The threat surface of a low-cost carrier is deceptively wide: an airline's attack vectors don't stop at the cockpit door. Breeze Airways operates nonstop flights on underserved U.S. routes using a mixed fleet of Airbus and Embraer aircraft, with nine maintenance bases spread across the country. Each of those nodes - crew scheduling systems, loyalty databases, ticketing APIs, operational technology on the tarmac - represents a distinct domain that needs defending. The company runs its own technology stack in-house rather than outsourcing it, meaning the security team isn't just bolting on third-party controls but is embedded in the build.
Breeze's model is point-to-point, deliberately bypassing hub-and-spoke congestion, which keeps operations lean but geographically distributed. That distribution extends to the digital estate: reservation platforms for the Breezy Rewards loyalty program, customer-facing booking systems, and backend airline operations all live within scope. For a cybersecurity professional, the job is to protect those systems across the full lifecycle - from application security and identity management to incident response - without the luxury of a massive legacy security org to lean on.
The company was founded by David Neeleman and positions itself around simplicity and affordability. That ethos trickles into engineering: fewer layers, faster iteration, and a need for security practitioners who can operate in a resource-constrained, high-velocity environment where the blast radius of a breach spans both data and physical operations.






