> Markdown version of [/jobs/ext/1364085-information-security-architect](https://www.wearedevelopers.com/jobs/ext/1364085-information-security-architect). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Security Architect - **Company:** Urban Airship, Inc. - **Location:** United States (Remote available) - **Experience:** Expert - **Salary:** $130,000.0 - $160,000.0 - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Java (Programming Language), Microsoft Windows, Artificial Intelligence, Apple Mac Systems, Authentication Protocols, Bash Shell, Cloud Computing, Cloud Computing Security, Cloud Engineering, Cyber Security, Continuous Integration, Data Security, Software Design Patterns, Linux, DevOps, Distributed Systems, Identity and Access Management, Intrusion Detection and Prevention, Python (Programming Language), Key Management, Network Security, Network Segmentation, OAuth, Open Web Application Security, Systems Development Life Cycle, Zero Trust Network Access, Security Assertion Markup Language (SAML), Software Deployment, Data Logging, Scripting, Google Cloud, Enterprise Software Applications, Data Classification, Okta, Spring Cloud, Software Security, Generative AI, Firewalls (Computer Science), AI Platforms, Kubernetes, Infrastructure Automation Frameworks, Build Process, Splunk, Devsecops - **Published:** July 21, 2026 - **Apply:** https://job-boards.eu.greenhouse.io/airship/jobs/4929188101 ## About the Role * 8+ years of experience in information security, security architecture, cloud security engineering, or a related technical discipline * Deep expertise in Google Cloud Platform (GCP) security, including native security capabilities, cloud architecture patterns, and workload protection * Hands-on experience securing CI/CD pipelines, including container security, IaC security, secrets management, and DevSecOps practices * Experience conducting threat modeling for complex, distributed systems using standard methodologies * Experience performing security architecture and design reviews for cloud-native applications and infrastructure * Proficiency in at least one scripting language (e.g., Python, Java, Bash/shell) * Working knowledge of network security concepts, including segmentation, Zero Trust principles, firewalls, and access control models * Working knowledge of identity and access management concepts, including SSO, MFA, federation, and least-privilege access * Strong understanding of application security, including OWASP, API security, secure SDLC practices, and authentication protocols (SAML, OAuth2) * Working knowledge of how to protect and administer macOS, Linux, and Windows systems * Ability to translate security requirements into practical, scalable technical solutions * Strong written and verbal communication skills, with a talent for explaining complex security concepts to both technical and non-technical audiences * Experience experimenting with AI tools in your personal or professional life, * One or more industry certifications (e.g., CISSP, CCSP, Google Cloud Professional Security Engineer, OSCP, GIAC certifications) * Experience with enterprise security technologies such as Splunk, CrowdStrike, Rapid7, Vanta, Okta, and DLP solutions * Familiarity with AI security concepts, secure AI platform adoption, and AI risk frameworks (e.g., NIST AI RMF, ISO 42001) * Experience developing security reference architectures, design patterns, and technical standards documentation * Experience with Kubernetes security, container orchestration, and cloud-native security tooling (CSPM, CWPP) * Knowledge of data security practices including encryption, data classification, DLP, and key management * Experience evaluating third-party technologies and conducting technical security assessments for vendor platforms ## Description Airship is looking for an Information Security Architect to own the design and evolution of our security architecture across cloud infrastructure, applications, and the CI/CD pipeline. You'll be Airship's technical authority on secure-by-design systems, partnering with Engineering, Platform, and Product teams to embed security into every phase of the development lifecycle. This is a hands-on architecture role. You'll conduct threat modeling, perform architecture reviews, define security standards and reference architectures, and drive secure design patterns across Airship's GCP-based environment. You'll also evaluate emerging technologies, including AI and generative AI platforms, to identify security risks and define secure adoption patterns. Why This Role * Depth over breadth. You'll focus on what matters most: securing Airship's cloud infrastructure and CI/CD pipelines, conducting threat modeling, and shaping architecture decisions * GCP at the core. Airship runs on Google Cloud Platform. You'll work deeply with GCP-native security capabilities, defining guardrails, segmentation patterns, logging standards, and workload protection across the platform * Secure the pipeline, secure the product. CI/CD pipeline security is a primary focus. You'll design and implement controls that protect the software delivery lifecycle from code commit through production deployment * AI-forward security. You'll evaluate and secure AI and GenAI platforms, define usage patterns for AI-assisted development tools, and help establish security architecture for Airship's AI-enabled features * Fully remote, flexible culture. Airship's Digital First approach means flexible, remote work is the norm, with a team that collaborates across timezones and geographies every day * Room to grow. This role is a path toward senior security architecture, security leadership, or deeper cloud security specialization What You'll Do* * Design, develop, and maintain Airship's security architecture, including reference architectures, secure design patterns, and technical security standards * Perform security architecture reviews for enterprise applications, cloud platforms, infrastructure services, and technology integrations, ensuring alignment with security standards and risk posture * Conduct threat modeling and technical risk assessments to identify security gaps and recommend mitigation strategies * Define and implement cloud security guardrails, network segmentation patterns, logging standards, and access control models across Airship's GCP environment * Partner with Engineering and DevOps teams to integrate security controls into the CI/CD pipeline, including secure build processes, container security, Infrastructure-as-Code (IaC) security, secrets management, and software supply chain integrity * Evaluate proposed architecture and design changes from engineering teams, analyze their security impact, and make recommendations * Assess emerging technologies (including AI platforms, generative AI tools, and AI-assisted development technologies) to identify security risks and define secure usage patterns * Develop security guidance for API security, application authentication (SAML, OAuth2), encryption, and identity and access management * Research security trends, emerging attack methods, and new classes of vulnerabilities to proactively reduce the risk of breach * Leverage AI-enabled tools and automation to improve security analysis, architecture review workflows, and threat detection * Partner with security tooling teams to evaluate enterprise security tools for architectural fit, integration models, and long-term scalability * Participate in the Security on-call rotation and respond to incidents * Provide technical security guidance for complex customer inquiries that require deep architectural expertise * Mentor colleagues across the organization on secure design principles and security best practices *Duties described are not a comprehensive list. Additional tasks may be assigned from time to time, and responsibilities may be amended at any time at the sole discretion of the Employer., Some roles may require that employees perform their work from a specific location to support business activities, and/or be within proximity to an Airship office location or customer or partner locations, while other roles can be performed 100% remotely. This position is fully remote and may require up to 10% travel based on business needs or as requested by your manager. ## Related Videos - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [Delay the AI Overlords: How OAuth and OpenFGA Can Keep Your AI Agents from Going Rogue](https://www.wearedevelopers.com/videos/1637-delay-the-ai-overlords-how-oauth-and-openfga-can-keep-your-ai-agents-from-going-rogue) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this)