10 дней назад
Security Engineer II
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Security Engineer II (Application Security/LLM Security): Building and operating security tooling, automated remediation, and CI/CD security checks to protect Booking.com applications and customer data with an accent on web vulnerabilities, secure code review, and AI-enabled application risks. Focus on analyzing security findings, securing LLM applications, and embedding threat modelling and defensive practices into software development.
Location: Amsterdam, Netherlands; hybrid working is available, with flexible arrangements and up to 20 days per year working from abroad in the home country. This role does not come with relocation assistance.
Company
operates a large-scale travel platform that helps people experience the world through its products, partners, and technology.
What you will do
- Review applications, APIs, and designs to identify security risks and support secure code reviews and vulnerability assessments.
- Help development teams understand and remediate web vulnerabilities and contribute to threat modelling and security requirements.
- Integrate and maintain SAST, DAST, software composition analysis, and secrets-scanning checks in CI/CD pipelines.
- Support security reviews of AI- and LLM-enabled applications, including identifying prompt injection, data disclosure, poisoning, and excessive-agency risks.
- Investigate, prioritise, document, and track security findings through remediation.
- Collaborate with software engineers, platform teams, and security colleagues while developing scripts and automation.
Requirements
- Basic to intermediate knowledge of application and web security, with 3+ years of relevant industry experience.
- Understanding of the OWASP Top 10, secure coding principles, HTTP, APIs, authentication, authorisation, and TLS.
- Ability to read code in at least one programming language and script or automate with Python, Bash, or a similar language.
- Experience with application security tools such as SAST, DAST, software composition analysis, vulnerability scanners, or secrets-scanning tools.
- Understanding of LLM applications, including prompts, model inputs and outputs, retrieval-augmented generation, and tool or API integrations.
- Bachelor’s or Master’s degree in Computer Science or a related field, plus clear communication and analytical skills.
Nice to have
- Experience with cloud platforms, containers, infrastructure as code, API security, or microservices.
- Experience or interest in securing AI or LLM-enabled applications.
- Experience with threat modelling, security testing, vulnerability management, or incident response.
- Security certifications or relevant practical projects.
Culture & Benefits
- Annual paid time off and generous parent, grandparent, bereavement, and care leave.
- Product discounts of up to 1400 per year, including Genius Level 3 status and wallet credit.
- Work on a high-scale product used by millions of travellers worldwide.
- Technical and interpersonal development through on-the-job opportunities, experimental projects, hackathons, conferences, and community participation.
- Inclusive workplace representing more than 140 nationalities, with adjustments and tools available for colleagues with disabilities.
Hiring process
- Applications and interviews follow ’s hiring process.
- Successful applicants may undergo pre-employment screening by a third party as permitted by applicable law.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →