Box is looking for a thought leader who can design, implement, and maintain a best-in-class software security posture.

We’re looking for a seasoned software security architect who understands secure software development to design automated and integrated secure development patterns within the development ecosystem and has an understanding of DevSecOps to create tool integration architecture.


  • Provide subject matter expertise, roadmaps, strategies, reference architectures for application and product security
  • Provide thought leadership in the areas of security tool automation, optimization, application vulnerability management and strategies for risk reduction
  • Create design of comprehensive architectural patterns for secure development standards for front end, APIs and mobile
  • Develop and maintain application security policies, standards, and guidelines, and ensure their adherence across projects.
  • Develop strategy to automate software security vulnerability verification within throughout the development process
  • Collaborate closely with cross-functional architects to identify application-based vulnerabilities, design secure application architectures, and guide the integration of security measures into the development process
  • Create architecture design for tool integrations and implement tooling within CI/CD pipeline, limit manual testing and troubleshooting
  • Lead security engineer and software engineer training related to high risk security risks
  • Evaluate products for security gaps through threat modeling and pen testing
  • Lead M&A security evaluations


  • You understand secure engineering best practices, can articulate problem statements and propose solutions to both technically savvy and non-technical audiences
  • You know the software security secure development best practices specific to development languages and frameworks, know the security tooling landscape and have implemented large scale security programs at organizations with complex application architecture
  • You have a growth mindset, push yourself towards excellence and focus on continuous functional improvements
  • You are a curious person who looks at problem statements and can clearly propose actionable solutions
  • You have a passion for cyber security demonstrated through participation/leadership in conferences, webinars, Capture the Flag (CTF), TryHackMe, Bug Bounty, Submission of CVEs and/or personal projects
  • Strong understanding of past, current, and emerging security exploits
  • Remote friendly
  • Box lives its values, with community and in-person collaboration being a core part of our culture. Boxers are expected to work from their assigned office a minimum of 2 days per week, with a focus on Tuesdays and Thursdays. Your Recruiter will share more about how we work and company culture during the hiring process.


  • At least 10+ years experience in software engineering, architecture and software security
  • 5+ years previous experience leading large software security initiatives and/or transformations
  • Knowledge of OWASP Top 10, Dynamic Application Security Testing (DAST), Static Application Security Testing (SAST), API Security Testing Tools, Automated Mobile Testing Tools and Threat Modeling tools
  • At least 1 security certification (ex. CISSP, OSCP, GWEB, CEH, GRTP, GWEB)
  • Experience with multiple languages such as Java, React, Node JS, PHP, Scala, C and/or Python
  • Understand how to detect and prioritize Front End, API’s, Microservices and Container vulnerabilities
  • Familiar with common build/automation tooling: ex. Jenkins, GIT
Job Overview
Job alerts

Subscribe to our weekly job alerts below and never miss the latest jobs

Sign in

Sign Up

Forgotten Password

Job Quick Search