application security engineer for travel experiences

HireHi

Amsterdam

On-site

EUR 90,000 - 140,000

Full time

11 days ago
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

26 дней отпуска в год
Страхование жизни
Пенсионный план

Job summary

FareHarbor ищет опытного специалиста по кибербезопасности для интеграции практик безопасности в процессы разработки в Амстердаме. Вы будете работать с командами product, platform и security, обеспечивая надёжный SDLC и защиту веб- и API‑сервисов.

Кандидат должен иметь опыт в GitLab CI/CD, SAST/DAST/SCA, владение Python/Go/Java и знание AWS/Kubernetes. Вакансия предполагает работу на месте в Амстердаме с комплексными льготами.

Qualifications

  • Сильный опыт в области безопасности приложений и безопасного жизненного цикла (SDLC).
  • Знания веб- и API-безопасности, OWASP Top 10.
  • Опыт внедрения GitLab CI/CD security controls и устранения уязвимостей.
  • Практические навыки программирования на Python/Go/Java.
  • Понимание AWS, Kubernetes, контейнеров и инфраструктуры как кода.

Responsibilities

  • Сотрудничество с командами продукта, платформы и безопасности для внедрения безопасности в SDLC.
  • Проведение обзоров безопасности, threat modeling и дизайна архитектуры.
  • Идентификация и устранение уязимостей в приложениях, API, сервисах и CI/CD пайплайнах.
  • Поддержка политики безопасности, SAST/DAST/SCA и сканирования контейнеров.
  • Участие в устранении результатов тестирования на проникновение и аудитов с документацией.

Skills

Application security
Threat modeling
Secure SDLC
Python
Go
Java
AWS security
Kubernetes
SIEM

Tools

GitLab CI/CD
SAST
DAST
SCA
IaC scanning
Container scanning

Job description

Описание: FareHarbor creates reservation software and operational tools for tours, activities, attractions, and other experience-based businesses. The company serves over 20,000 clients across more than 90 countries and operates as part of Booking Holdings.

Задачи:
  • Collaborate with product, platform, and security teams to integrate security into the SDLC;
  • Perform application security reviews, code reviews, threat modeling, and design reviews;
  • Promote application security practices across engineering teams;
  • Identify, assess, and help remediate vulnerabilities in applications, APIs, services, and GitLab CI/CD pipelines;
  • Implement and maintain security policies, SAST, DAST, SCA, container scanning, and other CI/CD security controls;
  • Support remediation of penetration test, bug bounty, vulnerability scan, and audit findings with technical input, documentation, and evidence;
  • Write and maintain code and automation for application security workflows, security tooling, vulnerability management, detection, and CI/CD security controls;
  • Guide engineering teams on secure coding, application architecture, authentication, authorization, API security, secrets management, and secure deployment patterns;
  • Support IAM and AWS WAF initiatives;
  • Fine-tune security monitoring and detection capabilities, including Elastic SIEM rules, WAF policies, alerting logic, logging improvements, and security automation;
  • Participate in security alert triage, investigations, and incident response activities;
  • Participate in the security on-call rotation.
Требования:
  • Strong experience in application security and secure SDLC;
  • Strong knowledge of web and API security, common vulnerabilities, and OWASP Top 10 mitigation strategies;
  • Experience with application security reviews, code reviews, design reviews, threat modeling, and remediation of findings from penetration tests, vulnerability scans, and security audits;
  • Experience implementing GitLab CI/CD security controls, including SAST, DAST, SCA, secret scanning, IaC scanning, and dependency scanning;
  • Strong hands‑on programming experience in Python, Go, Java, or another high‑level language;
  • Ability to independently write, review, debug, and maintain code;
  • Good understanding of AWS security concepts, IAM, WAF, Kubernetes, containers, and infrastructure as code;
  • Experience with security monitoring, alert tuning, SIEM use cases, logging, detection engineering, or WAF rule tuning;
  • Ability to assess risk, prioritize vulnerabilities, and balance security requirements with business needs and engineering realities;
  • Familiarity with NIST, PCI DSS, GDPR, SOC 2, SOX, or similar security and compliance frameworks;
  • Good understanding of incident response, security investigations, and technical incident management;
  • Experience with API security, microservices security, and distributed application architectures;
  • Experience with AI‑assisted security automation for AppSec triage, vulnerability assessment, detection tuning, and security monitoring workflows;
  • Strong communication, problem‑solving, decision‑making, and relationship‑building skills;
  • Ability to work effectively with product, engineering, platform, infrastructure, and security teams;
  • Ability to operate independently and take ownership of security initiatives from discovery through implementation;
  • Ability to provide practical security guidance that enables teams to move quickly and securely;
  • Nice to have: Pentesting experience, security certifications such as OSCP, OSWE, OSWA, GWAPT, GWEB, CISSP, CCSP, Security+, AWS Certified Security Specialty, experience with bug bounty programs and third‑party vulnerability remediation, Terraform, infrastructure as code, configuration management, policy‑as‑code frameworks, internal security tooling, developer‑facing security automation, security community contributions through research, blog posts, conference talks, open‑source tools, or responsible disclosures.
Условия:
  • Candidates must be located in the Netherlands;
  • 22 Weeks of paid parental leave;
  • 2 Weeks of paid grandparent leave;
  • Extended care and bereavement leave;
  • Life insurance policy;
  • Pension plan;
  • Central Amsterdam location;
  • Discounted CZ insurance;
  • Commuting allowance for public transport and subsidized lunch;
  • Wellness benefits, including Headspace subscription and wellness webinars;
  • Work-from-home assistance;
  • Educational opportunities and individual skill development and growth programming;
  • Social hours, events, and team-building;
  • 26 Vacation days per year;
  • Pre‑employment screening is required before any offer of work.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Application Security Engineer
Application Security Engineer

FareHarbor • Amsterdam

On-site
EUR 90,000 - 120,000
Parental leave
Pension plan
Central Amsterdam location
+6
security engineer in fintech
security engineer in fintech

Enfint • Amsterdam

On-site
EUR 70,000 - 110,000
Stock options
Pension
Hardware provided
+3
devops engineer for workplace learning
devops engineer for workplace learning

Enfint • Amsterdam

Hybrid
EUR 40,000 - 70,000
Гибкий график
Безлимитные отпуска
Lepaya Fridays каждые две недели
+1
Application Security Engineer – Travel Experiences
Application Security Engineer – Travel Experiences

HireHi • Amsterdam

On-site
EUR 90,000 - 140,000
26 дней отпуска в год
Страхование жизни
Пенсионный план
Senior Security Engineer
Senior Security Engineer

WeTravel • Amsterdam

On-site
EUR 85,000 - 125,000
Competitive salary
Time to Recharge
Work From Anywhere
+3
Security Testing
Security Testing

Cognizant • Amsterdam

On-site
EUR 90,000 - 120,000
NS Business Card for public transport
Laptop and smartphone provided
Pension scheme
+2
low-code developer for financial APIs
low-code developer for financial APIs

Enfint • Amsterdam

On-site
EUR 75,000 - 95,000
security engineer in edtech
security engineer in edtech

HireHi • Amsterdam

On-site
EUR 120,000 - 160,000
Relocation support
Lessons allowance
Learning budget
+2
machine learning engineer for travel LLMs
machine learning engineer for travel LLMs

Enfint • Amsterdam

Hybrid
EUR 95,000 - 140,000
Parental leave 22 weeks
Bike reimbursement
Headspace membership
+2
devops engineer in intelligent business
devops engineer in intelligent business

Enfint • Amsterdam

On-site
EUR 90,000 - 130,000
Hybrid work model
4X9 workweek
Annual Bonus
+12