Source Job

$130,000–$160,000/yr
US Unlimited PTO

  • Design and evolve security architecture across cloud infrastructure, applications, and CI/CD pipeline.
  • Conduct threat modeling, architecture reviews, and define secure design patterns for GCP-based environment.
  • Evaluate emerging technologies like AI and GenAI platforms to identify risks and define secure adoption patterns.

Threat Modeling Application Security Python

20 jobs similar to Information Security Architect

Jobs ranked by similarity.

India

  • Partner with engineering, product, and DevOps teams to integrate security practices throughout the SDLC, focusing on cloud-native environments and automated pipelines.
  • Design, implement, and maintain security tooling and gates within CI/CD pipelines covering SAST, DAST, SCA, secrets detection, and container scanning.
  • Lead threat modeling, conduct application security assessments including code review and manual penetration testing, and triage bug bounty reports.

Hyland is the pioneer of the Content Innovation Cloud, delivering ubiquitous enterprise intelligence to organizations. With a team of nearly 4,000 employees, the company fosters an employee-centric culture focused on community impact and innovation.

$83,922–$116,586/yr
UK

  • Design and automate controls, detection mechanisms, and tooling to improve Information Security of Algolia's infrastructure and products.
  • Partner with engineering and product teams to integrate Information Security into new features, systems, and development pipelines.
  • Conduct Information Security risk assessments and threat models of core systems, services, and third-party vendors.

Algolia is a pioneer and market leader in AI Search, empowering 17,000+ businesses with blazing-fast, predictive search experiences. The company raised $150M in Series D funding, quadrupling its valuation to $2.25B, and has a global team with offices in Paris, NYC, London, Sydney, and Bucharest.

Canada

  • Design and ship scalable security solutions to bridge the gap between security and engineering teams.
  • Build cooperative partnerships with product and engineering teams to integrate robust security capabilities at scale.
  • Drive security risk reduction through technical leadership, security reviews, and mentorship across engineering teams.

Twilio is a communications platform that delivers innovative solutions to hundreds of thousands of businesses and empowers millions of developers worldwide to craft personalized customer experiences. The company has a remote-first work culture with a strong focus on connection, global inclusion, and diverse experiences, making a global impact each day.

$125,000–$152,000/yr
US

  • Bridge the gap between traditional infrastructure security and modern DevSecOps, defining secure-by-design frameworks and implementing high-impact DevSecOps pipelines across multi-cloud environments.
  • Lead critical security reviews for emerging technologies, including artificial intelligence, and act as a collaborative partner to internal teams fostering proactive security and cyber vigilance.
  • Manage security lifecycles within multi-cloud environments, own the end-to-end vulnerability management program, and leverage SIEM platforms for real-time threat intelligence.

NPR is a thriving, mission-driven multimedia organization that produces award-winning news, information, and music programming in partnership with hundreds of independent public radio stations across the nation. They are innovators and leaders in diverse fields, from journalism and digital media to IT and development, committed to building an inclusive workplace where collaboration is essential and diverse voices are heard.

  • Owns product, cloud, engineering, vendor, AI-tooling, and compliance security functions.
  • Builds practical guardrails for AI tools, agents, MCPs, data leakage, and automation.
  • Understands OWASP, IAM, secrets, cloud security, vulnerability management, CI/CD, incident response, and frameworks like SOC 2, ISO 27001, GDPR, or HIPAA.

PlayPower Labs is a company focused on building practical security functions without slowing down teams. The organization values security sharpness, usefulness, and a product-minded approach, with a culture that balances protection and agility.

India

  • Integrate and automate security controls into CI/CD pipelines for continuous vulnerability scanning and secure software delivery.
  • Design, implement, and maintain secure Infrastructure as Code across GCP environments, enforcing IAM and network security policies.
  • Drive compliance and continuous auditing, acting as technical point for PCI-DSS and SOC 2 evidence collection.

Zact is a leading fintech innovator specializing in cutting-edge payments apps. They are a remote-first company with a focus on hiring in India, fostering a security-first engineering culture.

$145,000–$175,000/yr
United States

  • Strengthen company-wide security posture through hands-on engineering, collaboration, and pragmatic standards, focusing on application security, cloud and infrastructure security, and secure development practices.
  • Define and implement scalable security standards supporting SOC 2 readiness through practical, automated, and auditable solutions, partnering with Engineering, Infrastructure, IT, Product, Legal, and other teams.
  • Build and maintain internal security tools, automation, and services that support secure development, compliance workflows, vulnerability management, and operational visibility.

Later is the world’s most intelligent influencer marketing company, built to give brands the confidence to create unforgettable campaigns by combining real creator relationships, trusted intelligence, and expert guidance. Trusted by leading enterprise brands including Nike, Wayfair, Unilever, and Southwest Airlines, Later bridges creativity and performance so campaigns deliver results.

US 24w maternity 24w paternity

  • Own the end-to-end GRC strategy and roadmap, driving compliance maturity and reducing audit risk.
  • Design and implement policy-as-code systems, translating compliance frameworks into enforceable code.
  • Lead full audit cycles, manage evidence collection, and architect GRC platform strategy for continuous compliance.

Smartsheet empowers teams to manage work and scale solutions, now uniting human teams with AI agents to automate tasks and uncover insights. With a history of over 20 years, the company fosters a culture of inclusion, creativity, and big thinking, offering professional growth and a supportive environment.

Europe US Unlimited PTO

  • Triage, validate, and remediate security vulnerabilities across products, infrastructure, and internal systems.
  • Develop, maintain, and contribute to internal and open-source security tooling, writing production-grade code.
  • Improve secure development practices through code reviews, threat modeling, and security design reviews.

Tiger Data provides the fastest PostgreSQL platform for transactional, analytical, and agentic workloads. With over 2,000 customers and 3 million active databases, it is a remote-first team backed by $180 million in funding.

$230,000–$250,000/yr
United States Unlimited PTO 12w maternity 12w paternity

  • Own our approach to AI and agentic security: guardrails for agentic access to cloud and data, and the security of AI/ML workloads.
  • Own our detection platform (Panther): detection strategy and coverage across cloud, container, and SaaS log sources.
  • Act as the senior security resource across cloud security and security reviews, mentoring teammates.

SmarterDx is a clinical AI platform that helps health systems capture revenue and improve quality metrics using clinically-validated EHR data. The company is a remote-first team with a small, collaborative engineering culture focused on making healthcare more accurate and effective.

$120,000–$154,440/yr
US 12w maternity 12w paternity

  • Architect, design, and implement end-to-end security solutions including firewalls, intrusion detection, and cloud security controls.
  • Collaborate with DevOps to integrate security into CI/CD pipelines and automate secure deployments.
  • Conduct regular security assessments, threat modeling, and architecture reviews to identify risks and design mitigations.

Figure is transforming capital markets through blockchain, powering real products used by hundreds of thousands of consumers and institutions. With over 170 partners and $22 billion in home equity loans originated, Figure is the largest non-bank provider of home equity financing in the U.S., recognized as one of Forbes' Most Innovative Fintech Startups in 2025.

Poland

  • Monitor and investigate security alerts in AWS infrastructure, respond to incidents affecting the product platform.
  • Automate security operations using Python or Go, and configure tools like WAF, GuardDuty, and Security Hub.
  • Collaborate with engineering teams to prioritize vulnerabilities, conduct threat modeling, and guide secure coding practices.

Tripadvisor connects global travelers to experiences worth sharing through its brands, technology, and marketplaces. As a publicly traded company with a portfolio including Viator and TheFork, it fosters a culture of collaboration, trust, and remote-friendly flexibility.

US

  • Secure AI systems and use AI to scale security, conducting security reviews and threat modeling of AI-integrated product features.
  • Deliver end-to-end application security reviews for high-risk features, working directly with engineering teams to surface and close risk.
  • Advance CI/CD pipeline security by operating and evolving security scanning controls in GitLab pipelines.

Smartsheet empowers teams to manage work and scale solutions by uniting human teams with AI agents. They are a large company with over 20 years of experience, fostering a culture where ideas are heard and contributions have real impact.

India

  • Lead security initiatives across infrastructure, applications, cloud, and enterprise deployments to ensure a strong security posture.
  • Conduct penetration testing, vulnerability assessments, and security reviews to proactively identify and mitigate risks.
  • Collaborate with engineering, DevOps, and machine learning teams to embed security best practices into products and processes.

The company develops innovative AI-driven products for highly regulated environments. They operate with a startup culture, emphasizing collaboration, autonomy, and continuous improvement.

Mexico

  • Drive security engineering initiatives and embed security across engineering teams.
  • Manage threats and respond to incidents with advanced automation and AI agents.
  • Architect secure solutions for AI/ML workloads and mentor team members.

EarnIn is a pioneer of earned wage access, building products that deliver real-time financial flexibility for those living paycheck to paycheck. They have an experienced leadership team and world-class funding partners, and are growing fast with a healthy core business.

Netherlands

  • Design, implement, and optimize security monitoring, incident response, and detection capabilities across modern cloud and infrastructure ecosystems.
  • Build and maintain SIEM and log management capabilities, ensuring centralized log collection, normalization, and retention policies.
  • Automate operational security processes such as alert enrichment, incident notifications, and response orchestration.

Jobgether is an AI-powered job matching platform that connects candidates with hiring companies. They operate as a partner company managing applications and next steps, fostering a collaborative, transparent, and innovation-driven culture with a focus on professional growth and well-being.

India

  • Lead security discovery workshops and translate high-level architectural requirements into actionable security roadmaps.
  • Design end-to-end cloud security frameworks and document controls for SOC 2 and HITRUST compliance.
  • Establish governance and security processes for AI and manage vulnerability remediation with development teams.

Ollion is a global technology partner that helps organizations solve their toughest business challenges in AI, data, and cloud. They are a remote-first, globally distributed team focused on making a world of difference through innovation and collaboration.

United States Unlimited PTO

  • Partner with the CISO to drive security strategy, roadmap, and execution across application security, GRC, and operations.
  • Support compliance initiatives including PCI, SOC 2, ISO 27001, DORA, and FedRAMP readiness.
  • Serve as a trusted security leader in customer-facing settings, translating technical risks into business language.

Sardine is the leading agentic risk platform for fighting financial crime, integrating data across risk teams to stop fraud and automate AML operations. With over 6 billion profiled devices and 800 million consumers, we maintain a remote-first culture that values performance over hours worked.

$200,000–$220,000/yr
US

  • Embed security into every stage of software delivery across multi-cloud environments (AWS, Azure) as a hands-on technical leader.
  • Architect secure, scalable infrastructure, set engineering standards, and mentor a team of DevSecOps engineers.
  • Champion a shift-left security culture, integrate AI-powered tooling, and partner with cross-functional teams to align secure cloud solutions with business objectives.

ComPsych is the worldwide leader in organizational mental health, well-being, and absence management, dedicated to igniting human potential in workplaces across the globe. For over 40 years, they have combined technology with human expertise to support more than 75,000 customers worldwide, touching over 160 million lives across 200 countries.

UK 4w PTO

  • Lead security strategy and develop scalable practices to protect systems, products, and customers.
  • Partner with engineering teams to improve resilience, reduce risk, and embed security into development.
  • Manage security incidents, evaluate emerging technologies, and build a high-performing security team.

The company is a fast-growing technology firm focused on innovation and engineering excellence. It operates with a distributed international team and emphasizes trust, autonomy, and ownership.