Domain Expert – Secure Coding - 10826782

ITProposal

Amstelveen

On-site

EUR 90,000 - 130,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Hybrid work model
Collaborative environment

Job summary

ITProposal in Amstelveen, Netherlands, is seeking an experienced Domain Expert – Secure Coding (SECO) to strengthen the Secure Coding team within a large-scale banking environment. The role sits at the intersection of application security and software development and focuses on secure coding practices, vulnerability management, and DevSecOps.

The ideal candidate has 6–8 years of experience in secure coding, with a strong background in SAST/SCA tooling and security guidance for engineering teams.

Qualifications

  • 6–8 years of experience in software development, application security, or secure coding.
  • Proven experience with secure software development practices.
  • Strong understanding of application security principles.
  • Experience analyzing and resolving software vulnerabilities.
  • Experience working with developers to improve application security.
  • Experience in large enterprise environments.
  • Ability to communicate complex security concepts clearly to technical teams.

Responsibilities

  • Maintain and improve the organization's software security posture.
  • Define, maintain, and improve secure coding standards and guidelines.
  • Support development teams in implementing secure software development practices.
  • Provide guidance on application security best practices.
  • Help teams understand security risks and implement remediation strategies.
  • Analyze and triage security findings from tools like Fortify, Nexus Lifecycle, and other scanners.
  • Review, prioritize, and categorize vulnerabilities based on risk and business impact.
  • Improve vulnerability remediation processes.
  • Collaborate with development teams to fix vulnerabilities within applications.
  • Contribute to security tooling improvements and automation initiatives.

Skills

Secure coding
AppSec
Vulnerability analysis
Security remediation
SSDLC
DevSecOps practices

Education

Bachelor's degree in Computer Science
Bachelor's degree in Software Engineering
Bachelor's degree in Cyber Security
Bachelor's degree in Information Technology

Tools

Fortify
Nexus Lifecycle
GitHub Enterprise
Repository Scanner (RESC)

Job description

Job Summary

We are seeking an experienced Domain Expert – Secure Coding (SECO) to join the Development Services department within a large-scale regulated banking environment.

The Secure Coding (SECO) team acts as the knowledge center for software security, helping development teams improve the security, quality, and resilience of their applications. The successful candidate will work at the intersection of application security and software development, supporting engineering teams in identifying, understanding, and resolving security vulnerabilities.

This role focuses on improving secure coding practices, analyzing security findings, enhancing security tooling, and enabling developers to build secure software by design.

The ideal candidate will have strong experience in secure coding, application security, SAST/SCA tooling, software development, vulnerability management, and DevSecOps practices.

Key Responsibilities
Secure Coding & Application Security
  • Maintain and improve the organization's software security posture.
  • Define, maintain, and improve secure coding standards and guidelines.
  • Support development teams in implementing secure software development practices.
  • Provide guidance on application security best practices.
  • Help teams understand security risks and implement effective remediation strategies.
Security Findings Analysis & Vulnerability Management
  • Analyze and triage security findings from tools such as:
    • Fortify (SAST)
    • Nexus Lifecycle (SCA)
    • Similar security scanning tools
  • Review, prioritize, and categorize vulnerabilities based on risk and business impact.
  • Help developers understand security findings and provide remediation guidance.
  • Support development teams in fixing vulnerabilities within applications.
  • Improve vulnerability remediation processes.
Security Tooling Improvement
  • Improve and optimize security tooling capabilities.
  • Fine-tune security rulesets to:
    • Reduce false positives
    • Improve detection accuracy
    • Increase security quality
  • Contribute to internally developed security tools, including Repository Scanner (RESC).
  • Support automation initiatives around application security processes.
DevSecOps & Development Enablement
  • Collaborate closely with development teams across the organization.
  • Integrate security practices into software development workflows.
  • Support secure CI/CD practices.
  • Promote security-by-design principles.
  • Share knowledge and educate engineering teams on secure development practices.
Emerging Security Topics
  • Research and contribute to new security challenges, including:
    • AI-driven security threats
    • Agentic AI development risks
    • Emerging application security vulnerabilities
  • Help define approaches for managing new technology risks.
  • Support innovation within secure software development practices.
Collaboration & Knowledge Sharing
  • Work closely with:
    • Software developers
    • DevOps teams
    • Security specialists
    • Platform engineering teams
    • Architecture teams
  • Provide security guidance and technical support.
  • Conduct knowledge-sharing sessions.
  • Help create a security-aware development culture.
Working Environment

You will join a multicultural Agile team responsible for improving software security across the organization.

The Development Services department provides expertise and standards for software development practices across the enterprise.

The team operates in a collaborative environment where:

  • Developers are the primary stakeholders.
  • Secure development practices are continuously improved.
  • Innovation and automation are encouraged.
  • Hybrid working is the standard.

Work Location: Amstelveen, Netherlands
Work Model: Hybrid

Required Experience
  • 6–8 years of experience in software development, application security, or secure coding.
  • Proven experience working with secure software development practices.
  • Strong understanding of application security principles.
  • Experience analyzing and resolving software vulnerabilities.
  • Experience working with developers to improve application security.
  • Experience working in large enterprise environments.
  • Ability to communicate complex security concepts clearly to technical teams.
Mandatory Technical Skills
Application Security
  • Secure coding practices
  • Application Security (AppSec)
  • Vulnerability analysis
  • Security remediation
  • Secure Software Development Lifecycle (SSDLC)
  • DevSecOps practices
Security Testing Tools

Experience with:

  • Static Application Security Testing (SAST)
  • Software Composition Analysis (SCA)
  • Fortify
  • Nexus Lifecycle
  • Similar security scanning platforms
Development Skills
  • Strong software development experience in at least one programming language:
    • Python
    • Java
    • C#
    • JavaScript/TypeScript
    • Similar languages
Platform & Cloud Knowledge

Experience or understanding of:

  • Microsoft Azure
  • Kubernetes
  • GitHub Enterprise
  • CI/CD pipelines
  • Development tooling platforms
Nice-to-Have Skills
  • Experience with:
    • Repository security scanning
    • Security automation
    • Security policy enforcement
    • Cloud security practices
    • AI security risks
    • GitHub security features
  • Knowledge of container security.
  • Experience with Kubernetes security.
  • Experience in regulated industries such as banking or financial services.
  • Security certifications:
    • CISSP
    • CSSLP
    • Security+
    • CEH
    • Equivalent certifications
Key Competencies
  • Strong application security mindset
  • Analytical and problem-solving skills
  • Ability to investigate complex security issues
  • Strong communication and stakeholder management
  • Ability to collaborate with software engineers
  • Pragmatic approach to security
  • Knowledge-sharing mindset
  • Agile way of working
Language Requirements
  • English: Mandatory
  • Dutch language skills are advantageous but not required.
Education

Bachelor's degree or equivalent experience in:

  • Computer Science
  • Software Engineering
  • Cyber Security
  • Information TechnologyApplication Security

Relevant security certifications are beneficial.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Secure Coding & AppSec Specialist
Senior Secure Coding & AppSec Specialist

ITProposal • Amstelveen

Hybrid
EUR 90,000 - 130,000
Hybrid work model
Collaborative environment
Security Consultant
Security Consultant

Software Search • Netherlands

Hybrid
EUR 102,000 - 122,000
Permanent contract
Project variety and autonomy
Competitive compensation
+4
Security Engineer
Security Engineer

Software Search • Netherlands

Hybrid
EUR 100,000 - 123,000
Permanent contract
Training budget and security community
Cyber Security Specialist
Cyber Security Specialist

IQ Staffing • Amsterdam

On-site
Senior Application Security Engineer
Senior Application Security Engineer

Iceberg • Amsterdam

Hybrid
EUR 70,000 - 90,000
PD 2 | Senior DevSecOps Engineer | SaaS | Amsterdam | 115k
PD 2 | Senior DevSecOps Engineer | SaaS | Amsterdam | 115k

WKL Consultancy • Amsterdam

Hybrid
EUR 104,000 - 127,000
NS Business Card
Pension up to 6.5%
Hybrid working (Amsterdam office + WFH
+2
Security Software Engineer (Junior)
Security Software Engineer (Junior)

Accountancy Gemak • Delft

Hybrid
EUR 40,000 - 60,000
Hybrid working
Pension scheme
Vacation days (27 + 5 loyalty)
+3
Software Engineer Mission, Simulation & Training Systems
Software Engineer Mission, Simulation & Training Systems

United States Digital Space LLC • Den Haag

On-site
EUR 39,000 - 50,000
Flexible working hours
Work from home option
30 days holiday leave
IT Security Specialist
IT Security Specialist

Base Cyber Security • Utrecht

Hybrid
EUR 55,000 - 75,000
Senior Information Security Engineer
Senior Information Security Engineer

Cyber Security District • Amsterdam

Hybrid
EUR 79,000 - 94,000
Competitive salary
Hybrid work model
Employer-paid pension
+4