Job
- Level
- Experienced
- Job Field
- IT, Security
- Employment Type
- Full Time
- Contract Type
- Permanent employment
- Salary
- 61.000 to 76.000€ gross/year
- Location
- Munich
- Working Model
- Onsite
Job Summary
In this role, you will develop security strategies, conduct threat analyses, and integrate secure coding practices into the development process to protect applications and data from risks.
Job Technologies
Your role in the team
- As a Security Engineer at Air Apps, you will be responsible for safeguarding our applications, infrastructure, and data from threats and vulnerabilities.
- You will work closely with development, DevOps, and IT teams to implement secure coding practices, vulnerability scanning, and threat modeling to ensure our systems remain resilient against cyber threats.
- Your expertise will help build and maintain a secure development lifecycle (SDLC), security monitoring frameworks, and proactive risk mitigation strategies.
- This is a fully onsite position, based at our office in Lisbon, where you will collaborate closely with cross-functional teams in person and contribute to a dynamic and fast-paced environment.
- Develop and implement threat modeling to identify security risks across applications and infrastructure.
- Conduct vulnerability scanning, penetration testing, and security assessments to detect weaknesses.
- Define and enforce secure coding practices in collaboration with development teams.
- Work with DevOps to integrate security into CI/CD pipelines and automate security testing.
- Monitor and respond to security incidents, conducting root cause analysis and implementing preventative measures.
- Ensure compliance with security standards and regulations (e.g., ISO 27001, GDPR, SOC 2).
- Design and implement identity and access management (IAM) policies, encryption standards, and authentication mechanisms.
- Zusammenarbeit mit Produktteams, um Sicherheitsüberprüfungen von Funktionen, APIs und Drittanbieterintegrationen durchzuführen.
- Develop incident response plans, security documentation, and best practices.
- Bleiben Sie den aufkommenden Bedrohungen, Schwachstellen und Sicherheitstechnologien einen Schritt voraus.
This text has been machine translated. Show original
Our expectations of you
Qualifications
- Starkes Wissen über sichere Codierungsprinzipien, OWASP Top 10 und Bedrohungsmodellierungstechniken.
- Proficiency in scripting and automation (Python, Bash, PowerShell) for security tasks.
- Vertrautheit mit Cloud-Sicherheit in AWS, Azure oder GCP, einschließlich IAM und Workload-Schutz.
- Knowledge of encryption protocols, network security, and API security best practices.
- Ability to analyze security logs, detect anomalies, and mitigate potential threats.
- Excellent problem-solving skills and ability to communicate security concepts to non-technical stakeholders.
Experience
- Around 4+ years of experience in cybersecurity, application security, or security engineering.
- Experience with vulnerability scanning tools (Nessus, Qualys, Burp Suite) and penetration testing methodologies.
- Hands-on experience with SIEM, intrusion detection systems (IDS), and security monitoring tools.
- Experience working with DevSecOps, integrating security into CI/CD pipelines.
This text has been machine translated. Show original
What we offer
- Apple hardware ecosystem for work.
- Jahresbonus
- Top-tier Health and Life Insurance for peace of mind.
- Transportation budget to support your commute needs.
- Coverflex benefits package for meal allowances, well-being, and more.
- Childcare support.
- Air Conference - an opportunity to meet the team, collaborate, and grow together.
- Pension fund to support your long-term financial planning.
- Urban Sports Club membership to keep you active.
- Meals 100% free at the hub.
This text has been machine translated. Show original
Topics You Will Work On
Job Locations
About Your Employer
Air Apps
Air Apps is a family-founded, self-financed company with over 100 million downloads worldwide and offices in Lisbon and San Francisco. It focuses on innovative, user-friendly apps that simplify daily life and pursues an AI-first approach to create the first AI-powered Personal & Entrepreneurial Resource Planner (PRP).
Description
- Company Type
- Startup
- Working Model
- Full Remote, Onsite
- Industry
- Internet, IT, Telecommunication