Security Engineer

Air Apps

• $120K — $145K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 4+ years of experience in cybersecurity, application security, or security engineering.
  • Strong knowledge of secure coding principles and OWASP Top 10.
  • Experience with vulnerability scanning tools like Nessus or Burp Suite.
  • Hands-on experience with SIEM and intrusion detection systems.
  • Proficiency in scripting and automation languages (Python, Bash, PowerShell).
  • Familiarity with cloud security frameworks (AWS, Azure, GCP).
  • Ability to analyze security logs and detect anomalies.

Responsibilities

  • Develop and implement threat modeling to identify risks.
  • Conduct vulnerability scanning and penetration testing.
  • Define and enforce secure coding practices with development teams.
  • Integrate security into CI/CD pipelines with DevOps.
  • Monitor and respond to security incidents and conduct analyses.
  • Ensure compliance with security standards such as ISO 27001 and GDPR.
  • Design and implement identity and access management policies.

Benefits

  • Apple hardware ecosystem for work.
  • Annual bonus structure.
  • Comprehensive medical insurance including vision and dental.
  • Short and long-term disability insurance.
  • 401k with up to 4% contribution.
  • Opportunity to attend Air Conference for team collaboration.
  • Transportation budget assistance.
  • Free meals at the hub.
  • Gym membership included.
Full Job Description
The Role

As a Security Engineer at Air Apps, you will be responsible for safeguarding our applications, infrastructure, and data from threats and vulnerabilities. You will work closely with development, DevOps, and IT teams to implement secure coding practices, vulnerability scanning, and threat modeling to ensure our systems remain resilient against cyber threats.

Your expertise will help build and maintain a secure development lifecycle (SDLC), security monitoring frameworks, and proactive risk mitigation strategies.

Responsibilities
  • Develop and implement threat modeling to identify security risks across applications and infrastructure.
  • Conduct vulnerability scanning, penetration testing, and security assessments to detect weaknesses.
  • Define and enforce secure coding practices in collaboration with development teams.
  • Work with DevOps to integrate security into CI/CD pipelines and automate security testing.
  • Monitor and respond to security incidents, conducting root cause analysis and implementing preventative measures.
  • Ensure compliance with security standards and regulations (e.g., ISO 27001, GDPR, SOC 2).
  • Design and implement identity and access management (IAM) policies, encryption standards, and authentication mechanisms.
  • Collaborate with product teams to conduct security reviews of features, APIs, and third-party integrations.
  • Develop incident response plans, security documentation, and best practices.
  • Stay ahead of emerging threats, vulnerabilities, and security technologies.


Requirements
  • Around 4+ years of experience in cybersecurity, application security, or security engineering.
  • Strong knowledge of secure coding principles, OWASP Top 10, and threat modeling techniques.
  • Experience with vulnerability scanning tools (Nessus, Qualys, Burp Suite) and penetration testing methodologies.
  • Hands-on experience with SIEM, intrusion detection systems (IDS), and security monitoring tools.
  • Proficiency in scripting and automation (Python, Bash, PowerShell) for security tasks.
  • Familiarity with cloud security in AWS, Azure, or GCP, including IAM and workload protection.
  • Knowledge of encryption protocols, network security, and API security best practices.
  • Experience working with DevSecOps, integrating security into CI/CD pipelines.
  • Ability to analyze security logs, detect anomalies, and mitigate potential threats.
  • Excellent problem-solving skills and ability to communicate security concepts to non-technical stakeholders.


What benefits are we offering?
  • Apple hardware ecosystem for work.
  • Annual Bonus.
  • Medical Insurance (including vision & dental).
  • Disability insurance - short and long-term.
  • 401k up to 4% contribution.
  • Air Conference - an opportunity to meet the team, collaborate, and grow together.
  • Transportation budget
  • Free meals at the hub
  • Gym membership

Similar Jobs

More Jobs at Air Apps

  • Security Engineer
    $120K — $145K *
    San Francisco, CA 94112 (San Francisco County)
    Information Technology
    In-Person
  • Site Reliability Engineer (SRE)
    $120K — $145K *
    San Francisco, CA 94112 (San Francisco County)
    Information Technology
    In-Person
  • Content Marketing Manager
    $95K — $115K *
    San Francisco, CA 94112 (San Francisco County)
    Media
    In-Person
  • Release Engineer
    $110K — $130K *
    San Francisco, CA 94112 (San Francisco County)
    Information Technology
    In-Person
  • CRM Specialist
    $80K — $95K *
    San Francisco, CA 94112 (San Francisco County)
    Consumer Technology
    In-Person

More Information Technology Jobs

Find similar Security Engineer jobs: