Base Salary
$130k - $160k/yr
Responsibilities
- Design and maintain security reference architectures, secure design patterns, and technical security standards.
- Perform security architecture reviews and threat modeling for applications, cloud platforms, infrastructure, and integrations.
- Define and implement GCP security guardrails, network segmentation, logging standards, workload protection, and access control models.
- Integrate security controls into CI/CD, including secure builds, container security, IaC security, secrets management, and software supply chain integrity.
- Assess AI platforms, generative AI tools, and AI-assisted development technologies for security risks and define secure usage patterns.
- Provide guidance on API security, authentication, encryption, and identity and access management.
- Research emerging threats and vulnerabilities, improve security analysis through AI-enabled automation, and evaluate enterprise security tools.
- Participate in security on-call and incident response, provide technical guidance for complex customer inquiries, and mentor colleagues.
Requirements
- At least 8 years of experience in information security, security architecture, cloud security engineering, or a related technical discipline.
- Deep expertise in Google Cloud Platform security, including native capabilities, cloud architecture patterns, and workload protection.
- Hands-on experience securing CI/CD pipelines, containers, Infrastructure-as-Code, secrets management, and DevSecOps practices.
- Experience conducting threat modeling and security architecture reviews for complex distributed and cloud-native systems.
- Proficiency in at least one scripting language such as Python, Java, or Bash/shell.
- Knowledge of network security, segmentation, Zero Trust, firewalls, access control, identity and access management, SSO, MFA, federation, and least privilege.
- Strong understanding of application security, OWASP, API security, secure SDLC practices, SAML, and OAuth2.
- Working knowledge of protecting and administering macOS, Linux, and Windows systems.
- Ability to translate security requirements into practical, scalable technical solutions and communicate complex concepts to technical and non-technical audiences.
- Experience experimenting with AI tools.
- Preferred certifications include CISSP, CCSP, Google Cloud Professional Security Engineer, OSCP, or GIAC certifications.
- Preferred experience includes Splunk, CrowdStrike, Rapid7, Vanta, Okta, DLP, Kubernetes security, CSPM, CWPP, data security, key management, AI security, and third-party technology assessments.
Benefits
- Medical, dental, and vision insurance for employees and dependents.
- Flexible time off, company-paid holidays, paid parental leave, and paid volunteer time off.
- Mental health and wellness resources.
- Employer-subsidized life insurance and short-term and long-term disability coverage.
- Fully remote digital-first work environment with a monthly remote-work stipend and up to 10% travel.
- Mentorship and professional development opportunities.
Tech Stack
Categories
About Airship
Airship is the only mobile-first customer experience platform that empowers brands to build unified cross-channel experiences and AI-powered journeys that deliver measurable results at scale. For over 15 years, Airship has pioneered mobile innovation — with industry-first push notifications, mobile wallet passes, in-app messages, and now AI agents — delivering mobile expertise that’s unmatched across industries and global markets. Airship enables product and marketing teams to launch AI-powered, unified and personalized experiences across app and web, turning ordinary customer interactions into repeatable conversions. Thousands of top global brands trust Airship to deliver sustainable revenue growth, lasting loyalty, and meaningful impact.
