Product Security Engineering Director
We tailor your resume to this role and apply for you in seconds.
Apply to Product Security Engineering Director at EnvestnetJob details
- Work type
- Remote
- Compensation
- $184,200 - $224,200/yr
- Posted
- Aug 3, 2026
- Apply on
- careers.envestnet.com
About this role
Description
Responsible for embedding strong security practices into the design, development and operation of Envestnet financial technology platforms. Partners with product management, software engineering, architecture and infrastructure teams to identify and mitigate security risks early in the product lifecycle. Defines secure design standards, performs threat modeling and security reviews and helps teams remediate vulnerabilities in applications, APIs and cloud services.
• Acts as a technical expert in product and application security, supporting multiple product lines or platforms.
• Leads threat modeling, secure design reviews and architecture assessments for complex applications, APIs and cloud-native services.
• Partners with engineering and product teams to identify security risks early and recommend practical, scalable mitigations.
• Define secure development requirements, architecture standards, and security review criteria aligned with the Secure Development Lifecycle (SDLC).
• Performs and oversees application security testing, vulnerability analysis and remediation validation.
• Helps prioritize security findings based on risk, business impact and regulatory requirements.
• Review significant security incidents to identify architectural weaknesses, systemic control gaps, and long-term remediation opportunities.
• Defines and promotes secure-by-design patterns for modern applications, APIs, distributed systems, and AI-enabled solutions, including LLM-based capabilities.
• Mentors product security engineers through technical guidance and reviews.
• Participates in audits, assessments and compliance activities by providing detailed technical input and documentation.
• Establishes product security requirements related to encryption, identity, authentication, authorization, secrets management, and secure configuration, while ensuring alignment with industry standards and regulatory requirements.
• Assess and govern the security of Generative and Agentic AI architectures, including LLMs, RAG, AI agents, MCP integrations, orchestration frameworks, and third-party AI services through architecture reviews and threat modeling.
• Define AI security standards, guardrails, and secure-by-design patterns, and provide strategic guidance for secure adoption of AI-enabled products and AI-assisted development capabilities.
• Identify and address cross-product security risks by driving reusable security patterns, reference architectures, and strategic security improvements, while influencing product roadmaps, architecture decisions, and technology strategy through security-focused design guidance and risk assessments.
• Candidates should demonstrate the relevant experience, skills, and capabilities needed to successfully perform in the role. Relevant experience may be gained through current responsibilities, prior roles, project work, leadership opportunities, or other comparable experiences.
• Bachelor’s/Master’s in Computer Science, Cybersecurity, or related field.
• Strong experience in product or application security architecture, with a focus on design‑level security preferably in a financial services industry.
• Hands‑on experience with threat modeling, security architecture reviews, and secure system design including AI-enabled systems.
• Solid understanding of modern application architectures, including microservices, APIs, and cloud‑native platforms.
• Working knowledge of AI/LLM concepts, including model integration patterns, RAG architectures, and agentic workflows.
• Knowledge of identity and access management, encryption standards, and secure integration patterns.
- Familiarity with industry frameworks such as OWASP, NIST, and security requirements for regulated environments including emerging AI governance practices.
- Certifications (optional): CISSP, CSSLP, CCSP.
- Strong communication skills to influence design decisions without direct ownership of delivery teams.
- Ability to translate security risks into clear architectural guidance for product and engineering teams.