Apply now »

Are you an internal JetBlue Crewmember? Click here to apply.

Title:  Architect Product Security

Location: 

Long Island City, NY, US, 11101 Washington, DC, US, 20005 Orlando, FL, US, 32827 Salt Lake City, UT, US, 84121

Req ID:  58543
Category:  Information Technology

 

 

Position Summary

The Architect, Product Security partners with product and engineering teams to design and deliver secure applications, APIs, and digital services. This role embeds security into product design and development by providing hands-on guidance, conducting threat modeling, and helping teams implement secure-by-design practices across the SDLC. The Architect operates as a hands-on security partner to product teams. The role focuses on secure-by-design principles, practical risk reduction, and enabling delivery teams to build resilient, scalable, and secure products without unnecessary friction.

Essential Responsibilities

  • Define and implement security architecture patterns for applications, APIs, cloud services, and platforms
  • Develop secure design standards, reference architectures, and reusable patterns
  • Ensure alignment with enterprise architecture and security strategy
  • Embed security controls into Continuous Integration/Continuous Deployment pipelines and developer workflows
  • Define and enforce secure coding practices and product security requirements
  • Enable automation of security testing and validation (Static Application Security Testing, Dynamic Application Security Testing, Secure Code Analysis)
  • Conduct and facilitate threat modeling sessions across product teams
  • Identify architectural risks and define practical mitigation strategies
  • Translate enterprise risk posture into product-level decisions and tradeoffs
  • Define and guide application security testing strategies
  • Partner with engineering teams to prioritize and remediate vulnerabilities
  • Support penetration testing and security validation activities
  • Architect controls for Authentication, Data protection and service security
  • Support adoption of Zero Trust principles
  • Partner with: Product Managers, Software Engineers, Platform and Cloud teams
  • Other duties as assigned    

Minimum Experience and Qualifications

  • Bachelor’s Degree in a relevant field; OR demonstrated capability to perform job responsibilities with a High School Diploma/GED and at least four (4) years of previous relevant work experience
  • Four (4) years of experience in Application security, product security, or security architecture
  • Experience designing and securing: Cloud-native and distributed systems, and APIs and microservices architectures
  • Experience designing or securing modern applications, APIs, cloud services, distributed systems, or digital platforms
  • Strong ability to operate in fast-paced product and engineering environments
  • Ability to manage multiple priorities in a fast-paced, multi-team environment
  • Available for occasional overnight travel (10%)
  • Must pass a pre-employment drug test
  • Must be legally eligible to work in the country in which the position is located
  • Authorization to work in the US is required, this position is not eligible for visa sponsorship

Preferred Experience and Qualifications

  • Experience supporting customer-facing applications, digital platforms, mobile applications, ecommerce, loyalty, APIs, or cloud-native services.
  • Experience in aviation, transportation, financial services, or another regulated or operationally complex environment.
  • Familiarity with AWS, Azure, GCP, Kubernetes, containers, serverless platforms, API gateways, WAF technologies, secrets management, and CI/CD tooling.
  • Experience with SAST, DAST, SCA, or application security posture management tools.
  • Knowledge of OWASP Top 10, OWASP API Security Top 10, OWASP ASVS, NIST Cybersecurity Framework, NIST 800-53, NIST 800-63, CIS Benchmarks, ISO 27001, or similar frameworks.
  • Experience contributing to secure design standards, architecture patterns, product security checklists, or developer security guidance.
  • CISSP, CSSLP, CCSP, AWS Security Specialty, Azure Security Engineer, or equivalent certification preferred.

Crewmember Expectations:

  • Regular attendance and punctuality
  • Potential need to work flexible hours and be available to respond on short-notice
  • Able to maintain a professional appearance
  • When working or traveling on JetBlue flights, and if time permits, all capable crewmembers are asked to assist with light cleaning of the aircraft
  • Must be an appropriate organizational fit for the JetBlue culture, that is, exhibit the JetBlue values of Safety, Caring, Integrity, Passion and Fun
  • Promote JetBlue's #1 value of safety as a Safety Ambassador, supporting JetBlue's Safety Management System (SMS) components, Safety Policy and behavioral standards
  • Identify safety and security concerns, issues, incidents or hazards that should be reported and report them whenever possible and by any means necessary including JetBlue's confidential reporting systems (Aviation Safety Action Program (ASAP) or Safety Action Report (SAR))
  • The use of ChatGPT or any other automated tool during the interview process will disqualify a candidate from being considered for the position.

Equipment:

  • Computer and other office equipment

Work Environment:

  • Traditional office environment

Physical Effort: 

  • Generally not required, or up to 10 pounds occasionally, 0 pounds frequently. (Sedentary)

Compensation:

  • The base pay range for this position is between $105,600.00 and $150,400.00 per year. Base pay is one component of JetBlue’s total compensation package, which may also include access to healthcare benefits, a 401(k) plan and company match, crewmember stock purchase plan, short-term and long-term disability coverage, basic life insurance, free space available travel on JetBlue, and more.

 

#LI-AC1

#LI-Hybrid

JetBlue Airways is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, age, national origin, disability, protected veteran status, or any other legally protected basis.


Nearest Major Market: Brooklyn
Nearest Secondary Market: New York City

Apply now »