Security Engineer

Mews · Czechia; Spain · Engineering

Posted 2026-09-03

Apply for this role →

Security is load-bearing infrastructure at Mews. Every payment processed, every guest record stored, every API call made by an integration partner runs through systems this team is responsible for keeping secure. As the Security Engineer joining the Security Engineering team, you will own the tooling and controls that let hundreds of engineers build fast without creating risk they cannot see. This is a building role, not a monitoring role: you will design and implement security capabilities, embed checks into the pipelines (the automated processes that take code from a developer's laptop to production) that engineers use every day, and work directly with product and platform teams to make secure choices the easy ones.

The team is at a high-watermark moment for delivery. A recent promotion to Staff Engineer is great news for Mews, but it has shifted roughly half that person's capacity to a major compliance initiative, leaving a real gap in the security engineering roadmap. Supply chain security, cloud policy enforcement, and application security tooling all have concrete 2026 milestones attached. This hire closes that gap and has an immediate, visible impact on what the team ships.

What you would do

Build and maintain application security tooling (SAST, which finds vulnerabilities in code automatically, and SCA, which checks third-party libraries for known weaknesses) integrated directly into the engineering workflow

Run threat modeling sessions with product and platform teams, helping them identify how their systems could be attacked before code is written, not after

Own and improve cloud security controls on Azure, including policy-as-code enforcement (automated rules that flag or block insecure configuration before it reaches production) and secure-by-default configuration standards

Contribute to supply chain security, making sure the third-party dependencies and delivery pipelines Mews relies on are not introducing risk into the platform

Use AI tooling to accelerate threat modeling analysis, triage vulnerability findings at scale, and build repeatable security review workflows that the broader engineering team can run without a security specialist in the room for every review

AI Fluency Level 3: In this role, that means you have gone beyond using AI for your own productivity. You have looked at how a security function works and redesigned parts of it using AI: building review workflows or detection playbooks that other engineers can follow without a security specialist present every time, and actively checking AI-generated outputs for accuracy rather than accepting them. In security engineering specifically, this includes evaluating AI-generated code for vulnerabilities, using AI to surface threat patterns across large codebases, and knowing when the model is wrong. This is not a role for someone who uses Copilot occasionally; it is a role for someone who has thought carefully about where AI makes security work better and built something repeatable out of that insight.

For more information on AI fluency at Mews, please refer to AI Fluency at Mews: A Comprehensive Guide for Candidates on Confluence.

What you would bring

2-5 years of hands-on security engineering experience in a software company or cloud-native environment, building security capabilities rather than operating existing tooling

Practical experience with application security: SAST, SCA, secret scanning, or container security, with modern tooling (Wiz, Snyk, Semgrep, or similar)

Cloud security experience on Azure, AWS, or GCP, with a preference for Azure given the team's environment

A development or scripting background (Python, .NET, or similar) that lets you read code, reason about security issues in it, and build automation where repetition is slowing things down

AI Fluency Level 3, or the equivalent hands-on experience: you have redesigned a security workflow or review process using AI, built something others can follow, and you actively verify what AI tools give you rather than treating the output as correct by default

Nice to have

Familiarity with threat modeling methodologies such as STRIDE or PASTA

Experience with supply chain security controls (for example, SBOM generation, dependency pinning, or pipeline integrity verification)

Exposure to European cybersecurity compliance frameworks in a technical rather than audit capacity

Spain

€57.000—€70.000 EUR

Czechia

1 191 500 Kč—1 598 000 Kč CZK

Apply for this role →

← Back to all jobs