programming Language), Role Based Access Control (RBAC), Security Operations, Security Solutions, SLA Management, Social Collaboration, Software Development, Software Development Life Cycle (SDLC), System Designs, Technical Advice, Vulnerability Scanning

 Preferred Skills:

Job Posting End Date:

07/3/2025

*A job posting is effective until 11:59:59PM on the day BEFORE the listed job posting end date. Please ensure you apply to a job posting no later than the day BEFORE the job posting end date.

Average salary estimate

$155000 / YEARLY (est.)
min
max
$130000K
$180000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

Similar Jobs
Photo of the Rise User
Posted 7 days ago

Seeking a ServiceNow Lead/Architect for a New York-based W2 contract role to lead and mentor teams while driving platform enhancements and integrations.

Kraft Heinz is looking for an experienced Associate Manager, IT Field Services to deliver premium IT support to VIPs and Administrators at their Chicago location.

Photo of the Rise User
Mattel Hybrid 333 Continental Blvd, El Segundo, CALIFORNIA
Posted 11 days ago
Inclusive & Diverse
Empathetic
Collaboration over Competition
Growth & Learning

Become a key leader at Mattel as the Director of Enterprise Architecture and Integration, driving innovation and transformation in our technology landscape.

Photo of the Rise User

As an IT Asset Management Specialist at HRL, you will play a crucial role in the management and lifecycle of IT assets within the organization.

Photo of the Rise User
Posted 7 days ago

Innovative media company Vox Media seeks an Infrastructure Engineer skilled in network and systems administration to enhance their IT infrastructure in New York.

Photo of the Rise User

Serve as the strategic liaison between business units and IT at MacDonald-Miller Facility Solutions, driving technology investments that support organizational success and innovation.

Photo of the Rise User

We are seeking a Windows Systems Administrator II with an active Secret clearance and a passion for systems administration in a classified environment.

Photo of the Rise User
a16z Hybrid Menlo Park, California, United States
Posted 2 days ago

a16z is seeking a Cybersecurity Software Engineer Partner to build scalable, AI-driven security solutions and enhance security posture across cloud and developer environments at their Menlo Park office.

Photo of the Rise User
Inclusive & Diverse
Empathetic
Collaboration over Competition
Growth & Learning
Transparent & Candid
Medical Insurance
Dental Insurance
Mental Health Resources
Life insurance
Disability Insurance
Child Care stipend
Employee Resource Groups
Learning & Development

Join American Express as a Senior Information Security Analyst, where you'll lead incident response efforts to protect a trusted global brand.

Photo of the Rise User
Posted 10 days ago

Experienced ServiceNow Engineer needed to configure, develop, and support a FedRAMP High SaaS solution for a leading national security integrator.

Photo of the Rise User
Camunda Hybrid No location specified
Posted 4 days ago

Camunda is seeking a Senior InfoSec GRC Analyst to lead governance, risk, and compliance initiatives in a fully remote, fast-paced global team.

Photo of the Rise User
Posted 11 days ago

AbbVie is searching for a Senior Engineer in IT Automation to lead advanced digital solutions for their Bioresearch Center operations.

Photo of the Rise User

Lead the SAP COE Application Development and Maintenance team at Cardinal Health to ensure robust management of SAP S/4HANA operations supporting critical business processes.

Our purpose: We use the power of leading-edge science to save and improve lives around the world

45 jobs
MATCH
Calculating your matching score...
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, hybrid
DATE POSTED
June 26, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!