Connecting talent with opportunity

Loading WeHireYou

Free for the first 200 users

Claim spot

Information Security Architect

Airship · Remote · Remote

engineeringremoteseniorjavapythongcpci/cd
schedule

Posted

Today

work

Job type

Full-time

domain

Industry

IT & Software

group

Openings

1

About the role

Information Security Architect About Airship Airship is trusted by world’s leading brands such as Alaska Airlines, BBC and The Home Depot to drive revenue growth and customer loyalty with exceptional cross-channel customer experiences. Today, brands are challenged to deliver seamless, unified customer experiences across a fragmented array of channels and devices— apps, websites, email, SMS, wallets and more. Airship’s no-code, AI-powered platform was designed with non-technical, growth-focused teams in mind, making it easy to create, test and orchestrate hyper-personalized experiences across all channels. With the ability to easily enrich customer data and rapidly launch growth experiments, Airship enables brands to deliver consistent, meaningful interactions that accelerate conversion and foster deeper customer relationships. We invite you to be part of our journey in building products and delivering services that touch millions of customers around the world every day. To learn more about us, visit www.airship.com, read our blog or follow us on LinkedIn. About the Role Airship is looking for an Information Security Architect to own the design and evolution of our security architecture across cloud infrastructure, applications, and the CI/CD pipeline. You'll be Airship's technical authority on secure-by-design systems, partnering with Engineering, Platform, and Product teams to embed security into every phase of the development lifecycle. This is a hands-on architecture role. You'll conduct threat modeling, perform architecture reviews, define security standards and reference architectures, and drive secure design patterns across Airship's GCP-based environment. You'll also evaluate emerging technologies, including AI and generative AI platforms, to identify security risks and define secure adoption patterns. Why This Role - Depth over breadth. You'll focus on what matters most: securing Airship's cloud infrastructure and CI/CD pipelines, conducting threat modeling, and shaping architecture decisions - GCP at the core. Airship runs on Google Cloud Platform. You'll work deeply with GCP-native security capabilities, defining guardrails, segmentation patterns, logging standards, and workload protection across the platform - Secure the pipeline, secure the product. CI/CD pipeline security is a primary focus. You'll design and implement controls that protect the software delivery lifecycle from code commit through production deployment - AI-forward security. You'll evaluate and secure AI and GenAI platforms, define usage patterns for AI-assisted development tools, and help establish security architecture for Airship's AI-enabled features - Fully remote, flexible culture. Airship's Digital First approach means flexible, remote work is the norm, with a team that collaborates across timezones and geographies every day - Room to grow. This role is a path toward senior security architecture, security leadership, or deeper cloud security specialization What You'll Do* - Design, develop, and maintain Airship's security architecture, including reference architectures, secure design patterns, and technical security standards - Perform security architecture reviews for enterprise applications, cloud platforms, infrastructure services, and technology integrations, ensuring alignment with security standards and risk posture - Conduct threat modeling and technical risk assessments to identify security gaps and recommend mitigation strategies - Define and implement cloud security guardrails, network segmentation patterns, logging standards, and access control models across Airship's GCP environment - Partner with Engineering and DevOps teams to integrate security controls into the CI/CD pipeline, including secure build processes, container security, Infrastructure-as-Code (IaC) security, secrets management, and software supply chain integrity - Evaluate proposed architecture and design changes from engineering teams, analyze their security impact, and make recommendations - Assess emerging technologies (including AI platforms, generative AI tools, and AI-assisted development technologies) to identify security risks and define secure usage patterns - Develop security guidance for API security, application authentication (SAML, OAuth2), encryption, and identity and access management - Research security trends, emerging attack methods, and new classes of vulnerabilities to proactively reduce the risk of breach - Leverage AI-enabled tools and automation to improve security analysis, architecture review workflows, and threat detection - Partner with security tooling teams to evaluate enterprise security tools for architectural fit, integration models, and long-term scalability - Participate in the Security on-call rotation and respond to incidents - Provide technical security guidance for complex customer inquiries that require deep architectural expertise - Mentor colleagues across the organization on secure design principles and security best practices *Duties described are not a comprehensive list. Additional tasks may be assigned from time to time, and responsibilities may be amended at any time at the sole discretion of the Employer. What We're Looking For - 8+ years of experience in information security, security architecture, cloud security engineering, or a related technical discipline - Deep expertise in Google Cloud Platform (GCP) security, including native security capabilities, cloud architecture patterns, and workload protection - Hands-on experience securing CI/CD pipelines, including container security, IaC security, secrets management, and DevSecOps practices - Experience conducting threat modeling for complex, distributed systems using standard methodologies - Experience performing security architecture and design reviews for cloud-native applications and infrastructure - Proficiency in at least one scripting language (e.g., Python, Java, Bash/shell)...

Key responsibilities

  • check_circleCollaborate with the team on day-to-day project tasks
  • check_circleLearn tools and processes used by the organization
  • check_circleDocument work and participate in team meetings
  • check_circleSupport quality checks and continuous improvement

Requirements

  • check_circleDepth over breadth. You'll focus on what matters most: securing Airship's cloud infrastructure and CI/CD pipelines, conducting threat modeling, and shaping architecture decisions
  • check_circleGCP at the core. Airship runs on Google Cloud Platform. You'll work deeply with GCP-native security capabilities, defining guardrails, segmentation patterns, logging standards, and workload protection across the platform
  • check_circleSecure the pipeline, secure the product. CI/CD pipeline security is a primary focus. You'll design and implement controls that protect the software delivery lifecycle from code commit through production deployment
  • check_circleAI-forward security. You'll evaluate and secure AI and GenAI platforms, define usage patterns for AI-assisted development tools, and help establish security architecture for Airship's AI-enabled features
  • check_circleFully remote, flexible culture. Airship's Digital First approach means flexible, remote work is the norm, with a team that collaborates across timezones and geographies every day
  • check_circleRoom to grow. This role is a path toward senior security architecture, security leadership, or deeper cloud security specialization
  • check_circleDesign, develop, and maintain Airship's security architecture, including reference architectures, secure design patterns, and technical security standards
  • check_circlePerform security architecture reviews for enterprise applications, cloud platforms, infrastructure services, and technology integrations, ensuring alignment with security standards and risk posture
  • check_circleConduct threat modeling and technical risk assessments to identify security gaps and recommend mitigation strategies
  • check_circleDefine and implement cloud security guardrails, network segmentation patterns, logging standards, and access control models across Airship's GCP environment
  • check_circlePartner with Engineering and DevOps teams to integrate security controls into the CI/CD pipeline, including secure build processes, container security, Infrastructure-as-Code (IaC) security, secrets management, and software supply chain integrity
  • check_circleEvaluate proposed architecture and design changes from engineering teams, analyze their security impact, and make recommendations

Skills & keywords

airshiparchitectci/cdgcpinformationjavapythonremotesecurity

Benefits & perks

  • check_circleMentorship
  • check_circleCertificate of completion
  • check_circleFlexible work arrangement where applicable