Information Security Architect
Airship
| Company | Airship |
| Category | Security |
| Location | US |
| Remote | Remote |
| Employment | Not stated |
| Level | Lead |
| Salary | USD 130k–160k |
| Posted | 21 Jul 2026 |
| Last verified | 12 Aug 2026 |
| Source | The employer's own careers page (company_site) |
Description
Airship is a customer experience platform trusted by leading brands. This role is an Information Security Architect responsible for designing and evolving security architecture across Airship's GCP-based cloud infrastructure, applications, and CI/CD pipelines, serving as the technical authority on secure-by-design systems.
What You'll Do
• Design, develop, and maintain security architecture including reference architectures, secure design patterns, and technical security standards
• Perform security architecture reviews for enterprise applications, cloud platforms, infrastructure services, and technology integrations
• Conduct threat modeling and technical risk assessments for complex, distributed systems to identify security gaps and recommend mitigations
• Design and implement cloud security guardrails, network segmentation patterns, logging standards, and access control models across GCP environment
• Partner with Engineering and DevOps teams to integrate security controls into CI/CD pipelines, including secure build processes, container security, IaC security, and secrets management
• Evaluate emerging technologies including AI and generative AI platforms to identify security risks and define secure adoption patterns
• Participate in security on-call rotation and respond to incidents
What You Need
• 8+ years of experience in information security, security architecture, cloud security engineering, or related technical discipline
• Deep expertise in Google Cloud Platform (GCP) security, including native security capabilities and workload protection
• Hands-on experience securing CI/CD pipelines including container security, IaC security, secrets management, and DevSecOps practices
• Experience conducting threat modeling for complex, distributed systems using standard methodologies
• Proficiency in at least one scripting language such as Python, Java, or Bash
• Working knowledge of network security concepts including segmentation, Zero Trust principles, firewalls, and access control models
• Working knowledge of identity and access management concepts including SSO, MFA, federation, and least-privilege access
• Strong understanding of application security including OWASP, API security, secure SDLC practices, and authentication protocols (SAML, OAuth2)
• Working knowledge of protecting and administering macOS, Linux, and Windows systems
Nice to Have
• One or more industry certifications such as CISSP, CCSP, Google Cloud Professional Security Engineer, OSCP, or GIAC certifications
• Experience with enterprise security technologies such as Splunk, CrowdStrike, Rapid7, Vanta, Okta, and DLP solutions
• Familiarity with AI security concepts, secure AI platform adoption, and AI risk frameworks such as NIST AI RMF or ISO 42001
• Experience developing security reference architectures, design patterns, and technical standards documentation
• Experience with Kubernetes security, container orchestration, and cloud-native security tooling (CSPM, CWPP)
• Knowledge of data security practices including encryption, data classification, DLP, and key management
• Experience experimenting with AI tools in personal or professional life
Starting pay range $130,000–$160,000 USD per year base salary plus stock options. Benefits include competitive medical, dental, and vision insurance, flexible time off, paid parental leave, paid volunteer time off, mental health and wellness resources, employer-subsidized life insurance, short-term and long-term disability, digital-first work environment with remote work stipend, and mentorship and growth opportunities.