Security Engineer II

Booking.com

Amsterdam

Hybrid

EUR 90,000 - 130,000

Full time

46 hours ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Hybrid working
Product discounts
Amsterdam living benefits

Job summary

Booking.com is seeking an Application Security Engineer to safeguard our highly scalable travel platform. You will build and operate advanced security tooling, automate remediation, and partner with product teams to embed security across the software development lifecycle.

Your work will cover threat modelling, vulnerability assessments, and integrating SAST/DAST checks, while collaborating with engineers to implement secure-by-design solutions across our global services.

Qualifications

  • 3+ years of relevant industry experience in application security.
  • Understanding of OWASP Top 10 and secure coding principles.
  • Familiarity with HTTP, APIs, authentication, authorization, and TLS.

Responsibilities

  • Review applications, APIs, and designs to identify basic security risks.
  • Support secure code reviews and vulnerability assessments.
  • Help teams remediate common web vulnerabilities and integrate security checks in CI/CD.

Skills

Application security
OWASP Top 10
SAST/DAST tooling
Python/Bash scripting
CI/CD security

Education

Bachelor’s or Master’s degree in Computer Science or related field

Tools

SAST tools
DAST tools
Threat modelling tools

Job description

At Booking.com, data drives our decisions. Technology is at our core. And innovation is everywhere. But our company is more than datasets, lines of code or A/B tests. We’re the thrill of the first night in a new place. The excitement of the next morning. The friends you encounter. The journeys you take. The sights you see. And the memories you make. Through our products, partners and people, we make it easier for everyone to experience the world.

About the team

Booking.com’s Application Security team is responsible for protecting the world’s largest travel platform against attacks targeting our application stack. The team develops and maintains the signals, tools, and infrastructure used to secure Booking.com products and defines secure coding practices for all developers. We work closely with product and engineering teams to ensure customer data remains safe through secure-by-design software architecture.

Role Description

As an Application Security Engineer, you will play a key role in safeguarding the security and privacy of Booking.com customers. You will build and operate advanced security tooling, automate remediation, analyze security indicators, and partner with product teams to embed security throughout the software development lifecycle.

Your expertise will directly contribute to the detection, prevention, and response to application security threats across Booking.com’s global platform.

Key responsibilities
  • Review applications, APIs, and designs to identify basic security risks.
  • Support secure code reviews and vulnerability assessments.
  • Help teams understand and remediate common web vulnerabilities.
  • Contribute to threat modelling and security requirements for new features.
  • Help integrate and maintain security checks in CI/CD pipelines, such as SAST, DAST, software composition analysis, and secrets scanning.
  • Support security reviews of AI- and LLM-enabled applications, where applicable.
  • Help identify basic AI‑specific risks such as prompt injection, sensitive information disclosure, insecure output handling, excessive agency, model or data poisoning, and unbounded consumption.
  • Investigate security findings, assess their priority, and track remediation.
  • Support the configuration and use of application security tools.
  • Write simple scripts or automation to improve security processes.
  • Document findings, security requirements, procedures, and recommendations.
  • Work collaboratively with software engineers, platform teams, and security colleagues.
  • Keep up to date with common application security threats and defensive practices.
What we are looking for
  • Basic to intermediate knowledge of application and web security.
  • 3+ years of relevant industry experience
  • Familiarity with common risks such as injection, broken access control, authentication failures, security misconfiguration, cross-site scripting, and insecure dependencies.
  • Understanding of the OWASP Top 10 and basic secure coding principles.
  • Familiarity with HTTP, APIs, authentication, authorization, and TLS.
  • Ability to read and understand code in at least one programming language.
  • Basic scripting or automation skills in Python, Bash, or a similar language.
  • Some experience with application security tools, such as SAST, DAST, software composition analysis, vulnerability scanners, or secrets‑scanning tools.
  • Basic understanding of how LLM applications work, including prompts, model inputs and outputs, retrieval‑augmented generation, and tool or API integrations.
  • Basic understanding of how to secure LLM applications through input and output validation, data minimisation, access control, least privilege, rate limiting, logging, and human approval for high‑impact actions.
  • Ability to communicate security findings clearly and constructively.
  • Analytical mindset, attention to detail, and willingness to learn.
  • Ability to work effectively with developers and other technical teams.
  • Bachelor’s or Master’s degree in Computer Science or a related field.
Nice to have
  • Experience with cloud platforms, containers, or infrastructure as code.
  • Familiarity with API security or microservices.
  • Experience or interest in securing AI or LLM‑enabled applications.
  • Experience with threat modelling or security testing.
  • Familiarity with vulnerability management or incident response.
  • Knowledge of privacy or security requirements relevant to software development.
  • Security certifications or relevant practical projects.
What success looks like
  • You identify and explain common application security risks.
  • Development teams receive practical remediation guidance.
  • Security checks are applied consistently during software development.
  • Findings are documented, prioritised, and followed through to resolution.
  • You build deeper application security expertise through hands‑on work and continuous learning.
Benefits & Perks - Global Impact, Personal Relevance:

Booking.com’s Total Rewards Philosophy is not only about compensation but also about benefits. We offer a competitive compensation and benefits package, as well unique-to-Booking.com benefits which include:

  • Annual paid time off and generous paid leave scheme including: parent, grandparent, bereavement, and care leave
  • Hybrid working including flexible working arrangements, and up to 20 days per year working from abroad (home country)
  • Industry leading product discounts - up to 1400 per year - for yourself, including automatic Genius Level 3 status and Booking.com wallet credit
  • Living and working in Amsterdam, one of the most cosmopolitan cities in Europe
  • Contributing to a high scale, complex, world renowned product and seeing real‑time impact of your work on millions of travelers worldwide
  • Working in a fast‑paced and performance driven culture
  • Opportunity to utilize technical expertise, leadership capabilities and entrepreneurial spirit
  • Promote and drive impactful and innovative engineering solutions
  • Technical, behavioral and interpersonal competence advancement via on‑the‑job opportunities, experimental projects, hackathons, conferences and active community participation
  • Competitive compensation and benefits package and some great added perks of working in the home city of Booking.com
Diversity, Equity and Inclusion (DEI) at Booking.com:

Diversity, Equity & Inclusion have been a core part of our company culture since day one. This ongoing journey starts with our very own employees, who represent over 140 nationalities and a wide range of ethnic and social backgrounds, genders and sexual orientations.

Take it from our Chief People Officer, Paulo Pisano: “At Booking.com, the diversity of our people doesn’t just build an outstanding workplace, it also creates a better and more inclusive travel experience for everyone. Inclusion is at the heart of everything we do. It’s a place where you can make your mark and have a real impact in travel and tech.”

We ensure that colleagues with disabilities are provided the adjustments and tools they need to participate in the job application and interview process, to perform crucial job functions, and to receive other benefits and privileges of employment.

Booking.com is proud to be an equal opportunity workplace and is an affirmative action employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability, age, or veteran status. We strive to move well beyond traditional equal opportunity and work to create an environment that allows everyone to thrive.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Engineer II
Security Engineer II

Booking Holdings, Inc. • Amsterdam

On-site
EUR 80,000 - 120,000
Hybrid working
Annual paid time off
Product discounts
+2
Security Engineer
Security Engineer

Booking.com • Amsterdam

On-site
EUR 85,000 - 125,000
Health insurance
Headspace access
Pension plan
+3
Senior Security Architect
Senior Security Architect

Booking.com • Netherlands

Hybrid
EUR 120,000 - 180,000
Hybrid work
Work from abroad
Product discounts
+3
Physical Security Operations Specialist I
Physical Security Operations Specialist I

Booking Holdings, Inc. • Amsterdam

On-site
EUR 70,000 - 100,000
Principal Software Engineer I - Marketplace Data & AI
Principal Software Engineer I - Marketplace Data & AI

Booking.com • Amsterdam

On-site
EUR 150,000 - 195,000
Time off
Hybrid work
Ergonomic support
+3
Software Engineer II - Partner Identity & Access Management - ABU
Software Engineer II - Partner Identity & Access Management - ABU

Booking Holdings, Inc. • Amsterdam

Hybrid
EUR 90,000 - 130,000
Annual paid time off
Hybrid working with flexible remote/
Product discounts – up to 1400 per yr
Physical Security Operations Specialist I
Physical Security Operations Specialist I

Booking.com • Amsterdam

Hybrid
EUR 65,000 - 95,000
Paid time off
Hybrid work
Product discounts
Solution Engineer I
Solution Engineer I

Booking.com • Amsterdam

Hybrid
EUR 55,000 - 75,000
Annual paid time off
Hybrid working with international per-
Product discounts
Principal Software Engineer I - Data & AI - Marketplace
Principal Software Engineer I - Data & AI - Marketplace

Booking Holdings, Inc. • Amsterdam

On-site
EUR 150,000 - 190,000
Paid time off
Hybrid working options
HQ Amsterdam campus with on-site meals
+3
Trust & Safety Analyst
Trust & Safety Analyst

Booking.com • Amsterdam

On-site
EUR 65,000 - 90,000
Annual paid time off
Hybrid working up to 20 days abroad
Product discounts up to 1400/year