Security Engineer

Booking.com

Amsterdam

On-site

EUR 85,000 - 125,000

Full time

6 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Health insurance
Headspace access
Pension plan
Annual paid time off
Parental leave - 22 weeks
Bereavement leave

Job summary

Booking.com is seeking an Application Security Engineer to safeguard customer data and build advanced security tooling. You will partner with product teams to embed security across the software development lifecycle and improve remediation practices.

You'll review applications and APIs, perform secure code reviews, and help implement SAST/DAST/SCA scans. A strong focus on threat modelling, security requirements, and hands-on automation is expected.

Qualifications

  • Some experience with application security tools such as SAST, DAST, software composition analysis, vulnerability scanners, or secrets-scanning tools.
  • Bachelor's or Master's degree in Computer Science or a related field.
  • 3+ years of relevant industry experience.
  • Familiarity with common risks such as injection, broken access control, authentication failures, security misconfigurations, XSS, and insecure dependencies.

Responsibilities

  • Review applications, APIs, and designs to identify basic security risks.
  • Support secure code reviews and vulnerability assessments.
  • Help teams understand and remediate common web vulnerabilities.
  • Contribute to threat modelling and security requirements for new features.
  • Help integrate security checks in CI/CD pipelines (SAST, DAST, SCA, secrets scanning).
  • Support security reviews of AI- and LLM-enabled applications where applicable.
  • Investigate security findings, assess priority, and track remediation.
  • Document findings, security requirements, procedures, and recommendations.

Skills

SAST
DAST
Software composition analysis
Vulnerability scanners
Secrets scanning
Python scripting
Bash scripting
OWASP Top 10
Secure coding principles
Cloud platforms
Containers
APIs security
Threat modelling
Security testing
AI/LLM security

Education

Bachelor's or Master's degree in Computer Science or related field

Tools

SAST tools
DAST tools

Job description

  • As an Application Security Engineer, you will play a key role in safeguarding the security and privacy of Booking.com's customers.
  • You will build and operate advanced security tooling, automate remediation, analyze security indicators, and partner with product teams to embed security throughout the software development lifecycle
  • Your expertise will directly contribute to the detection, prevention, and response to application security threats across Booking.com's global platform
  • Review applications, APIs, and designs to identify basic security risks
  • Support secure code reviews and vulnerability assessments
  • Help teams understand and remediate common web vulnerabilities
  • Contribute to threat modelling and security requirements for new features
  • Help integrate and maintain security checks in CI/CD pipelines, such as SAST, DAST, software composition analysis, and secrets scanning
  • Support security reviews of AI- and LLM-enabled applications, where applicable
  • Help identify basic AI-specific risks such as prompt injection, sensitive information disclosure, insecure output handling, excessive agency, model or data poisoning, and unbounded consumption
  • Investigate security findings, assess their priority, and track remediation
  • Support the configuration and use of application security tools
  • Write simple scripts or automation to improve security processes
  • Document findings, security requirements, procedures, and recommendations
  • Work collaboratively with software engineers, platform teams, and security colleagues
  • Keep up to date with common application security threats and defensive practices
  • What success looks like;
  • You identify and explain common application security risks
  • Development teams receive practical remediation guidance
  • Security checks are applied consistently during software development
  • Findings are documented, prioritised, and followed through to resolution
  • You build deeper application security expertise through hands-on work and continuous learning
Benefits
  • Health insurance
  • Free access to Headspace for you and your loved ones
  • Global Employee Assistance Program
  • Meditation and Breastfeeding rooms at the office
  • Booking Cares - 2 days per year to volunteer and learn
  • Life insurance
  • Disability insurance
  • Pension plan
  • Annual paid time off
  • Parental leave - 22 weeks
  • Grandparent leave - 10 days
  • Care leave - 10 days
  • Bereavement leave - up to 4 weeks
  • Anniversary leave
  • Working from Home Furniture and Ergonomic Support
  • Working from Abroad - up to 20 days per year
  • Discounts & Wallet credits to spend on our products
  • Upgrade to Booking.com Genius Level 3
  • Friends & Family Booking.com discount vouchers
  • Free access to online learning platforms
  • Development and mentorship programs to support career growth
  • Access to trainings and workshops
  • Team development opportunities
  • Local discount programs
  • Game rooms in offices
  • On-site meals, coffee and snacks including vegan options

Some experience with application security tools, such as SAST, DAST, software composition analysis, vulnerability scanners, or secrets-scanning toolsBachelor's or Master's degree in Computer Science or a related field3+ years of relevant industry experienceFamiliarity with common risks such as injection, broken access control, authentication failures, security misconfiguration, cross-site scripting, and insecure dependenciesAbility to work effectively with developers and other technical teamsAbility to communicate security findings clearly and constructivelyBasic to intermediate knowledge of application and web securityFamiliarity with HTTP, APIs, authentication, authorization, and TLSAnalytical mindset, attention to detail, and willingness to learnBasic scripting or automation skills in Python, Bash, or a similar languageBasic understanding of how LLM applications work, including prompts, model inputs and outputs, retrieval-augmented generation, and tool or API integrationsUnderstanding of the OWASP Top 10 and basic secure coding principlesAbility to read and understand code in at least one programming languageBasic understanding of how to secure LLM applications through input and output validation, data minimisation, access control, least privilege, rate limiting, logging, and human approval for high-impact actionsExperience with cloud platforms, containers, or infrastructure as codeFamiliarity with API security or microservicesExperience with threat modelling or security testingExperience or interest in securing AI or LLM-enabled applicationsFamiliarity with vulnerability management or incident responseKnowledge of privacy or security requirements relevant to software developmentSecurity certifications or relevant practical projects

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Engineer II
Security Engineer II

Booking Holdings, Inc. • Amsterdam

On-site
EUR 80,000 - 120,000
Hybrid working
Annual paid time off
Product discounts
+2
Senior Security Architect
Senior Security Architect

Booking.com • Netherlands

Hybrid
EUR 120,000 - 180,000
Hybrid work
Work from abroad
Product discounts
+3
Application Security Engineer — Secure SDLC & AI Risks
Application Security Engineer — Secure SDLC & AI Risks

Booking.com • Amsterdam

On-site
EUR 85,000 - 125,000
Health insurance
Headspace access
Pension plan
+3
Physical Security Operations Specialist I
Physical Security Operations Specialist I

Booking Holdings, Inc. • Amsterdam

On-site
EUR 70,000 - 100,000
Solution Engineer I
Solution Engineer I

Booking Holdings, Inc. • Amsterdam

On-site
EUR 60,000 - 90,000
Hybrid working
Annual leave
Product discounts
Software Engineer II - Partner Identity & Access Management - ABU
Software Engineer II - Partner Identity & Access Management - ABU

Booking Holdings, Inc. • Amsterdam

Hybrid
EUR 90,000 - 130,000
Annual paid time off
Hybrid working with flexible remote/
Product discounts – up to 1400 per yr
Director Central Technology and Security, Safety & Fraud (SSF) Risk Operations
Director Central Technology and Security, Safety & Fraud (SSF) Risk Operations

Booking Holdings, Inc. • Amsterdam

Hybrid
EUR 180,000 - 240,000
Physical Security Operations Specialist I
Physical Security Operations Specialist I

Booking.com • Amsterdam

Hybrid
EUR 65,000 - 95,000
Paid time off
Hybrid work
Product discounts
Senior Operational Excellence Specialist - Trust & Safety
Senior Operational Excellence Specialist - Trust & Safety

Booking Holdings, Inc. • Amsterdam

On-site
EUR 90,000 - 120,000
Hybrid working including international
Generous paid leave
Product discounts
Principal Software Engineer I - Data & AI - Marketplace
Principal Software Engineer I - Data & AI - Marketplace

Booking Holdings, Inc. • Amsterdam

On-site
EUR 150,000 - 190,000
Paid time off
Hybrid working options
HQ Amsterdam campus with on-site meals
+3