At a Glance
- Tasks: Protect our apps and data from cyber threats while collaborating with dynamic teams.
- Company: Join a fast-growing, innovative company on a mission to revolutionise resource planning.
- Benefits: Enjoy top-tier health insurance, free meals, and a supportive work environment.
- Other info: Onsite role in vibrant Lisbon with excellent career growth and relocation support.
- Why this job: Make a real impact in cybersecurity while working with cutting-edge technology.
- Qualifications: 4+ years in cybersecurity with strong knowledge of secure coding and threat modeling.
The predicted salary is between 50000 - 70000 £ per year.
About Air Apps
At Air Apps, we believe in thinking bigger—and moving faster. We’re a family-founded company on a mission to create the world’s first AI-powered Personal & Entrepreneurial Resource Planner (PRP), and we need your passion and ambition to help us change how people plan, work, and live. Born in Lisbon, Portugal in 2018—and now with offices in both Lisbon and San Francisco—we’ve remained self-funded while reaching over 100 million downloads worldwide. Our long-term focus drives us to challenge the status quo every day, pushing the boundaries of AI-driven solutions that truly make a difference. Here, you’ll be a creative force, shaping products that empower people across the globe. Join us on this journey to redefine resource management—and change lives along the way.
The Role
As a Security Engineer at Air Apps, you will be responsible for safeguarding our applications, infrastructure, and data from threats and vulnerabilities. You will work closely with development, DevOps, and IT teams to implement secure coding practices, vulnerability scanning, and threat modeling to ensure our systems remain resilient against cyber threats. Your expertise will help build and maintain a secure development lifecycle (SDLC), security monitoring frameworks, and proactive risk mitigation strategies. This is a fully onsite position, based at our office in Lisbon, where you will collaborate closely with cross‑functional teams in person and contribute to a dynamic and fast‑paced environment. We are open to support with relocation efforts.
Responsibilities
- Develop and implement threat modeling to identify security risks across applications and infrastructure.
- Conduct vulnerability scanning, penetration testing, and security assessments to detect weaknesses.
- Define and enforce secure coding practices in collaboration with development teams.
- Work with DevOps to integrate security into CI/CD pipelines and automate security testing.
- Monitor and respond to security incidents, conducting root cause analysis and implementing preventative measures.
- Ensure compliance with security standards and regulations (e.g., ISO 27001, GDPR, SOC 2).
- Design and implement identity and access management (IAM) policies, encryption standards, and authentication mechanisms.
- Collaborate with product teams to conduct security reviews of features, APIs, and third‑party integrations.
- Develop incident response plans, security documentation, and best practices.
- Stay ahead of emerging threats, vulnerabilities, and security technologies.
Requirements
- Around 4+ years of experience in cybersecurity, application security, or security engineering.
- Strong knowledge of secure coding principles, OWASP Top 10, and threat modeling techniques.
- Experience with vulnerability scanning tools (Nessus, Qualys, Burp Suite) and penetration testing methodologies.
- Hands‑on experience with SIEM, intrusion detection systems (IDS), and security monitoring tools.
- Proficiency in scripting and automation (Python, Bash, PowerShell) for security tasks.
- Familiarity with cloud security in AWS, Azure, or GCP, including IAM and workload protection.
- Knowledge of encryption protocols, network security, and API security best practices.
- Experience working with DevSecOps, integrating security into CI/CD pipelines.
- Ability to analyze security logs, detect anomalies, and mitigate potential threats.
- Excellent problem‑solving skills and ability to communicate security concepts to non‑technical stakeholders.
What benefits are we offering?
- Apple hardware ecosystem for work.
- Annual Bonus.
- Top‑tier Health and Life Insurance for peace of mind.
- Transportation Budget to support your commute needs.
- Coverflex benefits package for meal allowances, well‑being, and more.
- Childcare support.
- Air Conference - an opportunity to meet the team, collaborate, and grow together.
- Pension Fund to support your long‑term financial planning.
- Urban Sports Club membership to keep you active.
- Meals 100% free at the hub.
Security Engineer — Onsite Lisbon (Threat Modeling & SDLC) in London employer: airapps
At Air Apps, we pride ourselves on fostering a vibrant and innovative work culture that encourages creativity and collaboration. As a Security Engineer in our Lisbon office, you will enjoy a range of benefits including top-tier health insurance, a supportive transportation budget, and opportunities for professional growth through events like the Air Conference. Join us in a dynamic environment where your contributions will directly impact our mission to revolutionise resource management with AI-driven solutions.
StudySmarter Expert Advice🤫
We think this is how you could land Security Engineer — Onsite Lisbon (Threat Modeling & SDLC) in London
✨Tip Number 1
Network like a pro! Get out there and connect with folks in the industry. Attend meetups, conferences, or even local tech events in Lisbon. You never know who might have the inside scoop on job openings or can put in a good word for you.
✨Tip Number 2
Show off your skills! Create a portfolio or GitHub repository showcasing your projects, especially those related to security engineering. This gives potential employers a tangible look at what you can do and sets you apart from the crowd.
✨Tip Number 3
Prepare for interviews by brushing up on common security scenarios and challenges. Practice explaining your thought process when it comes to threat modeling and secure coding practices. Confidence is key, so make sure you can articulate your expertise clearly!
✨Tip Number 4
Don’t forget to apply through our website! It’s the best way to ensure your application gets seen by the right people. Plus, we love seeing candidates who are genuinely interested in joining our mission at Air Apps.
We think you need these skills to ace Security Engineer — Onsite Lisbon (Threat Modeling & SDLC) in London
Some tips for your application 🫡
Tailor Your CV:Make sure your CV is tailored to the Security Engineer role. Highlight your experience with secure coding practices, threat modeling, and any relevant tools you've used. We want to see how your skills align with what we're looking for!
Craft a Compelling Cover Letter:Your cover letter is your chance to show us your passion for security engineering. Share why you're excited about working at Air Apps and how you can contribute to our mission. Keep it concise but impactful!
Showcase Your Projects:If you've worked on any projects related to cybersecurity or application security, make sure to mention them! We love seeing real-world examples of your work and how you've tackled security challenges.
Apply Through Our Website:We encourage you to apply directly through our website. It’s the best way for us to receive your application and ensures you’re considered for the role. Plus, it’s super easy to do!
How to prepare for a job interview at airapps
✨Know Your Stuff
Make sure you brush up on your knowledge of secure coding principles, OWASP Top 10, and threat modeling techniques. Be ready to discuss how you've applied these in your previous roles, as this will show your expertise and passion for security.
✨Showcase Your Tools
Familiarise yourself with the vulnerability scanning tools mentioned in the job description, like Nessus or Burp Suite. If you’ve used them before, be prepared to share specific examples of how you’ve leveraged these tools to identify and mitigate security risks.
✨Collaboration is Key
Since this role involves working closely with development and DevOps teams, think of examples where you successfully collaborated with cross-functional teams. Highlight how you integrated security into CI/CD pipelines and the impact it had on the overall project.
✨Stay Ahead of the Game
Demonstrate your awareness of emerging threats and security technologies. Bring up recent trends or incidents in cybersecurity that have caught your attention, and discuss how they could relate to the work at Air Apps. This shows you're proactive and genuinely interested in the field.