Security Engineer
Booking.com · Amsterdam, Netherlands
About The Role
Join as an Application Security Engineer, where you will play a crucial role in safeguarding the security and privacy of our customers. You will build and operate advanced security tooling, automate remediation, analyze security indicators, and partner with product teams to embed security throughout the software development lifecycle. Your expertise will directly contribute to the detection, prevention, and response to application security threats across our global platform. - Identifying and explaining common application security risks, providing practical remediation guidance to development teams. - Building and operating advanced security tooling, automating remediation, and analyzing security indicators to enhance application security. - Collaborating with software engineers, platform teams, and security colleagues to embed security throughout the software development lifecycle. - Some experience with application security tools, such as SAST, DAST, software composition analysis, vulnerability scanners, or secrets-scanning tools - Bachelor’s or Master’s degree in Computer Science or a related field - 3+ years of relevant industry experience - Familiarity with common risks such as injection, broken access control, authentication failures, security misconfiguration, cross-site scripting, and insecure dependencies - Ability to work effectively with developers and other technical teams - Ability to communicate security findings clearly and constructively - Basic to intermediate knowledge of application and web security - Familiarity with HTTP, APIs, authentication, authorization, and TLS - Analytical mindset, attention to detail, and willingness to learn - Basic scripting or automation skills in Python, Bash, or a similar language - Basic understanding of how LLM applications work, including prompts, model inputs and outputs, retrieval-augmented generation, and tool or API integrations - Understanding of the OWASP Top 10 and basic secure coding principles - Ability to read and understand code in at least one programming language - Basic understanding of how to secure LLM applications through input and output validation, data minimisation, access control, least privilege, rate limiting, logging, and human approval for high-impact actions - Experience with cloud platforms, containers, or infrastructure as code - Familiarity with API security or microservices - Experience with threat modelling or security testing - Experience or interest in securing AI or LLM-enabled applications - Familiarity with vulnerability management or incident response - Knowledge of privacy or security requirements relevant to software development - Security certifications or relevant practical projects
Similar roles you might like
See all →This is an external listing. JobSpring does not represent or verify the employer. Report this listing
