# Security Engineer

[Airapps](https://gurify.com/jobs?q=Airapps) · Madrid · Posted 4 months ago

[Security](https://gurify.com/jobs/security)

[Apply on the original posting → (opens in a new tab)](https://jobs.ashbyhq.com/airapps/3981c599-be19-4ab4-9932-326585575385)

## Job description

### ABOUT AIR APPS

At Air Apps, we believe in thinking bigger—and moving faster. We’re a family-founded company on a mission to create the world’s first AI-powered Personal & Entrepreneurial Resource Planner (PRP), and we need your passion and ambition to help us change how people plan, work, and live. Born in Lisbon, Portugal in 2018—and now with offices in both Lisbon and San Francisco—we’ve remained self-funded while reaching over 100 million downloads worldwide.

Our long-term focus drives us to challenge the status quo every day, pushing the boundaries of AI-driven solutions that truly make a difference. Here, you’ll be a creative force, shaping products that empower people across the globe.

Join us on this journey to redefine resource management—and change lives along the way.

### THE ROLE

As a Security Engineer at Air Apps, you will be responsible for safeguarding our applications, infrastructure, and data from threats and vulnerabilities. You will work closely with development, DevOps, and IT teams to implement secure coding practices, vulnerability scanning, and threat modeling to ensure our systems remain resilient against cyber threats.

Your expertise will help build and maintain a secure development lifecycle (SDLC), security monitoring frameworks, and proactive risk mitigation strategies.

- This is a fully onsite position, based at our office in Lisbon, where you will collaborate closely with cross-functional teams in person and contribute to a dynamic and fast-paced environment. We are open to support with relocation efforts.

### RESPONSIBILITIES

- Develop and implement threat modeling to identify security risks across applications and infrastructure.

- Conduct vulnerability scanning, penetration testing, and security assessments to detect weaknesses.

- Define and enforce secure coding practices in collaboration with development teams.

- Work with DevOps to integrate security into CI/CD pipelines and automate security testing.

- Monitor and respond to security incidents, conducting root cause analysis and implementing preventative measures.

- Ensure compliance with security standards and regulations (e.g., ISO 27001, GDPR, SOC 2).

- Design and implement identity and access management (IAM) policies, encryption standards, and authentication mechanisms.

- Collaborate with product teams to conduct security reviews of features, APIs, and third-party integrations.

- Develop incident response plans, security documentation, and best practices.

- Stay ahead of emerging threats, vulnerabilities, and security technologies.

### REQUIREMENTS

- Around 4+ years of experience in cybersecurity, application security, or security engineering.

- Strong knowledge of secure coding principles, OWASP Top 10, and threat modeling techniques.

- Experience with vulnerability scanning tools (Nessus, Qualys, Burp Suite) and penetration testing methodologies.

- Hands-on experience with SIEM, intrusion detection systems (IDS), and security monitoring tools.

- Proficiency in scripting and automation (Python, Bash, PowerShell) for security tasks.

- Familiarity with cloud security in AWS, Azure, or GCP, including IAM and workload protection.

- Knowledge of encryption protocols, network security, and API security best practices.

- Experience working with DevSecOps, integrating security into CI/CD pipelines.

- Ability to analyze security logs, detect anomalies, and mitigate potential threats.

- Excellent problem-solving skills and ability to communicate security concepts to non-technical stakeholders.

WHAT BENEFITS ARE WE OFFERING?

- Apple hardware ecosystem for work.

- Annual Bonus

- Top-tier Health and Life Insurance for peace of mind.

- Transportation Budget to support your commute needs.

- Coverflex benefits package for meal allowances, well-being, and more.

- Childcare support.

- Air Conference - an opportunity to meet the team, collaborate, and grow together.

- Pension Fund to support your long-term financial planning.

- Urban Sports Club membership to keep you active.

- Meals 100% free at the hub.

### DIVERSITY & INCLUSION

At Air Apps, we are committed to fostering a diverse, inclusive, and equitable workplace. We enthusiastically welcome applicants from all backgrounds, experiences, and perspectives. We celebrate diversity in all its forms and believe that varied voices and experiences make us stronger.

### APPLICATION DISCLAIMER

At Air Apps, we value transparency and integrity in our hiring process. Applicants must submit their own work without any AI-generated assistance. Any use of AI in application materials, assessments, or interviews will result in disqualification.

**Live in Airapps’s hiring system.** Read from the company's own applicant tracking system, not reposted from a job board — so it's a real, open requisition rather than an ad that outlived the role.

We remove it as soon as it disappears at source.

## More jobs like this

- DL [Senior Network & Edge Security Engineer](https://gurify.com/job/senior-network-edge-security-engineer-at-dlocal-5faf7ca75e99) Dlocal · Madrid · 4 weeks ago
- BR [Senior Security Engineer II](https://gurify.com/job/senior-security-engineer-ii-at-braze-429a7f0aab84) Braze · Atlanta · last week
- MO [Senior Developer Experience Security Engineer](https://gurify.com/job/senior-developer-experience-security-engineer-at-motorway-8088847ce3c6) Motorway · London · 3 days ago
- DA [Senior Security Engineer](https://gurify.com/job/senior-security-engineer-at-dashlane-fa6de436e6bf) Dashlane · Paris, France · last week
- VE [Senior Infrastructure and Cloud Security Engineer](https://gurify.com/job/senior-infrastructure-and-cloud-security-engineer-at-veo-f33c3b67f7e7) Veo · Copenhagen · last week
- CL [Network Security Engineer](https://gurify.com/job/network-security-engineer-at-classiq-8fadbac800f5) Classiq · Tel Aviv-Yafo, Israel · 5 days ago

```json
{"@context":"https://schema.org/","@type":"JobPosting","title":"Security Engineer","description":"\u003Ch3\u003EABOUT AIR APPS\u003C/h3\u003E\u003Cp\u003EAt Air Apps, we believe in thinking bigger\u2014and moving faster. We\u2019re a family-founded company on a mission to create the world\u2019s first AI-powered Personal \u0026amp; Entrepreneurial Resource Planner (PRP), and we need your passion and ambition to help us change how people plan, work, and live. Born in Lisbon, Portugal in 2018\u2014and now with offices in both Lisbon and San Francisco\u2014we\u2019ve remained self-funded while reaching over 100 million downloads worldwide.\u003C/p\u003E\u003Cp\u003EOur long-term focus drives us to challenge the status quo every day, pushing the boundaries of AI-driven solutions that truly make a difference. Here, you\u2019ll be a creative force, shaping products that empower people across the globe.\u003C/p\u003E\u003Cp\u003EJoin us on this journey to redefine resource management\u2014and change lives along the way.\u003C/p\u003E\u003Ch3\u003ETHE ROLE\u003C/h3\u003E\u003Cp\u003EAs a Security Engineer at Air Apps, you will be responsible for safeguarding our applications, infrastructure, and data from threats and vulnerabilities. You will work closely with development, DevOps, and IT teams to implement secure coding practices, vulnerability scanning, and threat modeling to ensure our systems remain resilient against cyber threats.\u003C/p\u003E\u003Cp\u003EYour expertise will help build and maintain a secure development lifecycle (SDLC), security monitoring frameworks, and proactive risk mitigation strategies.\u003C/p\u003E\u003Cul\u003E\u003Cli\u003EThis is a fully onsite position, based at our office in Lisbon, where you will collaborate closely with cross-functional teams in person and contribute to a dynamic and fast-paced environment. We are open to support with relocation efforts.\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003ERESPONSIBILITIES\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003EDevelop and implement threat modeling to identify security risks across applications and infrastructure.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EConduct vulnerability scanning, penetration testing, and security assessments to detect weaknesses.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EDefine and enforce secure coding practices in collaboration with development teams.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EWork with DevOps to integrate security into CI/CD pipelines and automate security testing.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EMonitor and respond to security incidents, conducting root cause analysis and implementing preventative measures.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EEnsure compliance with security standards and regulations (e.g., ISO 27001, GDPR, SOC 2).\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EDesign and implement identity and access management (IAM) policies, encryption standards, and authentication mechanisms.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ECollaborate with product teams to conduct security reviews of features, APIs, and third-party integrations.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EDevelop incident response plans, security documentation, and best practices.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EStay ahead of emerging threats, vulnerabilities, and security technologies.\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003EREQUIREMENTS\u003C/h3\u003E\u003Cul\u003E\u003Cli\u003EAround 4\u002B years of experience in cybersecurity, application security, or security engineering.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EStrong knowledge of secure coding principles, OWASP Top 10, and threat modeling techniques.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EExperience with vulnerability scanning tools (Nessus, Qualys, Burp Suite) and penetration testing methodologies.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EHands-on experience with SIEM, intrusion detection systems (IDS), and security monitoring tools.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EProficiency in scripting and automation (Python, Bash, PowerShell) for security tasks.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EFamiliarity with cloud security in AWS, Azure, or GCP, including IAM and workload protection.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EKnowledge of encryption protocols, network security, and API security best practices.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EExperience working with DevSecOps, integrating security into CI/CD pipelines.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EAbility to analyze security logs, detect anomalies, and mitigate potential threats.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EExcellent problem-solving skills and ability to communicate security concepts to non-technical stakeholders.\u003C/li\u003E\u003C/ul\u003E\u003Cp\u003EWHAT BENEFITS ARE WE OFFERING?\u003C/p\u003E\u003Cul\u003E\u003Cli\u003EApple hardware ecosystem for work.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EAnnual Bonus\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ETop-tier Health and Life Insurance for peace of mind.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ETransportation Budget to support your commute needs.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003ECoverflex benefits package for meal allowances, well-being, and more.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EChildcare support.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EAir Conference - an opportunity to meet the team, collaborate, and grow together.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EPension Fund to support your long-term financial planning.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EUrban Sports Club membership to keep you active.\u003C/li\u003E\u003C/ul\u003E\u003Cul\u003E\u003Cli\u003EMeals 100% free at the hub.\u003C/li\u003E\u003C/ul\u003E\u003Ch3\u003EDIVERSITY \u0026amp; INCLUSION\u003C/h3\u003E\u003Cp\u003EAt Air Apps, we are committed to fostering a diverse, inclusive, and equitable workplace. We enthusiastically welcome applicants from all backgrounds, experiences, and perspectives. We celebrate diversity in all its forms and believe that varied voices and experiences make us stronger.\u003C/p\u003E\u003Ch3\u003EAPPLICATION DISCLAIMER\u003C/h3\u003E\u003Cp\u003EAt Air Apps, we value transparency and integrity in our hiring process. Applicants must submit their own work without any AI-generated assistance. Any use of AI in application materials, assessments, or interviews will result in disqualification.\u003C/p\u003E","identifier":{"@type":"PropertyValue","name":"Gurify","value":"security-engineer-at-airapps-6d279c132127"},"url":"https://gurify.com/job/security-engineer-at-airapps-6d279c132127","datePosted":"2026-04-24","validThrough":"2026-10-13T23:59:59Z","hiringOrganization":{"@type":"Organization","name":"Airapps","sameAs":"https://jobs.ashbyhq.com/airapps"},"directApply":false,"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressCountry":"ES","addressLocality":"Madrid"}}}
```

```json
{"@context":"https://schema.org/","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Jobs","item":"https://gurify.com/jobs"},{"@type":"ListItem","position":2,"name":"Spain","item":"https://gurify.com/jobs/spain"},{"@type":"ListItem","position":3,"name":"Security Engineer","item":"https://gurify.com/job/security-engineer-at-airapps-6d279c132127"}]}
```
