← BACK_TO_JOBS

Information Security Architect

Airship · Remote - U.S. · posted 1 day ago
REMOTE REMOTE Software / IT
GCP

About Airship

Airship is trusted by world’s leading brands such as Alaska Airlines, BBC and The Home Depot to drive revenue growth and customer loyalty with exceptional cross-channel customer experiences. Today, brands are challenged to deliver seamless, unified customer experiences across a fragmented array of channels and devices— apps, websites, email, SMS, wallets and more.

Airship’s no-code, AI-powered platform was designed with non-technical, growth-focused teams in mind, making it easy to create, test and orchestrate hyper-personalized experiences across all channels. With the ability to easily enrich customer data and rapidly launch growth experiments, Airship enables brands to deliver consistent, meaningful interactions that accelerate conversion and foster deeper customer relationships.

We invite you to be part of our journey in building products and delivering services that touch millions of customers around the world every day.

To learn more about us, visit www.airship.com, read our blog or follow us on LinkedIn.

About the Role

Airship is looking for an Information Security Architect to own the design and evolution of our security architecture across cloud infrastructure, applications, and the CI/CD pipeline. You'll be Airship's technical authority on secure-by-design systems, partnering with Engineering, Platform, and Product teams to embed security into every phase of the development lifecycle.

This is a hands-on architecture role. You'll conduct threat modeling, perform architecture reviews, define security standards and reference architectures, and drive secure design patterns across Airship's GCP-based environment. You'll also evaluate emerging technologies, including AI and generative AI platforms, to identify security risks and define secure adoption patterns.

Why This Role

  • Depth over breadth. You'll focus on what matters most: securing Airship's cloud infrastructure and CI/CD pipelines, conducting threat modeling, and shaping architecture decisions
  • GCP at the core. Airship runs on Google Cloud Platform. You'll work deeply with GCP-native security capabilities, defining guardrails, segmentation patterns, logging standards, and workload protection across the platform
  • Secure the pipeline, secure the product. CI/CD pipeline security is a primary focus. You'll design and implement controls that protect the software delivery lifecycle from code commit through production deployment
  • AI-forward security. You'll evaluate and secure AI and GenAI platforms, define usage patterns for AI-assisted development tools, and help establish security architecture for Airship's AI-enabled features
  • Fully remote, flexible culture. Airship's Digital First approach means flexible, remote work is the norm, with a team that collaborates across timezones and geographies every day
  • Room to grow. This role is a path toward senior security architecture, security leadership, or deeper cloud security specialization

What You'll Do*

  • Design, develop, and maintain Airship's security architecture, including reference architectures, secure design patterns, and technical security standards
  • Perform security architecture reviews for enterprise applications, cloud platforms, infrastructure services, and technology integrations, ensuring alignment with security standards and risk posture
  • Conduct threat modeling and technical risk assessments to identify security gaps and recommend mitigation strategies
  • Define and implement cloud security guardrails, network segmentation patterns, logging standards, and access control models across Airship's GCP environment
  • Partner with Engineering and DevOps teams to integrate security controls into the CI/CD pipeline, including secure build processes, container security, Infrastructure-as-Code (IaC) security, secrets management, and software supply chain integrity
  • Evaluate proposed architecture and design changes from engineering teams, analyze their security impact, and make recommendations
  • Assess emerging technologies (including AI platforms, generative AI tools, and AI-assisted development technologies) to identify security risks and define secure usage patterns
  • Develop security guidance for API security, application authentication (SAML, OAuth2), encryption, and identity and access management
  • Research security trends, emerging attack methods, and new classes of vulnerabilities to proactively reduce the risk of breach
  • Leverage AI-enabled tools and automation to improve security analysis, architecture review workflows, and threat detection
  • Partner with security tooling teams to evaluate enterprise security tools for architectural fit, integration models, and long-term scalability
  • Participate in the Security on-call rotation and respond to incidents
  • Provide technical security guidance for complex customer inquiries that require deep architectural expertise
  • Mentor colleagues across the organization on secure design principles and security best practices

*Duties described are not a comprehensive list. Additional tasks may be assigned from time to time, and responsibilities may be amended at any time at the sole discretion of the Employer.