08 oct
|
Ryanair Group Holdings
|
Madrid
08 oct
Ryanair Group Holdings
Madrid
Job Description
About the role
A senior, self-directed architect in a lean airline security team. You work without day-to-day supervision: you find where the team spends effort on repeatable work, decide what to automate, build it and measure the result. You own the security architecture for the AI systems we build and buy, and you take a lead role in strategic security initiatives across on-prem and multicloud (AWS, GCP, Azure). You still build: automation, policy-as-code and proofs of concept, not only documents.
How you'll work: find → design → build → verify → evolve
- Find. Independently map how the security team works detection, incident response, vulnerability management, pentesting, IAM, compliance and spot repeatable manual work, weak controls and gaps; threat-model new AI systems and initiatives (MITRE ATLAS, MITRE ATT&CK;, OWASP).
- Design. Automation and architecture patterns with explicit trade-offs: data boundaries, identity for humans and agents, least-privilege tool access, guardrails, human-in-the-loop for decisions.
- Build. Ship it yourself or alongside engineers: agentic workflows, integrations, IaC and policy-as-code, proofs of concept.
- Verify. Validate with the pentest and detection teams; measure hours removed, error rates and coverage.
- Evolve. Keep a roadmap and metrics; update patterns as the AI and threat landscape shifts.
What you'll do
Automate the security team
- Build agentic and scripted automation for alert enrichment and triage, incident timeline assembly, vulnerability-to-owner routing and remediation tracking, pentest recon and reporting,
access reviews and joiner/mover/leaver checks, audit evidence collection, threat-intel ingestion, log-source onboarding and policy-as-code checks.
- Integrate security tooling via APIs and MCP; keep humans in the loop for decisions; track toil removed.
- Make LLM assistants and agentic coding tools (Claude Code, OpenCode) productive and governed for the team: safe-use standards, data-handling boundaries, shared patterns.
AI security architecture
- Secure patterns for LLM apps, RAG pipelines, agents and MCP/tool integrations: prompt-injection and data-leakage defences, non-human identity and least privilege, logging that feeds detection.
- AI governance in practice: AI system inventory, approval path for new AI tools and vendors, model and vendor risk assessment, shadow-AI discovery with the detection team.
Security initiatives (examples)
- Zero-trust and identity modernisation: phishing-resistant MFA, conditional access, privileged access management, non-human identities.
- Multicloud security baseline across AWS, GCP and Azure: landing zones, guardrails and policy-as-code, logging baseline into the SIEM.
- Secure SDLC / DevSecOps: SAST, DAST, SCA and secrets management in CI/CD.
- Network segmentation between corporate, passenger-facing and airport/ground operational systems.
- SaaS security posture and supplier/third-party access.
- Data protection for passenger and crew data; PCI scope reduction.
- Ransomware resilience: backup immutability and recovery testing.
- Regulatory readiness: gap assessments, control mapping and evidence automation for applicable security regulations and standards.
📌 Information Security Architect - AI & Strategic Initiatives (Madrid)
🏢 Ryanair Group Holdings
📍 Madrid