Application Security Engineer (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Application Security Engineer (Cybersecurity): Ensuring the security of the software development lifecycle and application infrastructure with an accent on secure SDLC, threat modeling, and CI/CD security controls. Focus on identifying and remediating vulnerabilities in APIs and microservices while implementing AI-assisted security automation.
Location: Must be based in the Netherlands (Hybrid setup in Amsterdam)
Company
is a leading reservation software provider for the tours and activities industry, enabling thousands of global businesses to operate and grow.
What you will do
- Integrate security into the SDLC through application security reviews, threat modeling, and design evaluations.
- Implement and maintain CI/CD security controls, including SAST, DAST, SCA, and container scanning within GitLab.
- Remediate vulnerabilities identified via penetration tests, bug bounty programs, and internal/external audits.
- Provide technical guidance on secure coding, API security, authentication, authorization, and secrets management.
- Optimize security monitoring and detection capabilities using Elastic SIEM, WAF policies, and security automation.
- Participate in security alert triage, incident response activities, and the security on-call rotation.
Requirements
- Senior-level experience in application security, secure SDLC, and practical mitigation of OWASP Top 10 vulnerabilities.
- Proven track record of performing code reviews and supporting the remediation of security findings.
- Proficiency in Python or other high-level languages such as Go or Java.
- Strong understanding of AWS security concepts, including IAM, WAF, Kubernetes, and Infrastructure as Code.
- Must be located in the Netherlands to work in a hybrid setup.
- Familiarity with compliance frameworks such as NIST, PCI DSS, GDPR, SOC 2, or SOX.
Nice to have
- Relevant security certifications (e.g., OSCP, OSWE, CISSP, CCSP, AWS Certified Security Specialty).
- Experience coordinating vulnerability remediation with third-party bug bounty programs.
- Experience with Terraform and policy-as-code frameworks.
- Experience developing internal security tooling or developer-facing automation.
Culture & Benefits
- Comprehensive leave package including 22 weeks of paid parental leave and 26 vacation days per year.
- Pension plan and life insurance policy.
- Hybrid work model with work-from-home assistance and a central Amsterdam office.
- Wellness perks including a Headspace subscription and wellness webinars.
- Multicultural environment with commuting allowance for public transport and subsidized lunch.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →