Information Security Architect
Airship
$130,000–$160,000from the description
Jul 20, 2026
—
Jul 22, 2026
What this job asks for AI summary
A hands-on security architecture role centered on designing and maintaining secure systems across a GCP-based cloud environment, CI/CD pipelines, and application layers. Day-to-day work involves threat modeling, architecture reviews, defining security standards and reference architectures, and embedding controls into the software delivery lifecycle. The role also covers evaluating AI and generative AI platforms for security risk, and suits an experienced security architect with deep GCP and DevSecOps knowledge.
Senior level · 8+ years · Remote · Full-time
“or” means any one of them counts — you don't need all of them.
We read this from the posting text with AI. Skim the description below before ruling yourself out.
How this req sits in the market our data
Roughly 220 people nationally plausibly meet what this posting asks for (information security analysts). range 65–340
Applicant volume Moderate — A normal amount of company. The rare requirements below are what will separate a shortlisted application from the rest.
Rare in this occupation — lead with these, and say what you built with them.
Most people in this occupation already list these. Still required — just not what gets you shortlisted.
What the occupation pays Median $132,021 (middle half $99,961–$167,095). This posting is about at that midpoint.
Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.
Why we read it this way (10)
The title 'Information Security Architect' carries no explicit seniority level word, so advertised seniority is Unspecified; however, the 8+ years requirement and org-wide architectural authority support a Senior classification.
SOC 15-1212 (Information Security Analysts) is the closest available code for a security architecture role; 15-1299 (Computer Occupations, All Other) is noted as a runner-up since 'Security Architect' sits between analyst and engineering functions not perfectly captured by any single SOC.
Python, Java, and Bash are listed together as 'at least one scripting language (e.g., Python, Java, Bash/shell)' — emitted as a single skill with alternatives.
CISSP, CCSP, and OSCP are listed together as example certifications under the 'We'd Be Delighted' (preferred) section — emitted as one skill with alternatives. Google Cloud Professional Security Engineer is also in that section but is a distinct, separately-marketed credential and is emitted separately.
NIST AI RMF and ISO 42001 are listed together as example AI risk frameworks under the preferred section — emitted as one skill with alternatives.
SAML and OAuth2 appear in the required qualifications as distinct authentication protocols used together; emitted as separate skills.
macOS, Linux, and Windows appear together in the required section as endpoint platforms to protect and administer; emitted as separate skills.
DLP appears both in the preferred enterprise security tools list (as a solution type alongside Splunk, CrowdStrike, etc.) and in the preferred data security section — captured once as preferred.
Stock options are mentioned as part of compensation but no equity range is provided; not representable in the compensation fields.
Ignored 2 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): secrets management, Google Cloud Professional Security Engineer.
Read the full posting
The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.