Security Engineer II

Booking Holdings, Inc.

Amsterdam

Hybrid

EUR 70,000 - 100,000

Full time

2 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Hybrid working
Industry-leading discounts
Global impact

Job summary

Booking.com is seeking an Application Security Engineer to safeguard its global platform. You will build and operate security tooling, analyze indicators, and partner with product teams to embed security across the software lifecycle.

You will review applications, assist with vulnerability assessments, and help implement secure-by-design practices in collaboration with engineers and security colleagues.

Qualifications

  • Bachelor’s or Master’s in Computer Science or related field.
  • Basic to intermediate knowledge of application and web security.
  • Familiarity with OWASP Top 10 and secure coding principles.

Responsibilities

  • Review applications, APIs, and designs to identify basic security risks.
  • Support secure code reviews and vulnerability assessments.
  • Help teams remediate common web vulnerabilities.
  • Integrate security checks in CI/CD pipelines (SAST, DAST, SBOM, secrets).
  • Investigate findings and track remediation across the platform.

Skills

Application security knowledge
3+ years experience
OWASP Top 10
HTTP APIs TLS
Code reading (language)
Scripting (Python Bash)
Communication

Education

Bachelor’s or Master’s in CS

Tools

SAST
DAST
Software Composition Analysis
Vulnerability scanners
Secrets-scanning tools

Job description

About Us: At Booking.com, data drives our decisions. Technology is at our core. And innovation is everywhere. But our company is more than datasets, lines of code or A/B tests. We’re the thrill of the first night in a new place. The excitement of the next morning. The friends you encounter. The journeys you take. The sights you see. And the memories you make. Through our products, partners and people, we make it easier for everyone to experience the world.

About the team: Booking.com’s Application Security team is responsible for protecting the world’s largest travel platform against attacks targeting our application stack. The team develops and maintains the signals, tools, and infrastructure used to secure Booking.com products and defines secure coding practices for all developers. We work closely with product and engineering teams to ensure customer data remains safe through secure-by-design software architecture.

Role Description: As an Application Security Engineer, you will play a key role in safeguarding the security and privacy of Booking.com customers. You will build and operate advanced security tooling, automate remediation, analyze security indicators, and partner with product teams to embed security throughout the software development lifecycle.

Your expertise will directly contribute to the detection, prevention, and response to application security threats across Booking.com’s global platform.

Key responsibilities
  • Review applications, APIs, and designs to identify basic security risks.
  • Support secure code reviews and vulnerability assessments.
  • Help teams understand and remediate common web vulnerabilities.
  • Contribute to threat modelling and security requirements for new features.
  • Help integrate and maintain security checks in CI/CD pipelines, such as SAST, DAST, software composition analysis, and secrets scanning.
  • Support security reviews of AI- and LLM-enabled applications, where applicable.
  • Help identify basic AI-specific risks such as prompt injection, sensitive information disclosure, insecure output handling, excessive agency, model or data poisoning, and unbounded consumption.
  • Investigate security findings, assess their priority, and track remediation.
  • Support the configuration and use of application security tools.
  • Write simple scripts or automation to improve security processes.
  • Document findings, security requirements, procedures, and recommendations.
  • Work collaboratively with software engineers, platform teams, and security colleagues.
  • Keep up to date with common application security threats and defensive practices.
What we are looking for
  • Basic to intermediate knowledge of application and web security.
  • 3+ years of relevant industry experience
  • Familiarity with common risks such as injection, broken access control, authentication failures, security misconfiguration, cross-site scripting, and insecure dependencies.
  • Understanding of the OWASP Top 10 and basic secure coding principles.
  • Familiarity with HTTP, APIs, authentication, authorization, and TLS.
  • Ability to read and understand code in at least one programming language.
  • Basic scripting or automation skills in Python, Bash, or a similar language.
  • Some experience with application security tools, such as SAST, DAST, software composition analysis, vulnerability scanners, or secrets-scanning tools.
  • Basic understanding of how LLM applications work, including prompts, model inputs and outputs, retrieval-augmented generation, and tool or API integrations.
  • Basic understanding of how to secure LLM applications through input and output validation, data minimisation, access control, least privilege, rate limiting, logging, and human approval for high-impact actions.
  • Ability to communicate security findings clearly and constructively.
  • Analytical mindset, attention to detail, and willingness to learn.
  • Ability to work effectively with developers and other technical teams.
  • Bachelor’s or Master’s degree in Computer Science or a related field.
Nice to have
  • Experience with cloud platforms, containers, or infrastructure as code.
  • Familiarity with API security or microservices.
  • Experience or interest in securing AI or LLM-enabled applications.
  • Experience with threat modelling or security testing.
  • Familiarity with vulnerability management or incident response.
  • Knowledge of privacy or security requirements relevant to software development.
  • Security certifications or relevant practical projects.
What success looks like
  • You identify and explain common application security risks.
  • Development teams receive practical remediation guidance.
  • Security checks are applied consistently during software development.
  • Findings are documented, prioritised, and followed through to resolution.
  • You build deeper application security expertise through hands-on work and continuous learning.
Benefits & Perks - Global Impact, Personal Relevance:

Booking.com’s Total Rewards Philosophy is not only about compensation but also about benefits. We offer a competitive compensation and benefits package, as well unique-to-Booking.com benefits which include:

  • Annual paid time off and generous paid leave scheme including: parent, grandparent, bereavement, and care leave
  • Hybrid working including flexible working arrangements, and up to 20 days per year working from abroad (home country)
  • Industry leading product discounts - up to 1400 per year - for yourself, including automatic Genius Level 3 status and Booking.com wallet credit
  • Living and working in Amsterdam, one of the most cosmopolitan cities in Europe
  • Contributing to a high scale, complex, world renowned product and seeing real-time impact of your work on millions of travelers worldwide
  • Working in a fast-paced and performance driven culture
  • Opportunity to utilize technical expertise, leadership capabilities and entrepreneurial spirit
  • Promote and drive impactful and innovative engineering solutions
  • Technical, behavioral and interpersonal competence advancement via on-the-job opportunities, experimental projects, hackathons, conferences and active community participation
  • Competitive compensation and benefits package and some great added perks of working in the home city of Booking.com
Diversity, Equity and Inclusion (DEI) at Booking.com:

Diversity, Equity & Inclusion have been a core part of our company culture since day one. This ongoing journey starts with our very own employees, who represent over 140 nationalities and a wide range of ethnic and social backgrounds, genders and sexual orientations.

Take it from our Chief People Officer, Paulo Pisano: “At Booking.com, the diversity of our people doesn’t just build an outstanding workplace, it also creates a better and more inclusive travel experience for everyone. Inclusion is at the heart of everything we do. It’s a place where you can make your mark and have a real impact in travel and tech.”

We ensure that colleagues with disabilities are provided the adjustments and tools they need to participate in the job application and interview process, to perform crucial job functions, and to receive other benefits and privileges of employment.

Application Process:
  • Let’s go places together: How we Hire
  • This role does not come with relocation assistance.

Booking.com is proud to be an equal opportunity workplace and is an affirmative action employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability, age, or veteran status. We strive to move well beyond traditional equal opportunity and work to create an environment that allows everyone to thrive.

Pre-Employment Screening

If your application is successful, your personal data may be used for a pre-employment screening check by a third party as permitted by applicable law. Depending on the vacancy and applicable law, a pre-employment screening may include employment history, education and other information (such as media information) that may be necessary for determining your qualifications and suitability for the position.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Manager, Proactive Cyber Defence & Engineering
Manager, Proactive Cyber Defence & Engineering

Booking Holdings, Inc. • Amsterdam

Hybrid
EUR 170,000 - 210,000
Generous paid leave
Hybrid work including up to 20 days ab
Product discounts & benefits
Manager - Proactive Cyber Defence & Engineering
Manager - Proactive Cyber Defence & Engineering

Booking Holdings, Inc. • Amsterdam

Hybrid
EUR 180,000 - 260,000
Paid time off
Hybrid working
Product discounts
Security Engineer
Security Engineer

Booking.com • Amsterdam

On-site
EUR 85,000 - 125,000
Health insurance
Headspace access
Pension plan
+3
Solution Engineer I
Solution Engineer I

Booking Holdings, Inc. • Amsterdam

On-site
EUR 60,000 - 90,000
Hybrid working
Annual leave
Product discounts
Enterprise Applications Engineer II
Enterprise Applications Engineer II

Booking.com • Amsterdam

On-site
EUR 110,000 - 140,000
Annual time off
Hybrid work arrangements
Product discounts
+1
Physical Security Operations Specialist I
Physical Security Operations Specialist I

Booking.com • Amsterdam

Hybrid
EUR 65,000 - 95,000
Paid time off
Hybrid work
Product discounts
Senior Legal Counsel - Cyber
Senior Legal Counsel - Cyber

Booking.com • Amsterdam

Hybrid
EUR 110,000 - 150,000
Hybrid working
Product discounts
Generous paid leave
Software Engineer II - Partner Identity & Access Management - ABU
Software Engineer II - Partner Identity & Access Management - ABU

Booking Holdings, Inc. • Amsterdam

On-site
EUR 90,000 - 130,000
Annual paid time off
Hybrid working with flexible remote/
Product discounts – up to 1400 per yr
Technical Program Manager - IT Services
Technical Program Manager - IT Services

Booking.com • Amsterdam

Hybrid
EUR 90,000 - 130,000
Hybrid working
Annual paid time off
Travel discounts
Junior Trust & Safety Analyst
Junior Trust & Safety Analyst

Booking Holdings, Inc. • Amsterdam

On-site
EUR 38,000 - 54,000
Hybrid work
Generous leave and PTO
Product discounts
+1