Information Security Architect
Job description
About the role
Airship seeks a seasoned Information Security Architect to lead the development and ongoing enhancement of our security architecture. You will be the primary technical authority for secure system design, collaborating closely with engineering and product teams to integrate security throughout the development lifecycle. This is a hands-on role focused on architecting secure cloud infrastructure and development pipelines.
Key facts
What you'll do
- Develop and maintain the company's security architecture, including reference designs, secure development patterns, and technical security standards.
- Conduct thorough security reviews of applications, cloud infrastructure, and system integrations to ensure adherence to security policies.
- Perform threat modeling and technical risk assessments to pinpoint security vulnerabilities and propose effective mitigation strategies.
- Establish and enforce cloud security policies, network segmentation, logging protocols, and access control frameworks within the Google Cloud Platform (GCP) environment.
- Collaborate with engineering and DevOps teams to embed security controls into the CI/CD process, covering secure builds, container security, Infrastructure-as-Code (IaC), secrets management, and software supply chain integrity.
- Evaluate proposed architectural and design changes from engineering teams, assessing their security implications and providing recommendations.
- Assess emerging technologies, including AI and generative AI platforms, to identify security risks and define secure adoption strategies.
- Provide security guidance for API security, application authentication (SAML, OAuth2), encryption, and identity and access management.
- Stay informed about security trends, new attack vectors, and vulnerabilities to proactively reduce breach risks.
- AI-powered tools to enhance security analysis, architecture review processes, and threat detection capabilities.
- Partner with security tooling teams to evaluate enterprise security solutions for architectural compatibility, integration, and scalability.
- Participate in the security on-call rotation and assist with incident response.
- Offer expert technical security guidance for complex customer inquiries.
- Mentor colleagues on secure design principles and best security practices.
Requirements
- A minimum of 8 years of experience in information security, security architecture, cloud security engineering, or a comparable technical field.
- Extensive knowledge of Google Cloud Platform (GCP) security, including its native security features, cloud architecture best practices, and workload protection.
- Practical experience in securing CI/CD pipelines, including container security, IaC security, secrets management, and DevSecOps methodologies.
- Proven experience in conducting threat modeling for complex, distributed systems using established frameworks.
- Demonstrated experience in performing security architecture and design reviews for cloud-native applications and infrastructure.
- Proficiency in at least one scripting language such as Python, Java, or Bash/shell.
- Solid understanding of network security principles, including segmentation, Zero Trust concepts, firewalls, and access control.
- Working knowledge of identity and access management concepts, including single sign-on (SSO), multi-factor authentication (MFA), federation, and the principle of least privilege.
- Strong grasp of application security, including OWASP guidelines, API security, secure software development lifecycle (SDLC) practices, and authentication protocols like SAML and OAuth2.
- Familiarity with protecting and administering macOS, Linux, and Windows operating systems.
- Ability to translate security requirements into practical and scalable technical solutions.
- Excellent written and verbal communication skills, with the ability to explain complex security concepts clearly to diverse audiences.
- Experience experimenting with AI tools in a personal or professional capacity.
Nice to have
- Possession of one or more industry certifications such as CISSP, CCSP, Google Cloud Professional Security Engineer, OSCP, or GIAC certifications.
- Experience with enterprise security tools like Splunk, CrowdStrike, Rapid7, Vanta, Okta, and Data Loss Prevention (DLP) solutions.
- Familiarity with AI security concepts, secure AI platform adoption, and AI risk frameworks (e.g., NIST AI RMF, ISO 42001).
- Experience developing security reference architectures, design patterns, and technical standards documentation.
- Experience with Kubernetes security, container orchestration, and cloud-native security tools (CSPM, CWPP).
- Knowledge of data security practices, including encryption, data classification, DLP, and key management.
- Experience evaluating third-party technologies and conducting technical security assessments for vendor platforms.
Skills & tools
- Google Cloud Platform (GCP)
- CI/CD Pipeline Security
- Threat Modeling
- Infrastructure-as-Code (IaC) Security
- Container Security
- Secrets Management
- DevSecOps
- Python, Java, Bash/shell
- OWASP
- SAML, OAuth2
- macOS, Linux, Windows
- Splunk, CrowdStrike, Rapid7, Vanta, Okta, DLP (nice to have)
- Kubernetes Security, CSPM, CWPP (nice to have)
- AI Security Concepts (nice to have)
Practical notes
- This is a fully remote position.
- Travel may be required up to 10% of the time.
- Starting Pay Range: $130,000 - $160,000 USD per year.
- Compensation includes stock options.
- Benefits include medical, dental, and vision insurance, flexible time off, paid holidays, parental leave, volunteer time off, mental health and wellness resources, employer-subsidized life insurance, short-term and long-term disability, and a monthly stipend for remote work.
- Airship uses AI tools in recruitment as decision-support tools only. All AI-generated scores and recommendations are reviewed by the People Operations team. Applicants may have the right to request human review of AI-assisted employment decisions or opt out of AI evaluation by contacting privacy@airship.com.
- Airship will only contact candidates via email addresses ending in "@airship.com".
About the company
Airship is trusted by worldâs leading brands such as Alaska Airlines, BBC and The Home Depot to drive revenue growth and customer loyalty with exceptional cross-channel customer experiences. Today, brands are challenged to deliver , unified customer experiences across a fragmented array of channels and devicesâ apps, websites, email, SMS, wallets and more.