- As an Application Security Engineer, you will play a key role in safeguarding the security and privacy of Booking.com's customers.
- You will build and operate advanced security tooling, automate remediation, analyze security indicators, and partner with product teams to embed security throughout the software development lifecycle
- Your expertise will directly contribute to the detection, prevention, and response to application security threats across Booking.com's global platform
- Review applications, APIs, and designs to identify basic security risks
- Support secure code reviews and vulnerability assessments
- Help teams understand and remediate common web vulnerabilities
- Contribute to threat modelling and security requirements for new features
- Help integrate and maintain security checks in CI/CD pipelines, such as SAST, DAST, software composition analysis, and secrets scanning
- Support security reviews of AI- and LLM-enabled applications, where applicable
- Help identify basic AI-specific risks such as prompt injection, sensitive information disclosure, insecure output handling, excessive agency, model or data poisoning, and unbounded consumption
- Investigate security findings, assess their priority, and track remediation
- Support the configuration and use of application security tools
- Write simple scripts or automation to improve security processes
- Document findings, security requirements, procedures, and recommendations
- Work collaboratively with software engineers, platform teams, and security colleagues
- Keep up to date with common application security threats and defensive practices
- What success looks like;
- You identify and explain common application security risks
- Development teams receive practical remediation guidance
- Security checks are applied consistently during software development
- Findings are documented, prioritised, and followed through to resolution
- You build deeper application security expertise through hands-on work and continuous learning
Benefits
- Health insurance
- Free access to Headspace for you and your loved ones
- Global Employee Assistance Program
- Meditation and Breastfeeding rooms at the office
- Booking Cares - 2 days per year to volunteer and learn
- Life insurance
- Disability insurance
- Pension plan
- Annual paid time off
- Parental leave - 22 weeks
- Grandparent leave - 10 days
- Care leave - 10 days
- Bereavement leave - up to 4 weeks
- Anniversary leave
- Working from Home Furniture and Ergonomic Support
- Working from Abroad - up to 20 days per year
- Discounts & Wallet credits to spend on our products
- Upgrade to Booking.com Genius Level 3
- Friends & Family Booking.com discount vouchers
- Free access to online learning platforms
- Development and mentorship programs to support career growth
- Access to trainings and workshops
- Team development opportunities
- Local discount programs
- Game rooms in offices
- On-site meals, coffee and snacks including vegan options
Some experience with application security tools, such as SAST, DAST, software composition analysis, vulnerability scanners, or secrets-scanning toolsBachelor's or Master's degree in Computer Science or a related field3+ years of relevant industry experienceFamiliarity with common risks such as injection, broken access control, authentication failures, security misconfiguration, cross-site scripting, and insecure dependenciesAbility to work effectively with developers and other technical teamsAbility to communicate security findings clearly and constructivelyBasic to intermediate knowledge of application and web securityFamiliarity with HTTP, APIs, authentication, authorization, and TLSAnalytical mindset, attention to detail, and willingness to learnBasic scripting or automation skills in Python, Bash, or a similar languageBasic understanding of how LLM applications work, including prompts, model inputs and outputs, retrieval-augmented generation, and tool or API integrationsUnderstanding of the OWASP Top 10 and basic secure coding principlesAbility to read and understand code in at least one programming languageBasic understanding of how to secure LLM applications through input and output validation, data minimisation, access control, least privilege, rate limiting, logging, and human approval for high-impact actionsExperience with cloud platforms, containers, or infrastructure as codeFamiliarity with API security or microservicesExperience with threat modelling or security testingExperience or interest in securing AI or LLM-enabled applicationsFamiliarity with vulnerability management or incident responseKnowledge of privacy or security requirements relevant to software developmentSecurity certifications or relevant practical projects