Security Architect, Product

Other Jobs To Apply

College Board - Technology - Product Security Location: This is a fully remote role. Candidates who live near CB offices have the option of being fully remote or hybrid (Tuesday and Wednesday in office). Type: This is a full-time position   About the Team  College Boards' Product Security team is a close-knit group of technologists focused on building secure, cloud-native products. We partner closely with product and engineering teams to identify risks early, solve hard problems, and enable delivery through practical security architecture and DevSecOps practices. We value diverse perspectives and ensure every voice is heard. Security Architects collaborate with product teams and key stakeholders to translate business needs into secure design decisions. They lead threat modeling and architecture reviews, help teams adopt secure development practices, and contribute to security standards and tooling decisions. About the Opportunity   As a Product Security Architect, you will serve as a trusted advisor to product teams building and operating multi-tenant SaaS applications that support millions of students. You’ll guide secure-by-design architecture, lead threat modeling and design reviews, and help teams make practical trade-offs across security, privacy, resilience, and delivery. This role requires strong judgment and agency. You will be expected to make risk-based decisions within established guardrails, knowing when to escalate and when to move forward independently. You will also help shape security architecture for high-trust assessment experiences and large-scale integrations common in K–12 and higher education ecosystems. In this role, you will: Secure SaaS Architectures (50%) - Serve as a trusted security advisor to engineering and product teams, offering clear guidance on secure architecture, design decisions, and remediation strategies. - Review system and application architectures, identifying gaps, recommending enhancements, and aligning solutions with College Board’s Product Security Framework and zero-trust principles. - Partner with product teams early in the lifecycle to conduct architectural assessments, threat modeling, and data flow review, ensuring that secure-by-design practices guide every phase of development. - Advise on secure implementation of cloud-native services, client/mobile applications, IAM, encryption, storage, access control and data protection, and serverless design patterns. - Provide architectural guidance that supports audit and compliance readiness by ensuring security and privacy requirements are reflected in system design, technical controls, and documented patterns. - Support the evaluation of new technologies, third-party integrations, and design proposals to assess security impact and ensure alignment to enterprise standards, including large-scale customer integrations (SSO/identity federation and data exchange) common in K–12 and higher education ecosystems - Partner with engineering teams to evaluate failure modes, dependency risks, and systemic weaknesses as part of architectural reviews and threat modeling. - Embed deeply within one of more product domains, partnering early with engineering and product teams as the primary security architecture advisor. - Lead risk-based trade-off discussions (security, privacy, usability, delivery), documenting key decisions and rationale to help teams move quickly and consistently. Elevate Product Security (25%) - Lead the creation and documentation of secure architectural reference patterns for recurring use cases across College Board (e.g., external API patterns, secure data ingestion). - Collaborate with other architects to shape the long-term technical strategy for secure software and cloud architecture. - Contribute to the continuous improvement of Product Security standards and threat modeling methodologies, ensuring consistency and scalability. - Analyze emerging security and privacy threats, industry trends, and cloud-security advancements to proactively update architectural patterns and security guidance. - Mentor junior security engineers and developers, providing coaching on architectural thinking, secure design, and modern application security concepts. - Work with security partner team in maturing product-specific risk registers. Improve Product Security Operations (25%) - Partner with engineering, DevSecOps, and cloud platform teams to create secure design patterns in CI/CD, infrastructure-as-code, and runtime environments. - Support the design of security and platform guardrails that improve system resilience at scale, including secure defaults, automated rollback, isolation controls, and observable failure detection. - Support governance workflows as stakeholders in broader multi-team processes. - Contribute to development of metrics, KPIs, and maturity indicators to measure architectural security posture and influence roadmap planning. - Assist in implementing automated guardrails and tooling that enforce architectural best practices at scale. - Participate in evaluating and improving new and existing security policies and standards, tools, and controls across the organization to enhance the overall security posture.   About you, you have: - Meaningful experience in security architecture, application security, or cloud security, with ownership of architectural decisions and trade-offs. - Strong understanding of security risks in modern multi-tenant SaaS architectures (APIs, microservices/event-driven patterns, identity, data protection). - Experience leading threat modeling, architecture reviews, and risk assessments, translating findings into clear, actionable guidance for technical and non-technical audiences. - Cloud security depth (AWS preferred; comparable depth in Azure or GCP is valued). - Experience securing third-party and customer integrations at scale (e.g., SSO/identity federation and data exchange). - Experience in K–12 or higher education ecosystems (e.g., SIS/classroom platforms) is a strong advantage. - A pragmatic, risk-based approach and comfort operating with ambiguity, able to exercise agency and make decisions within guardrails. - AI-native behavior: you actively use AI today (work or personal) and can articulate where it helps, where it introduces risk, and the guardrails you apply. - Strong collaboration and influence skills; able to challenge ideas respectfully, mentor others, and partner effectively across engineering, product, privacy, and compliance. All roles at College Board require: - A passion for expanding educational and career opportunities and mission-driven work - Curiosity and enthusiasm for emerging technologies, with a willingness to experiment with and adopt new AI-driven solutions and comfort with learning and applying new digital tools independently and proactively. - Clear and concise communication skills, written and verbal - A learner's mindset and a commitment to growth: welcoming diverse perspectives, giving and receiving timely, respectful feedback, and continuously improving through iterative learning and user input. - A drive for impact and excellence: solving complex problems, making data-informed decisions, prioritizing what matters most, and continuously improving through learning, user input, and external benchmarking. - A collaborative and empathetic approach: working across differences, fostering trust, and contributing to a culture of shared success - Authorization to work in the United States About Our Process - Application review will begin immediately and will continue until the position is filled. This role is expected to accept applications for a minimum of 5 business days. - While the hiring process may vary, it generally includes: resume and application submission, recruiter phone/video screen, hiring manager interview, performance exercise such as live coding, a panel interview, a conversation with leadership and reference checks. What We Offer At College Board, we offer more than a paycheck- we provide a meaningful career, a supportive team, and a comprehensive package designed to help you thrive. We’re a self-sustaining nonprofit that believes in fair and competitive compensation grounded in your qualifications, experience, impact, and the market. A Thoughtful Approach to Compensation - The hiring range for this role is $156,000–$172,000. - Your exact salary will depend on your location, experience, and how your background compares to others in similar roles at the College Board. - We aim to make our best offer upfront, rooted in fairness, transparency, and market data. - We adjust salaries by location to ensure fairness, no matter where you live. You’ll have open, transparent conversations about compensation, benefits, and what it’s like to work at College Board throughout your hiring process. Check out our careers page for more.

Back to blog

Common Interview Questions And Answers

1. HOW DO YOU PLAN YOUR DAY?

This is what this question poses: When do you focus and start working seriously? What are the hours you work optimally? Are you a night owl? A morning bird? Remote teams can be made up of people working on different shifts and around the world, so you won't necessarily be stuck in the 9-5 schedule if it's not for you...

2. HOW DO YOU USE THE DIFFERENT COMMUNICATION TOOLS IN DIFFERENT SITUATIONS?

When you're working on a remote team, there's no way to chat in the hallway between meetings or catch up on the latest project during an office carpool. Therefore, virtual communication will be absolutely essential to get your work done...

3. WHAT IS "WORKING REMOTE" REALLY FOR YOU?

Many people want to work remotely because of the flexibility it allows. You can work anywhere and at any time of the day...

4. WHAT DO YOU NEED IN YOUR PHYSICAL WORKSPACE TO SUCCEED IN YOUR WORK?

With this question, companies are looking to see what equipment they may need to provide you with and to verify how aware you are of what remote working could mean for you physically and logistically...

5. HOW DO YOU PROCESS INFORMATION?

Several years ago, I was working in a team to plan a big event. My supervisor made us all work as a team before the big day. One of our activities has been to find out how each of us processes information...

6. HOW DO YOU MANAGE THE CALENDAR AND THE PROGRAM? WHICH APPLICATIONS / SYSTEM DO YOU USE?

Or you may receive even more specific questions, such as: What's on your calendar? Do you plan blocks of time to do certain types of work? Do you have an open calendar that everyone can see?...

7. HOW DO YOU ORGANIZE FILES, LINKS, AND TABS ON YOUR COMPUTER?

Just like your schedule, how you track files and other information is very important. After all, everything is digital!...

8. HOW TO PRIORITIZE WORK?

The day I watched Marie Forleo's film separating the important from the urgent, my life changed. Not all remote jobs start fast, but most of them are...

9. HOW DO YOU PREPARE FOR A MEETING AND PREPARE A MEETING? WHAT DO YOU SEE HAPPENING DURING THE MEETING?

Just as communication is essential when working remotely, so is organization. Because you won't have those opportunities in the elevator or a casual conversation in the lunchroom, you should take advantage of the little time you have in a video or phone conference...

10. HOW DO YOU USE TECHNOLOGY ON A DAILY BASIS, IN YOUR WORK AND FOR YOUR PLEASURE?

This is a great question because it shows your comfort level with technology, which is very important for a remote worker because you will be working with technology over time...