> Markdown version of [/jobs/ext/1673848-security-engineer](https://www.wearedevelopers.com/jobs/ext/1673848-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer - **Company:** Airapps - **Location:** Barcelona, Spain - **Contract:** Permanent contract - **Skills:** Clean Code Principles, Application Programming Interfaces (APIs), Amazon Web Services, Software System Penetration Testing, Microsoft Azure, Bash Shell, Burp Suite, Cloud Computing Security, Cyber Security, Continuous Integration, DevOps, Cryptographic Protocols, Identity and Access Management, Intrusion Detection Systems, Python (Programming Language), Network Security, Open Web Application Security, Windows PowerShell, Secure Coding, Security Information and Event Management, Software Security, Cybercrime, Tenable Nessus, Nessus, Devsecops, Qualys, Vulnerability Analysis - **Published:** July 20, 2026 - **Apply:** https://www.buscojobs.com.es/security-engineer-en-barcelona-ID-363513993 ## About the Role Around 4+ years of experience in cybersecurity, application security, or security engineering . Strong knowledge of secure coding principles, OWASP Top 10, and threat modeling techniques . Experience with vulnerability scanning tools (Nessus, Qualys, Burp Suite) and penetration testing methodologies . Hands?on experience with SIEM, intrusion detection systems (IDS), and security monitoring tools . Proficiency in scripting and automation (Python, Bash, PowerShell) for security tasks. Familiarity with cloud security in AWS, Azure, or GCP, including IAM and workload protection. Knowledge of encryption protocols, network security, and API security best practices . Experience working with DevSecOps , integrating security into CI/CD pipelines. Ability to analyze security logs, detect anomalies, and mitigate potential threats . Excellent problem?solving skills and ability to communicate security concepts to non?technical stakeholders. ## Description The RoleAs aSecurity Engineerat Air Apps, you will be responsible forsafeguarding our applications, infrastructure, and datafrom threats and vulnerabilities. You will work closely with development, DevOps, and IT teams to implementsecure coding practices, vulnerability scanning, and threat modelingto ensure our systems remain resilient against cyber threats.Your expertise will help build and maintain asecure development lifecycle (SDLC), security monitoring frameworks, and proactive risk mitigation strategies.This is afully onsite position, based at our office in Lisbon, where you will collaborate closely with cross?functional teams in person and contribute to a dynamic and fast?paced environment.We are open to support with relocation efforts.ResponsibilitiesDevelop and implementthreat modelingto identify security risks across applications and infrastructure.Conductvulnerability scanning, penetration testing, and security assessmentsto detect weaknesses.Define and enforcesecure coding practicesin collaboration with development teams.Work with DevOps to integratesecurity into CI/CD pipelinesand automate security testing.Monitor and respond tosecurity incidents, conducting root cause analysis and implementing preventative measures.Ensure compliance withsecurity standards and regulations(e.g., ISO *****, GDPR, SOC 2).Design and implementidentity and access management (IAM) policies, encryption standards, and authentication mechanisms.Collaborate with product teams to conductsecurity reviews of features, APIs, and third?party integrations.Developincident response plans, security documentation, and best practices.Stay ahead of emerging threats, vulnerabilities, and security technologies.RequirementsAround4+ yearsof experience incybersecurity, application security, or security engineering.Strong knowledge ofsecure coding principles, OWASP Top 10, and threat modeling techniques.Experience withvulnerability scanning tools(Nessus, Qualys, Burp Suite) andpenetration testing methodologies.Hands?on experience withSIEM, intrusion detection systems (IDS), and security monitoring tools.Proficiency inscripting and automation(Python, Bash, PowerShell) for security tasks.Familiarity withcloud securityin AWS, Azure, or GCP, including IAM and workload protection.Knowledge ofencryption protocols, network security, and API security best practices.Experience working withDevSecOps, integrating security into CI/CD pipelines.Ability to analyzesecurity logs, detect anomalies, and mitigate potential threats.Excellent problem?solving skills and ability to communicate security concepts to non?technical stakeholders.What benefits are we offering?Apple hardwareecosystem for work.Annual BonusTop?tier Health and Life Insurancefor peace of mind.Transportation Budgetto support your commute needs.Coverflexbenefits package for meal allowances, well?being, and more.Childcaresupport.Air Conference- an opportunity to meet the team, collaborate, and grow together.Pension Fundto support your long?term financial planning.Urban Sports Clubmembership to keep you active.Meals 100% freeat the hub.Diversity & InclusionAt Air Apps, we are committed to fostering a diverse, inclusive, and equitable workplace. We enthusiastically welcome applicants from all backgrounds, experiences, and perspectives. We celebrate diversity in all its forms and believe that varied voices and experiences make us stronger.#J-*****-Ljbffr ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [DevOps Maturity Check – a way to balance autonomy and alignment](https://www.wearedevelopers.com/videos/58-devops-maturity-check-a-way-to-balance-autonomy-and-alignment) - [Securing Your Web Application Pipeline From Intruders](https://www.wearedevelopers.com/videos/53-securing-your-web-application-pipeline-from-intruders) - [#90DaysOfDevOps - The DevOps Learning Journey](https://www.wearedevelopers.com/videos/548-90daysofdevops-the-devops-learning-journey) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [The Ultimate Software Engineer Career Path Guide for 2023](https://www.wearedevelopers.com/magazine/146-the-ultimate-software-engineer-career-path-guide-for-2023) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers)