> Markdown version of [/jobs/ext/2302850-security-engineer](https://www.wearedevelopers.com/jobs/ext/2302850-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer - **Company:** Air Apps - **Location:** München, Germany - **Experience:** Experienced - **Salary:** €61,000.0 - €76,000.0 - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Amazon Web Services, Software System Penetration Testing, Microsoft Azure, Bash Shell, Burp Suite, Cloud Computing Security, Cyber Security, DevOps, Cryptographic Protocols, Identity and Access Management, Intrusion Detection Systems, Python (Programming Language), Network Security, Open Web Application Security, Windows PowerShell, Secure Coding, Security Information and Event Management, Software Security, Cybercrime, Nessus, Devsecops, Qualys, Vulnerability Analysis - **Published:** August 30, 2026 - **Apply:** https://www.careerjet.de/jobad/dec7dbd378820db6f2882cfe9404509122 ## About the Role Around 4+ years of experience in cybersecurity, application security, or security engineering. Strong knowledge of secure coding principles, OWASP Top 10, and threat modeling techniques. Experience with vulnerability scanning tools (Nessus, Qualys, Burp Suite) and penetration testing methodologies. Hands-on experience with SIEM, intrusion detection systems (IDS), and security monitoring tools. Proficiency in scripting and automation (Python, Bash, PowerShell) for security tasks. Familiarity with cloud security in AWS, Azure, or GCP, including IAM and workload protection. Knowledge of encryption protocols, network security, and API security best practices. Experience working with DevSecOps, integrating security into CI/CD pipelines. Ability to analyze security logs, detect anomalies, and mitigate potential threats. Excellent problem-solving skills and ability to communicate security concepts to non-technical stakeholders. ## Description As a Security Engineer at Air Apps, you will be responsible for safeguarding our applications, infrastructure, and data from threats and vulnerabilities. You will work closely with development, DevOps, and IT teams to implement secure coding practices, vulnerability scanning, and threat modeling to ensure our systems remain resilient against cyber threats. Your expertise will help build and maintain a secure development lifecycle (SDLC), security monitoring frameworks, and proactive risk mitigation strategies. This is a fully onsite position, based at our office in Lisbon, where you will collaborate closely with cross-functional teams in person and contribute to a dynamic and fast-paced environment. We are open to support with relocation efforts. Responsibilities Develop and implement threat modeling to identify security risks across applications and infrastructure. Conduct vulnerability scanning, penetration testing, and security assessments to detect weaknesses. Define and enforce secure coding practices in collaboration with development teams. Work with DevOps to integrate security into CI/CD pipelines and automate security testing. Monitor and respond to security incidents, conducting root cause analysis and implementing preventative measures. Ensure compliance with security standards and regulations (e.g., ISO 27001, GDPR, SOC 2). Design and implement identity and access management (IAM) policies, encryption standards, and authentication mechanisms. Collaborate with product teams to conduct security reviews of features, APIs, and third-party integrations. Develop incident response plans, security documentation, and best practices. Stay ahead of emerging threats, vulnerabilities, and security technologies. ## Related Videos - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevOps Maturity Check – a way to balance autonomy and alignment](https://www.wearedevelopers.com/videos/58-devops-maturity-check-a-way-to-balance-autonomy-and-alignment) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [#90DaysOfDevOps - The DevOps Learning Journey](https://www.wearedevelopers.com/videos/548-90daysofdevops-the-devops-learning-journey) ## Related Articles - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market) - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [The Ultimate Software Engineer Career Path Guide for 2023](https://www.wearedevelopers.com/magazine/146-the-ultimate-software-engineer-career-path-guide-for-2023) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking)