Find Jobs
Find Jobs Near You – Available Work in Your Location
Skip to job details
J
JetBlue
Architect Product Security
Career Insights for Enterprise Architect
See where this job fits in the broader career landscape. Knowing your career path helps you see what's possible from here.
Scorecard
Based on New York data
Review key factors to help you decide if this role fits your goals. How is this calculated?
What they do
An Enterprise Architect is responsible for ensuring that the business mission, strategy, and processes of an organization are aligned with the organization's IT strategy, and documents this using multiple architectural models or views that show how best to meet the current and future needs of the organization.
$146,041 / year median in New York
+9% projected growth
Job Description
Job Description The Architect, Product Security partners with product and engineering teams to design and deliver secure applications, APIs, and digital services. This role embeds security into product design and development by providing hands-on guidance, conducting threat modeling, and helping teams implement secure-by-design practices across the SDLC. The Architect operates as a hands-on security partner to product teams. The role focuses on secure-by-design principles, practical risk reduction, and enabling delivery teams to build resilient, scalable, and secure products without unnecessary friction. Essential Responsibilities Define and implement security architecture patterns for applications, APIs, cloud services, and platforms Develop secure design standards, reference architectures, and reusable patterns Ensure alignment with enterprise architecture and security strategy Embed security controls into Continuous Integration/Continuous Deployment pipelines and developer workflows Define and enforce secure coding practices and product security requirements Enable automation of security testing and validation (Static Application Security Testing, Dynamic Application Security Testing, Secure Code Analysis) Conduct and facilitate threat modeling sessions across product teams Identify architectural risks and define practical mitigation strategies Translate enterprise risk posture into product-level decisions and tradeoffs Define and guide application security testing strategies Partner with engineering teams to prioritize and remediate vulnerabilities Support penetration testing and security validation activities Architect controls for Authentication, Data protection and service security Support adoption of Zero Trust principles Partner with: Product Managers, Software Engineers, Platform and Cloud teams Other duties as assigned Minimum Experience and Qualifications Bachelor's Degree in a relevant field; OR demonstrated capability to perform job responsibilities with a High School Diploma/GED and at least four (4) years of previous relevant work experience Four (4) years of experience in Application security, product security, or security architecture Experience designing and securing: Cloud-native and distributed systems, and APIs and microservices architectures Experience designing or securing modern applications, APIs, cloud services, distributed systems, or digital platforms Strong ability to operate in fast-paced product and engineering environments Ability to manage multiple priorities in a fast-paced, multi-team environment Available for occasional overnight travel (10%) Must pass a pre-employment drug test Must be legally eligible to work in the country in which the position is located Authorization to work in the US is required, this position is not eligible for visa sponsorship Preferred Experience and Qualifications Experience supporting customer-facing applications, digital platforms, mobile applications, ecommerce, loyalty, APIs, or cloud-native services. Experience in aviation, transportation, financial services, or another regulated or operationally complex environment. Familiarity with AWS, Azure, GCP, Kubernetes, containers, serverless platforms, API gateways, WAF technologies, secrets management, and CI/CD tooling. Experience with SAST, DAST, SCA, or application security posture management tools. Knowledge of OWASP Top 10, OWASP API Security Top 10, OWASP