Skip to content
← Back to job listings

Security Engineer

Bynder · Rotterdam, Netherlands

Quick applyfull-time24 days ago

About The Role

Join Bynder's Security team as a Security Engineer. You'll work closely with the VP of Information Security and an Associate Security Engineer to cover the full security stack, including AppSec, cloud, detection, and governance. Your responsibilities will include executing penetration tests, embedding security across the SDLC, evolving our cloud security posture, championing security controls within CI/CD pipelines, supporting security incident response, translating compliance requirements into technical controls, conducting vendor and third-party security risk assessments, and sharing knowledge with your team. Enjoy a hybrid work environment, generous parental and family leave, comprehensive health plans, unlimited holidays, and more.

  • Plan and execute penetration tests against web applications, APIs, and cloud infrastructure, and manage external pentest engagements.
  • Embed security across the full SDLC: leading threat modeling, security assessments, and vulnerability remediation in close collaboration with engineering and product teams.
  • Own and evolve our cloud security posture across our AWS environment, working with Wiz to drive risk prioritization, misconfiguration remediation, and shift-left security workflows.
  • At Bynder, we believe security should never be an afterthought. We’re looking for a Security Engineer who thrives in a growth-oriented environment, someone who sees security as a starting point, not the finish line
  • If you’re hands-on by nature, energized by breadth, and serious about building security that actually scales in a cloud-native SaaS environment, you’ll feel right at home here
  • Solid understanding of AWS security: IAM, VPC design, cloud-native architecture and a clear intuition for what secure cloud infrastructure looks like
  • A growth mindset and genuine curiosity, you’re comfortable operating across domains, actively building skills you don’t yet have, and you see a broad scope as an opportunity, not a burden
  • 3–7 years of hands-on experience in application security, cloud security (AWS), or a broad security engineering role
  • Proven experience conducting penetration tests on web applications, APIs, and/or cloud environments, with a solid grip on OWASP Top 10 and common vulnerability classes
  • Familiarity with application security testing tools (SAST, DAST) and a practical understanding of DevSecOps: you know where to plug in and how to make it stick with developers
  • Strong communication skills, you can explain security risks clearly to both engineers and non-technical stakeholders, and you don’t default to “no” when there’s a smarter path forward
  • Have hands-on experience with Wiz, or other CSPM/CNAPP platforms
  • Write security scripts, tinker with tools, or keep a personal GitHub with automation or research projects
  • Hold an offensive security certification (OSCP or similar) or have contributed to bug bounty programmes
  • Have experience with AI/ML security risks and frameworks (OWASP LLM Top 10, MITRE ATLAS)
  • Have experience with Terraform or IaC security scanning
  • Have hands-on experience with Kubernetes and container security
  • Are familiar with common programming languages (e.g. Python, Java, Scala) and can read and reason about code to support security reviews
  • If you don’t tick every box but you’re the kind of person who figures things out, speaks up, and raises the standard around you we’d still love to hear from you

This listing was posted by a verified recruiter at Bynder. Report this listing