Security Engineer at Air Apps
on-site · full_time · Visa sponsorship
Apply for this role at Air Apps
Responsibilities:
- Lead threat modeling and security reviews for applications, APIs and infrastructure.
- Run vulnerability scans, penetration tests and security assessments; report findings and track remediation.
- Integrate security into CI/CD: automated SAST/DAST, dependency scanning and pipeline checks.
- Define and promote secure coding practices and perform security code reviews.
- Build and operate security monitoring (SIEM, IDS) and lead incident response and RCAs.
- Implement IAM, encryption, authentication and data protection controls.
- Ensure compliance with relevant standards (GDPR, ISO 27001, SOC 2) and document security policies.
Requirements:
- ~4+ years in cybersecurity, application security or security engineering.
- Strong understanding of OWASP Top 10, threat modeling and secure development lifecycle.
- Hands-on with vulnerability tools (Nessus, Qualys, Burp Suite) and penetration testing methods.
- Experience with SIEM/IDS, logging and incident response playbooks.
- Scripting/automation skills (Python, Bash, PowerShell) for tooling and remediation.
- Familiarity with cloud security (AWS/Azure/GCP) and IAM best practices.
- Good communication skills for cross-team security guidance and documentation.