Information Security Architect
$130,000–$160,000 year
RemoteUnited States
Job Summary
Design and evolve Airship's security architecture across cloud infrastructure, applications, and the CI/CD pipeline, conducting threat modeling and architecture reviews to embed secure-by-design systems. Define guardrails, segmentation patterns, and access controls within the GCP environment while integrating security controls into the software delivery lifecycle. Evaluate emerging AI and generative AI platforms to identify risks and establish secure adoption patterns. Participate in the Security on-call rotation and provide technical guidance for complex customer inquiries. This senior architecture role focuses on securing Airship's digital-first platform used by leading brands like Alaska Airlines and BBC, with a path toward security leadership.
Required Qualifications
- 8+ years of experience in information security, security architecture, cloud security engineering, or a related technical discipline
- Deep expertise in Google Cloud Platform (GCP) security, including native security capabilities, cloud architecture patterns, and workload protection
- Hands-on experience securing CI/CD pipelines, including container security, IaC security, secrets management, and DevSecOps practices
- Experience conducting threat modeling for complex, distributed systems using standard methodologies
- Experience performing security architecture and design reviews for cloud-native applications and infrastructure
- Proficiency in at least one scripting language (e.g., Python, Java, Bash/shell)
- Working knowledge of network security concepts, including segmentation, Zero Trust principles, firewalls, and access control models
- Working knowledge of identity and access management concepts, including SSO, MFA, federation, and least-privilege access
- Strong understanding of application security, including OWASP, API security, secure SDLC practices, and authentication protocols (SAML, OAuth2)
- Working knowledge of how to protect and administer macOS, Linux, and Windows systems
- Ability to translate security requirements into practical, scalable technical solutions
- Strong written and verbal communication skills, with a talent for explaining complex security concepts to both technical and non-technical audiences
- Experience experimenting with AI tools in your personal or professional life
- Must be able to collaborate, innovate, and support one another across different locations and timezones
- This position is fully remote and may require up to 10% travel based on business needs or as requested by your manager
Desired Qualifications
- One or more industry certifications (e.g., CISSP, CCSP, Google Cloud Professional Security Engineer, OSCP, GIAC certifications)
- Experience with enterprise security technologies such as Splunk, CrowdStrike, Rapid7, Vanta, Okta, and DLP solutions
- Familiarity with AI security concepts, secure AI platform adoption, and AI risk frameworks (e.g., NIST AI RMF, ISO 42001)
- Experience developing security reference architectures, design patterns, and technical standards documentation
- Experience with Kubernetes security, container orchestration, and cloud-native security tooling (CSPM, CWPP)
- Knowledge of data security practices including encryption, data classification, DLP, and key management
- Experience evaluating third-party technologies and conducting technical security assessments for vendor platforms
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.