Security Engineer

Air Apps

City Of London

On-site

GBP 60,000 - 103,000

Full time

12 days ago
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Apple hardware ecosystem for work
Annual Bonus
Top-tier Health and Life Insurance
Transportation Budget
Coverflex benefits package
Childcare support
Air Conference
Pension Fund
Urban Sports Club
Meals 100% free

Job summary

Air Apps, a Lisbon-based AI-driven Personal & Entrepreneurial Resource Planner startup, seeks a Security Engineer to safeguard applications, infrastructure, and data. You will implement secure coding, threat modeling, and vulnerability management in collaboration with cross-functional teams.

The role is fully onsite at our Lisbon office, with relocation support available. Responsibilities include security reviews, CI/CD integration, incident response planning, and ongoing threat monitoring.

Qualifications

  • 4+ years in cybersecurity, application security, or security engineering.
  • Strong knowledge of secure coding principles, OWASP Top 10, and threat modeling techniques.
  • Experience with vulnerability scanning tools (Nessus, Qualys, Burp Suite) and penetration testing methodologies.
  • Hands-on with SIEM, IDS, and security monitoring tools.
  • Proficiency in scripting and automation (Python, Bash, PowerShell).
  • Familiarity with cloud security (AWS, Azure, GCP) including IAM and workload protection.
  • Knowledge of encryption, network security, and API security best practices.
  • Experience with DevSecOps and integrating security into CI/CD pipelines.
  • Ability to analyze security logs, detect anomalies, and communicate security concepts to non-technical stakeholders.

Responsibilities

  • Develop threat modeling to identify security risks across applications and infrastructure.
  • Conduct vulnerability scanning, penetration testing, and security assessments.
  • Define and enforce secure coding practices with development teams.
  • Integrate security into CI/CD pipelines and automate security testing.
  • Monitor security incidents, perform root cause analysis, and implement mitigations.
  • Ensure compliance with security standards (ISO 27001, GDPR, SOC 2).
  • Design IAM policies, encryption standards, and authentication mechanisms.
  • Collaborate on security reviews of features, APIs, and third-party integrations.
  • Develop incident response plans and security documentation.
  • Stay ahead of threats and emerging security technologies.

Skills

Threat modeling
Vulnerability scanning
Penetration testing
Secure coding
CI/CD security
Security monitoring
IAM & encryption
Cloud security
Scripting
Communication of security concepts

Tools

Nessus
Qualys
Burp Suite
SIEM
IDS
Python
Bash
PowerShell

Job description

About Air Apps

At Air Apps, we believe in thinking bigger-and moving faster. We're a family-founded company on a mission to create the world's first AI-powered Personal & Entrepreneurial Resource Planner (PRP), and we need your passion and ambition to help us change how people plan, work, and live. Born in Lisbon, Portugal in 2018-and now with offices in both Lisbon and San Francisco-we've remained self-funded while reaching over 100 million downloads worldwide.

Our long-term focus drives us to challenge the status quo every day, pushing the boundaries of AI-driven solutions that truly make a difference. Here, you'll be a creative force, shaping products that empower people across the globe.

Join us on this journey to redefine resource management-and change lives along the way.

The Role

As a Security Engineer at Air Apps, you will be responsible for safeguarding our applications, infrastructure, and data from threats and vulnerabilities. You will work closely with development, DevOps, and IT teams to implement secure coding practices, vulnerability scanning, and threat modeling to ensure our systems remain resilient against cyber threats.

Your expertise will help build and maintain a secure development lifecycle (SDLC), security monitoring frameworks, and proactive risk mitigation strategies.

  • This is a fully onsite position, based at our office in Lisbon, where you will collaborate closely with cross-functional teams in person and contribute to a dynamic and fast-paced environment. We are open to support with relocation efforts.
Responsibilities
  • Develop and implement threat modeling to identify security risks across applications and infrastructure.
  • Conduct vulnerability scanning, penetration testing, and security assessments to detect weaknesses.
  • Define and enforce secure coding practices in collaboration with development teams.
  • Work with DevOps to integrate security into CI/CD pipelines and automate security testing.
  • Monitor and respond to security incidents, conducting root cause analysis and implementing preventative measures.
  • Ensure compliance with security standards and regulations (e.g., ISO 27001, GDPR, SOC 2).
  • Design and implement identity and access management (IAM) policies, encryption standards, and authentication mechanisms.
  • Collaborate with product teams to conduct security reviews of features, APIs, and third-party integrations.
  • Develop incident response plans, security documentation, and best practices.
  • Stay ahead of emerging threats, vulnerabilities, and security technologies.
Requirements
  • Around 4+ years of experience in cybersecurity, application security, or security engineering.
  • Strong knowledge of secure coding principles, OWASP Top 10, and threat modeling techniques.
  • Experience with vulnerability scanning tools (Nessus, Qualys, Burp Suite) and penetration testing methodologies.
  • Hands-on experience with SIEM, intrusion detection systems (IDS), and security monitoring tools.
  • Proficiency in scripting and automation (Python, Bash, PowerShell) for security tasks.
  • Familiarity with cloud security in AWS, Azure, or GCP, including IAM and workload protection.
  • Knowledge of encryption protocols, network security, and API security best practices.
  • Experience working with DevSecOps, integrating security into CI/CD pipelines.
  • Ability to analyze security logs, detect anomalies, and mitigate potential threats.
  • Excellent problem-solving skills and ability to communicate security concepts to non-technical stakeholders.
What benefits are we offering?
  • Apple hardware ecosystem for work.
  • Annual Bonus
  • Top-tier Health and Life Insurance for peace of mind.
  • Transportation Budget to support your commute needs.
  • Coverflex benefits package for meal allowances, well-being, and more.
  • Childcare support.
  • Air Conference - an opportunity to meet the team, collaborate, and grow together.
  • Pension Fund to support your long-term financial planning.
  • Urban Sports Club membership to keep you active.
  • Meals 100% free at the hub.
Diversity & Inclusion

At Air Apps, we are committed to fostering a diverse, inclusive, and equitable workplace. We enthusiastically welcome applicants from all backgrounds, experiences, and perspectives. We celebrate diversity in all its forms and believe that varied voices and experiences make us stronger.

Application Disclaimer

At Air Apps, we value transparency and integrity in our hiring process. Applicants must submit their own work without any AI-generated assistance. Any use of AI in application materials, assessments, or interviews will result in disqualification.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Financial Analyst
Financial Analyst

Air Apps • City Of London

On-site
GBP 27,000 - 36,000
Apple hardware ecosystem
Flexible Paid Time Off
Annual Bonus
+7
Financial Controller
Financial Controller

Air Apps • City Of London

On-site
GBP 56,000 - 77,000
Apple hardware ecosystem for work
Annual Bonus
Health and Life Insurance
+6
Security Engineer (Product Security)
Security Engineer (Product Security)

Aircall • Greater London

On-site
GBP 60,000 - 80,000
Competitive salary package
Work-life balance
Fast-learning environment
+1
Principal Security Architect
Principal Security Architect

Artificial Labs Ltd • Greater London

Hybrid
GBP 110,000 - 160,000
Private medical insurance
Income protection insurance
Life insurance
+11
Security Engineer, SDO AppSec
Security Engineer, SDO AppSec

AMAZON UK • Greater London

On-site
GBP 90,000 - 120,000
Senior Product Security Engineer
Senior Product Security Engineer

Cloudflare • Greater London

On-site
GBP 120,000 - 180,000
Medical/Rx Insurance
Dental Insurance
Vision Insurance
+4
Solution Engineer, Air
Solution Engineer, Air

Applied Intuition • Greater London

On-site
GBP 90,000 - 120,000
Senior Application Security Engineer
Senior Application Security Engineer

Cloudsmith • Belfast City District

On-site
GBP 90,000 - 130,000
Equity
Health, dental, vision insurance
Generous annual leave
+3
Azure Principal Platform Engineer - UK Security Clearance eligibility required
Azure Principal Platform Engineer - UK Security Clearance eligibility required

Appvia • Greater London

Hybrid
GBP 90,000 - 120,000
Private healthcare
Pension
25 days holiday a year (plus bank hols
+5
Azure Senior Platform Engineer - UK Security Clearance eligibility required
Azure Senior Platform Engineer - UK Security Clearance eligibility required

Appvia • Greater London

Hybrid
GBP 75,000 - 90,000
Hybrid work model
25 days holiday a year
Private healthcare cover
+5