VP, Product Security Architecture
Listed on 2026-09-16
-
IT/Tech
Cybersecurity, Information Security & Data Protection, Security Management & Operations, Systems Engineer
Role Summary/Purpose
Synchrony is seeking a VP, Product Security Architect to provide enterprise-level product security architecture leadership across Synchrony’s application and SaaS ecosystem. This role operates at L13 scope—setting direction, defining standards, and driving adoption at scale—while partnering closely with product and engineering leaders to embed security into product strategy and modern software delivery.
Role Summary/PurposeSynchrony is seeking a VP, Product Security Architect to provide enterprise-level product security architecture leadership across Synchrony’s application and SaaS ecosystem. This role operates at L13 scope—setting direction, defining standards, and driving adoption at scale—while partnering closely with product and engineering leaders to embed security into product strategy and modern software delivery.
The VP will lead the definition of an Application Security Blueprint (reference architectures, approved patterns, and engineering guardrails) and will influence outcomes across multiple portfolios by enabling teams to design and deliver software that is secure-by-design, resilient, and compliant.
Essential Responsibilities- Provide executive leadership for the Product Security Architecture function, establishing the strategic vision, operating model, and multi-year roadmap for application and product security across the enterprise.
- Set product security architecture direction for assigned portfolios, aligning security architecture decisions with Synchrony technology strategy, risk appetite, and regulatory expectations.
- Own and evolve the Application Security Blueprint: enterprise application security standards, reference architectures, reusable patterns, and guardrails that enable consistent secure engineering across teams.
- Serve as a strategic partner to product and engineering leadership, influencing roadmaps and operating models to ensure security is built-in (not bolted-on) and delivery teams can move quickly with well-defined paved roads.
- Lead architecture governance for product/application security:
- establish review criteria and decision frameworks
- perform design reviews and approve/drive remediation plans
- manage exceptions with documented risk acceptance, compensating controls, and time-bound closure
- Drive threat modeling at scale by defining methodology and minimum expectations, and by facilitating modeling for high-risk initiatives—explicitly documenting trust boundaries, data flows, abuse cases, and security requirements.
- Define and standardize API security architectures (north-south and east-west), including authentication/authorization, token strategy, schema and input validation, anti-automation protections, and rate limiting/throttling patterns.
- Establish security architecture patterns for distributed systems, cloud-native applications, and service-to-service communications, including workload identity, authorization, mTLS, secrets management, and policy enforcement.
- Establish security architecture patterns for service-to-service security controls in distributed systems, including workload identity, authorization, mTLS, secrets handling, and policy enforcement—ensuring controls are practical for engineering adoption.
- Develop and report key performance indicators, risk metrics, and security maturity measures to executive leadership, demonstrating business impact and risk reduction outcomes.
- Influence and enable secure SDLC and platform controls with engineering enablement in mind (security requirements, pipeline guardrails, dependency/supply-chain controls, secure configuration guidance), partnering with platform teams to operationalize.
- Establish and track measurable outcomes (e.g., blueprint adoption, recurring architecture risks, API posture…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).