About the job
About Air Apps
At Air Apps, we are driven by a vision to innovate and accelerate. Founded in Lisbon, Portugal in 2018, we are on a mission to revolutionize personal and entrepreneurial planning with our groundbreaking AI-powered Personal & Entrepreneurial Resource Planner (PRP). With over 100 million downloads globally, our self-funded journey has expanded our footprint to San Francisco while maintaining our commitment to pushing the limits of AI technology.
We challenge the norm daily, striving to create AI-driven solutions that have a meaningful impact on people's lives. Join our team where your creativity will shape products that empower individuals worldwide.
Be part of our mission to redefine resource management and transform lives.
The Role
As a Security Engineer at Air Apps, you will play a crucial role in protecting our applications, infrastructure, and data from potential threats and vulnerabilities. You will collaborate closely with development, DevOps, and IT teams to establish secure coding practices, conduct vulnerability assessments, and develop threat models to ensure our systems are fortified against cyber threats.
Your expertise will be essential in building and maintaining a secure development lifecycle (SDLC), security monitoring frameworks, and proactive risk mitigation strategies.
Responsibilities
Create and implement threat modeling strategies to identify security vulnerabilities across applications and infrastructure.
Perform vulnerability scanning, penetration testing, and security assessments to uncover weaknesses.
Collaborate with development teams to establish and enforce secure coding standards.
Partner with DevOps to integrate security measures into CI/CD pipelines and automate security testing.
Monitor and address security incidents, conducting root cause analyses and implementing preventive strategies.
Ensure adherence to security regulations and standards such as ISO 27001, GDPR, and SOC 2.
Design and implement identity and access management (IAM) policies, encryption protocols, and authentication processes.
Work with product teams to perform security evaluations of features, APIs, and third-party integrations.
