Ryanair Group Holdings logo

Information Security Architect - AI & Strategic Initiatives

Hiring from
Spain
Work type
Hybrid
Posted
Is this job info correct?
Show job description

Ryanair Labs are currently recruiting two Information Security Architect to join Europe’s Largest Airline Group!

This is a very exciting time to join Ryanair as we look to expand our operation to 800 aircraft and 300 million guests within the next 10 years.

Ryanair Labs is the technology brand of Ryanair. Labs is a state of-the-art digital & IT innovation hub creating Europe’s Leading Travel Experience for our customers.

About the role
A senior, self-directed architect in a lean airline security team. You work without day-to-day supervision: you find where the team spends effort on repeatable work, decide what to automate, build it and measure the result. You own the security architecture for the AI systems we build and buy, and you take a lead role in strategic security initiatives across on-prem and multicloud (AWS, GCP, Azure). You still build: automation, policy-as-code and proofs of concept, not only documents.

How you'll work: find → design → build → verify → evolve

  • Find. Independently map how the security team works detection, incident response, vulnerability management, pentesting, IAM, compliance and spot repeatable manual work, weak controls and gaps; threat-model new AI systems and initiatives (MITRE ATLAS, MITRE ATT&CK, OWASP).
  • Design. Automation and architecture patterns with explicit trade-offs: data boundaries, identity for humans and agents, least-privilege tool access, guardrails, human-in-the-loop for decisions.
  • Build. Ship it yourself or alongside engineers: agentic workflows, integrations, IaC and policy-as-code, proofs of concept.
  • Verify. Validate with the pentest and detection teams; measure hours removed, error rates and coverage.
  • Evolve. Keep a roadmap and metrics; update patterns as the AI and threat landscape shifts.

What you'll do

Automate the security team

  • Build agentic and scripted automation for alert enrichment and triage, incident timeline assembly, vulnerability-to-owner routing and remediation tracking, pentest recon and reporting, access reviews and joiner/mover/leaver checks, audit evidence collection, threat-intel ingestion, log-source onboarding and policy-as-code checks.
  • Integrate security tooling via APIs and MCP; keep humans in the loop for decisions; track toil removed.
  • Make LLM assistants and agentic coding tools (Claude Code, OpenCode) productive and governed for the team: safe-use standards, data-handling boundaries, shared patterns.

AI security architecture

  • Secure patterns for LLM apps, RAG pipelines, agents and MCP/tool integrations: prompt-injection and data-leakage defences, non-human identity and least privilege, logging that feeds detection.
  • AI governance in practice: AI system inventory, approval path for new AI tools and vendors, model and vendor risk assessment, shadow-AI discovery with the detection team.

Security initiatives (examples)

  • Zero-trust and identity modernisation: phishing-resistant MFA, conditional access, privileged access management, non-human identities.
  • Multicloud security baseline across AWS, GCP and Azure: landing zones, guardrails and policy-as-code, logging baseline into the SIEM.
  • Secure SDLC / DevSecOps: SAST, DAST, SCA and secrets management in CI/CD.
  • Network segmentation between corporate, passenger-facing and airport/ground operational systems.
  • SaaS security posture and supplier/third-party access.
  • Data protection for passenger and crew data; PCI scope reduction.
  • Ransomware resilience: backup immutability and recovery testing.
  • Regulatory readiness: gap assessments, control mapping and evidence automation for applicable security regulations and standards.

Must have

  • 6+ years in security, including 3+ in architecture or senior engineering roles, with an engineering background you still use.
  • Demonstrated autonomy: examples of automation or initiatives you identified, built and shipped on your own initiative, with measured results.
  • Deep understanding of how LLM applications, RAG, agents and tool/MCP integrations are built, and of their attack surface (OWASP Top 10 for LLM Applications, agentic-AI threat guidance, MITRE ATLAS).
  • Multicloud architecture across AWS, GCP and Azure: identity, network, logging, policy-as-code.
  • Identity and zero-trust architecture, including workload and non-human identities.
  • Threat modelling, secure design and secure SDLC practice.
  • Hands-on skills: Python, APIs, IaC; effective daily use of LLM assistants and agentic coding tools (e.g., Claude Code, OpenCode) with critical validation of output.
  • Track record of leading cross-functional initiatives without formal authority: roadmap, business case, delivery.
  • Clear communication with executives and engineers alike.

Nice to have

  • Aviation, logistics or other regulated-sector experience.
  • EU AI Act, ISO/IEC 42001 and NIST AI RMF in practice.
  • Strongly valued: contributions to, or research on, AI security red-teaming agents, guardrail frameworks, agent security patterns, open-source, publications or talks.
  • Data security and privacy architecture (PII, PCI); SaaS security.
  • OT/ICS and safety-critical system security for airport and ground systems.
  • Certifications: CISSP, CCSP, SABSA or TOGAF; cloud architecture/security (AZ-305, AZ-500, AWS Solutions Architect Professional, AWS Security Specialty, Google Professional Cloud Security Engineer or Cloud Architect).
  • A competitive but flexible technical career plan.
  • Possibility for career growth in a continuously growing team.
  • We believe in a hybrid working model, you can work up to three days per week remote, but you are also going to enjoy the excellent work environment at our modern offices in the heart of Madrid
  • Optional discounts on health insurances (various companies).
  • Travel discounts, of course!

Similar jobs

Apply for this job