Skip to content
← Back to job listings

Application Security Engineer

FareHarbor · Amsterdam, Netherlands

External listingfull-time3 days ago

About The Role

Join FareHarbor, a leading company in the travel and tourism industry, as a full-time Application Security Engineer. In this role, you will focus on application security and secure SDLC initiatives, while also supporting security monitoring efforts. You will work closely with the Senior Application Security Engineer on various security initiatives, including application security reviews, secure development practices, CI/CD security controls, and application vulnerability remediation. The ideal candidate will have strong application security expertise and the ability to contribute to automation, detection engineering, and incident response.

  • Collaborate with cross-functional teams to integrate security into the software development lifecycle (SDLC) and promote secure coding practices.
  • Conduct application security reviews, code reviews, threat modeling, and design reviews for new and existing features, and help remediate vulnerabilities.
  • Implement and maintain application security controls such as security policies, SAST, DAST, SCA, container scanning, and other CI/CD security controls.
  • Ability to assess risk, prioritize vulnerabilities, and balance security requirements with business needs and engineering realities
  • Strong relationship building skills across diverse cross-functional teams
  • Familiarity with security and compliance frameworks such as NIST, PCI DSS, GDPR, SOC 2, SOX, or similar
  • Strong problem-solving skills and ability to analyze complex systems and make decisions based on risk, data, and best practices
  • Good understanding of AWS security concepts, including IAM, WAF, Kubernetes, containers, and infrastructure as code
  • Proactive attitude, always on the look-out for improving your and our way of working
  • Strong communication skills, able to explain technical security risks clearly to both technical and non-technical stakeholders
  • Experience with security monitoring, alert tuning, SIEM use cases, logging, detection engineering, or WAF rule tuning
  • Able to provide practical security guidance that enables teams to move quickly and securely
  • Pentesting experience is a plus
  • Proven experience performing application security reviews, including code reviews, design reviews, and threat modeling, as well as supporting the remediation of security findings from penetration tests, vulnerability scans, and security audits
  • Experience implementing security controls in GitLab CI/CD pipeline, such as SAST, DAST, SCA, secret scanning, IaC scanning, dependency scanning etc
  • Experience with API security, microservices security, and distributed application architectures
  • Good understanding of incident response, security investigations, and technical incident management
  • Senior engineer with strong experience in application security, secure SDLC, strong technical knowledge of web/API security, common vulnerabilities, and practical mitigation strategies for OWASP Top 10
  • Able to work effectively with product, engineering, platform, infrastructure, and security teams
  • Proficiency in Python or other high-level language such as Go, Java, or similar
  • Comfortable operating independently and taking ownership of security initiatives from discovery through implementation
  • Experience with AI-assisted security automation for AppSec triage, vulnerability assessment, detection tuning, and security monitoring workflows using tools such as Cursor, Tines, Elastic, or similar
  • Security certifications such as OSCP, OSWE, OSWA, GWAPT, GWEB, CISSP, CCSP, Security+, AWS Certified Security Specialty, or similar
  • Experience with bug bounty programs and coordinating vulnerability remediation with third party
  • Experience with Terraform, infrastructure as code, configuration management, and policy-as-code frameworks
  • Experience building internal security tooling or developer-facing security automation
  • Contributions to the security community through research, blog posts, conference talks, open-source tools, or responsible disclosures

This is an external listing. JobSpring does not represent or verify the employer. Report this listing