Security Engineer

Mews
Spain
1 day ago
Apply on startup.jobs
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience required
2 years minimum
Compensation
€57,000.0 - €70,000.0
Working hours
Regular working hours
Job source

Tech stack

Kubernetes Security .NET Framework Application Programming Interfaces (APIs) Artificial Intelligence Amazon Web Services Build Automation Microsoft Azure Cloud Computing Security Python (Programming Language) Delivery Pipeline Software Security Containerization
+1 more
Static Application Security Testing

Job description

Let’s get into the specifics. It’s impossible to capture every nuance of a role - especially at a rapidly growing company like Mews - but if we had to distil it into a job description (which we do because this is a job description), it would be this:

Security is load-bearing infrastructure at Mews. Every payment processed, every guest record stored, every API call made by an integration partner runs through systems this team is responsible for keeping secure. As the Security Engineer joining the Security Engineering team, you will own the tooling and controls that let hundreds of engineers build fast without creating risk they cannot see. This is a building role, not a monitoring role: you will design and implement security capabilities, embed checks into the pipelines (the automated processes that take code from a developer’s laptop to production) that engineers use every day, and work directly with product and platform teams to make secure choices the easy ones.

The team is at a high-watermark moment for delivery. A recent promotion to Staff Engineer is great news for Mews, but it has shifted roughly half that person’s capacity to a major compliance initiative, leaving a real gap in the security engineering roadmap. Supply chain security, cloud policy enforcement, and application security tooling all have concrete 2026 milestones attached. This hire closes that gap and has an immediate, visible impact on what the team ships.

What you would do

  • Build and maintain application security tooling (SAST, which finds vulnerabilities in code automatically, and SCA, which checks third-party libraries for known weaknesses) integrated directly into the engineering workflow
  • Run threat modeling sessions with product and platform teams, helping them identify how their systems could be attacked before code is written, not after
  • Own and improve cloud security controls on Azure, including policy-as-code enforcement (automated rules that flag or block insecure configuration before it reaches production) and secure-by-default configuration standards
  • Contribute to supply chain security, making sure the third-party dependencies and delivery pipelines Mews relies on are not introducing risk into the platform
  • Use AI tooling to accelerate threat modeling analysis, triage vulnerability findings at scale, and build repeatable security review workflows that the broader engineering team can run without a security specialist in the room for every review

AI Fluency Level 3: In this role, that means you have gone beyond using AI for your own productivity. You have looked at how a security function works and redesigned parts of it using AI: building review workflows or detection playbooks that other engineers can follow without a security specialist present every time, and actively checking AI-generated outputs for accuracy rather than accepting them. In security engineering specifically, this includes evaluating AI-generated code for vulnerabilities, using AI to surface threat patterns across large codebases, and knowing when the model is wrong. This is not a role for someone who uses Copilot occasionally; it is a role for someone who has thought carefully about where AI makes security work better and built something repeatable out of that insight.

Requirements

If you’re motivated by ownership, curiosity and meaningful impact, and are driven to deliver consistent high performance, you’ll feel at home here., * 2-5 years of hands-on security engineering experience in a software company or cloud-native environment, building security capabilities rather than operating existing tooling

  • Practical experience with application security: SAST, SCA, secret scanning, or container security, with modern tooling (Wiz, Snyk, Semgrep, or similar)
  • Cloud security experience on Azure, AWS, or GCP, with a preference for Azure given the team’s environment
  • A development or scripting background (Python, .NET, or similar) that lets you read code, reason about security issues in it, and build automation where repetition is slowing things down
  • AI Fluency Level 3, or the equivalent hands-on experience: you have redesigned a security workflow or review process using AI, built something others can follow, and you actively verify what AI tools give you rather than treating the output as correct by default, * Familiarity with threat modeling methodologies such as STRIDE or PASTA
  • Experience with supply chain security controls (for example, SBOM generation, dependency pinning, or pipeline integrity verification)
  • Exposure to European cybersecurity compliance frameworks in a technical rather than audit capacity

Benefits & conditions

€57.000-€70.000 EUR Czechia 1 191 500 Kč-1 598 000 Kč CZK

Pay Transparency at Mews

Salary ranges are provided in good faith and reflect current market conditions and internal pay structures. Final compensation may be adjusted based on funding, budget constraints, or exceptional candidate qualifications, but will remain within reasonable proximity to the stated range.

This salary disclosure is provided in compliance with applicable pay transparency legislation. We are committed to equal pay practices and prohibit salary history inquiries during our recruitment process.

If the location you’re applying from wasn’t originally advertised for this role, salary range information is available upon request at any point during the application/interview process - your recruiter will be able to help.

What’s in it for you?

Our success is powered by our incredible people, supported by benefits that help them thrive.

Global benefits

No matter where you’re based, you’ll enjoy:

  • Unlimited paid holiday (yes, really)
  • Participation in our company share program
  • Paid parental leave (6 months fully paid for primary caregivers, 2 months for secondary, available after one year of service)
  • An annual Learning budget of €300 (and more for high performers) to support your development
  • Monthly “EDGE” time to Explore, Develop, Grow, and Elevate yourself
  • A work from anywhere policy with flexibility to work abroad for a few weeks each year
  • Relocation options, available after one year
  • Flexible, hybrid working options
  • A home office setup budget to make your workspace your own and a monthly work-from-home allowance
  • Claude tokens, so you can automate workflows and build smarter, more efficient ways of working

About the company

The hospitality industry is uniquely human, and it deserves technology that’s just as inspiring as the people behind it. At Mews, we’re transforming the industry with a platform that helps hotels run smarter, move faster and create better guest experiences.

You’ll work with smart, curious people who care deeply about what they do. You’ll have autonomy and the trust to make good decisions and move quickly. And you’ll enjoy a real sense of purpose as you see the impact of what we’re building., We’re an equal opportunities employer. We value teams that reflect the diversity of the customers and communities we serve. Different perspectives make better ideas, stronger products and a more welcoming company.

We also believe transparency is important when deciding if you’re the right fit. Mews is an ambitious, high-pressure environment of continuous learning and high standards. Success here requires resilience, adaptability and a willingness to solve difficult problems.

A few things that define how we work:

  • High autonomy means high responsibility. People are expected to take ownership and drive outcomes. There isn’t a detailed playbook for everything, and that’s part of what makes the work challenging - and rewarding.
  • Change is constant. We’re growing quickly and adapting as we scale. Teams, processes and priorities continue to evolve, and only people who stay curious and agile will thrive.
  • We’re remote-first, not relationship-free. Flexibility is core to how we work, but strong relationships still matter. Our teams are global, so we need expert collaborators and communicators to help us move forward together.
  • AI is an integral part of our processes. It’s not here to steal people’s jobs, but to amplify efficiency and productivity. We’re motivated to proactively use the technology to seek out better ways of working and share our findings with the rest of the company.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on startup.jobs
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

2:50 min

Electronic diagnostic software tools and factory production flashing

Denis Grahovac · World Congress 2021

1:06 min

Outline of free tools for Microsoft Azure

Radu Vunvulea Radu Vunvulea · World Congress 2022

6:37 min

Evolution of build systems and Gradle basics

Amanda Martin · LIVE

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

3:05 min

Differences between RPA platforms and the .NET framework

Maria Doina Irimias · LIVE

Videos

See all

Related articles

See all