hirly
Likely filled

This role has closed. Airship has taken the posting down.

hirly last saw it live on 10 September 2026. See similar open roles below, or browse the live board.

Airship

Information Security Architect

Remote - U.S.

hirly's read of this role

Seniority
Mid level
Country
US
Work mode
Remote-friendly
First seen by hirly
3 Sept 2026

Derived automatically from the posting.

the posting

About Airship

Airship is trusted by world’s leading brands such as Alaska Airlines, BBC and The Home Depot to drive revenue growth and customer loyalty with exceptional cross-channel customer experiences. Today, brands are challenged to deliver seamless, unified customer experiences across a fragmented array of channels and devices— apps, websites, email, SMS, wallets and more.

Airship’s no-code, AI-powered platform was designed with non-technical, growth-focused teams in mind, making it easy to create, test and orchestrate hyper-personalized experiences across all channels. With the ability to easily enrich customer data and rapidly launch growth experiments, Airship enables brands to deliver consistent, meaningful interactions that accelerate conversion and foster deeper customer relationships.

We invite you to be part of our journey in building products and delivering services that touch millions of customers around the world every day.

To learn more about us, visit www.airship.com , read our blog or follow us on LinkedIn.

About the Role

Airship is looking for an Information Security Architect to own the design and evolution of our security architecture across cloud infrastructure, applications, and the CI/CD pipeline. You'll be Airship's technical authority on secure-by-design systems, partnering with Engineering, Platform, and Product teams to embed security into every phase of the development lifecycle.

This is a hands-on architecture role. You'll conduct threat modeling, perform architecture reviews, define security standards and reference architectures, and drive secure design patterns across Airship's GCP-based environment. You'll also evaluate emerging technologies, including AI and generative AI platforms, to identify security risks and define secure adoption patterns.

Why This Role

Depth over breadth. You'll focus on what matters most: securing Airship's cloud infrastructure and CI/CD pipelines, conducting threat modeling, and shaping architecture decisions

GCP at the core. Airship runs on Google Cloud Platform. You'll work deeply with GCP-native security capabilities, defining guardrails, segmentation patterns, logging standards, and workload protection across the platform

Secure the pipeline, secure the product. CI/CD pipeline security is a primary focus. You'll design and implement controls that protect the software delivery lifecycle from code commit through production deployment

AI-forward security. You'll evaluate and secure AI and GenAI platforms, define usage patterns for AI-assisted development tools, and help establish security architecture for Airship's AI-enabled features

Fully remote, flexible culture. Airship's Digital First approach means flexible, remote work is the norm, with a team that collaborates across timezones and geographies every day

Room to grow. This role is a path toward senior security architecture, security leadership, or deeper cloud security specialization

What You'll Do*

Design, develop, and maintain Airship's security architecture, including reference architectures, secure design patterns, and technical security standards

Perform security architecture reviews for enterprise applications, cloud platforms, infrastructure services, and technology integrations, ensuring alignment with security standards and risk posture

Conduct threat modeling and technical risk assessments to identify security gaps and recommend mitigation strategies

Define and implement cloud security guardrails, network segmentation patterns, logging standards, and access control models across Airship's GCP environment

Partner with Engineering and DevOps teams to integrate security controls into the CI/CD pipeline, including secure build processes, container security, Infrastructure-as-Code (IaC) security, secrets management, and software supply chain integrity

Evaluate proposed architecture and design changes from engineering teams, analyze their security impact, and make recommendations

Assess emerging technologies (including AI platforms, generative AI tools, and AI-assisted development technologies) to identify security risks and define secure usage patterns

Develop security guidance for API security, application authentication (SAML, OAuth2), encryption, and identity and access management

Research security trends, emerging attack methods, and new classes of vulnerabilities to proactively reduce the risk of breach

Leverage AI-enabled tools and automation to improve security analysis, architecture review workflows, and threat detection

Partner with security tooling teams to evaluate enterprise security tools for architectural fit, integration models, and long-term scalability

Participate in the Security on-call rotation and respond to incidents

Provide technical security guidance for complex customer inquiries that require deep architectural expertise

Mentor colleagues across the organization on secure design principles and security best practices

*Duties described are not a comprehensive list. Additional tasks may be assigned from time to time, and responsibilities may be amended at any time at the sole discretion of the Employer.

What We're Looking For

8+ years of experience in information security, security architecture, cloud security engineering, or a related technical discipline

Deep expertise in Google Cloud Platform (GCP) security, including native security capabilities, cloud architecture patterns, and workload protection

Hands-on experience securing CI/CD pipelines, including container security, IaC security, secrets management, and DevSecOps practices

Experience conducting threat modeling for complex, distributed systems using standard methodologies

Experience performing security architecture and design reviews for cloud-native applications and infrastructure

Proficiency in at least one scripting language (e.g., Python, Java, Bash/shell)

Working knowledge of network security concepts, including segmentation, Zero Trust principles, firewalls, and access control models

Working knowledge of identity and access management concepts, including SSO, MFA, federation, and least-privilege access

Strong understanding of application security, including OWASP, API security, secure SDLC practices, and authentication protocols (SAML, OAuth2)

Working knowledge of how to protect and administer macOS, Linux, and Windows systems

Ability to translate security requirements into practical, scalable technical solutions

Strong written and verbal communication skills, with a talent for explaining complex security concepts to both technical and non-technical audiences

Experience experimenting with AI tools in your personal or professional life

We'd Be Delighted If You Also Have

One or more industry certifications (e.g., CISSP, CCSP, Google Cloud Professional Security Engineer, OSCP, GIAC certifications)

Experience with enterprise security technologies such as Splunk, CrowdStrike, Rapid7, Vanta, Okta, and DLP solutions

Familiarity with AI security concepts, secure AI platform adoption, and AI risk frameworks (e.g., NIST AI RMF, ISO 42001)

Experience developing security reference architectures, design patterns, and technical standards documentation

Experience with Kubernetes security, container orchestration, and cloud-native security tooling (CSPM, CWPP)

Knowledge of data security practices including encryption, data classification, DLP, and key management

Experience evaluating third-party technologies and conducting technical security assessments for vendor platforms

Work Location & Travel Requirements

Airship’s ‘Digital First’ approach to work means that for the majority of our roles, work can be performed remotely, either some or most of the time. Airship believes that flexible work contributes to a more productive and more equitable work environment, and that Airshippers are able to collaborate, innovate, and

Original posting on Airship's site ↗