Remote job
Information Security Architect
Job details
About this role
Role overview This Information Security Architect role owns the design and evolution of security architecture across cloud infrastructure, applications, and the CI/CD pipeline at a company running on Google Cloud Platform. It is a hands-on architecture position focused on secure-by-design systems, partnering with Engineering, Platform, and Product to embed security into every phase of the development lifecycle. A key responsibility is evaluating emerging AI and generative AI platforms to identify risks and define secure adoption patterns.
Responsibilities - Design and maintain security architecture, including reference architectures, secure design patterns, and technical security standards - Conduct security architecture reviews for enterprise applications, cloud platforms, infrastructure services, and technology integrations - Run threat modeling and technical risk assessments to identify gaps and recommend mitigations - Define and implement cloud security guardrails, network segmentation patterns, logging standards, and access control models across the GCP environment - Partner with Engineering and DevOps to integrate security into the CI/CD pipeline, covering secure builds, container security, infrastructure-as-code security, secrets management, and software supply chain integrity - Evaluate proposed architecture changes from engineering teams and analyze their security impact - Assess emerging AI platforms, generative AI tools, and AI-assisted development technologies to identify risks and define secure usage patterns - Develop security guidance for API security, application authentication (SAML, OAuth2), encryption, and identity and access management - Mentor colleagues across the organization on secure design principles and best practices - Participate in a security on-call rotation and respond to incidents
Requirements - 8+ years in information security, security architecture, cloud security engineering, or a related technical discipline - Deep expertise in Google Cloud Platform security, including native capabilities, cloud architecture patterns, and workload protection - Hands-on experience securing CI/CD pipelines, including container security, infrastructure-as-code security, secrets management, and DevSecOps - Experience conducting threat modeling for complex distributed systems using standard methodologies - Experience performing security architecture and design reviews for cloud-native applications and infrastructure - Proficiency in at least one scripting language such as Python, Java, or Bash/shell - Working knowledge of network security concepts including segmentation, Zero Trust, firewalls, and access control models - Working knowledge of identity and access management, including SSO, MFA, federation, and least-privilege access - Strong understanding of application security, including OWASP, API security, secure SDLC, and authentication protocols (SAML, OAuth2) - Working knowledge of how to protect and administer macOS, Linux, and Windows systems - Strong written and verbal communication skills
Benefits and work setup - Fully remote, digital-first culture with flexible work across timezones - Competitive medical, dental, and vision insurance for you and your dependents - Flexible time off, company-paid holidays, paid parental leave, and paid volunteer time off - Mental health and wellness resources, employer-subsidized life insurance, and short- and long-term disability - Monthly stipend to support remote work - Stock options included as part of every offer, plus mentorship and growth opportunities - This is a path toward senior security architecture, security leadership, or deeper cloud security specialization