> Markdown version of [/jobs/ext/1491970-application-security-engineer](https://www.wearedevelopers.com/jobs/ext/1491970-application-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Application Security Engineer - **Company:** FareHarbor - **Location:** Amsterdam, Netherlands - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Java (Programming Language), Application Programming Interfaces (APIs), Artificial Intelligence, Amazon Web Services, Applications Architecture, Software System Penetration Testing, Configuration Management, Code Review, CompTIA Security+, Continuous Integration, Cursor (Graphical User Interface Elements), Identity and Access Management, Intrusion Detection and Prevention, Python (Programming Language), Key Management, Open Source Technology, Open Web Application Security, PCI Data Security Standards, Performance Tuning, Systems Development Life Cycle, Secure Coding, Security Information and Event Management, Software Vulnerability Management, Policy as Code, Data Logging, Software Security, GWAPT, Gitlab-ci, Kubernetes, Infrastructure Automation Frameworks, Terraform, Security Orchestration, Automation & Response, Static Application Security Testing, Vulnerability Analysis, Microservices, Dynamic Application Security Testing - **Published:** July 30, 2026 - **Apply:** https://nl.indeed.com/viewjob?jk=62189c32e8093472 ## About the Role * Senior engineer with strong experience in application security, secure SDLC, strong technical knowledge of web/API security, common vulnerabilities, and practical mitigation strategies for OWASP Top 10. * Proven experience performing application security reviews, including code reviews, design reviews, and threat modeling, as well as supporting the remediation of security findings from penetration tests, vulnerability scans, and security audits. * Experience implementing security controls in GitLab CI/CD pipeline, such as SAST, DAST, SCA, secret scanning, IaC scanning, dependency scanning etc. * Proficiency in Python or other high-level language such as Go, Java, or similar * Good understanding of AWS security concepts, including IAM, WAF, Kubernetes, containers, and infrastructure as code * Experience with security monitoring, alert tuning, SIEM use cases, logging, detection engineering, or WAF rule tuning * Pentesting experience is a plus * Ability to assess risk, prioritize vulnerabilities, and balance security requirements with business needs and engineering realities * Familiarity with security and compliance frameworks such as NIST, PCI DSS, GDPR, SOC 2, SOX, or similar * Good understanding of incident response, security investigations, and technical incident management * Experience with API security, microservices security, and distributed application architectures * Experience with AI-assisted security automation for AppSec triage, vulnerability assessment, detection tuning, and security monitoring workflows using tools such as Cursor, Tines, Elastic, or similar., * Strong communication skills, able to explain technical security risks clearly to both technical and non-technical stakeholders * Able to work effectively with product, engineering, platform, infrastructure, and security teams * Proactive attitude, always on the look-out for improving your and our way of working * Strong problem-solving skills and ability to analyze complex systems and make decisions based on risk, data, and best practices * Strong relationship building skills across diverse cross-functional teams * Comfortable operating independently and taking ownership of security initiatives from discovery through implementation * Able to provide practical security guidance that enables teams to move quickly and securely, * Security certifications such as OSCP, OSWE, OSWA, GWAPT, GWEB, CISSP, CCSP, Security+, AWS Certified Security Specialty, or similar * Experience with bug bounty programs and coordinating vulnerability remediation with third party * Experience with Terraform, infrastructure as code, configuration management, and policy-as-code frameworks * Experience building internal security tooling or developer-facing security automation * Contributions to the security community through research, blog posts, conference talks, open-source tools, or responsible disclosures This role is available to candidates located in the Netherlands and requires ability to work in a hybrid setup with in-office presence.. ## Description FareHarbor is looking for a full time Application Security Engineer to join our Security Engineering team in Amsterdam. This role will primarily focus on application security and secure SDLC initiatives, while also supporting security monitoring efforts. We are looking for someone who can work closely with our Senior Application Security Engineer on application security reviews, secure development practices, CI/CD security controls, application vulnerability remediation, and broader security engineering initiatives. The ideal candidate is comfortable operating across multiple areas of security, with strong application security expertise and the ability to contribute to automation, detection engineering, and incident response., * Work closely with product, platform, and security teams to ensure security is an integral part of our SDLC * Perform application security reviews, code reviews, threat modeling, and design reviews for new and existing features, promote application security practices across engineering teams * Identify, assess, and help remediate vulnerabilities in applications, APIs, services, and GitLab CI/CD pipelines by implementing and maintaining application security controls such as security policies, SAST, DAST, SCA, container scanning, and other CI/CD security controls * Support assessment and remediation such as for penetration test findings, bug bounty findings, vulnerability scan results, internal or external audit by providing technical input, documentation, and evidence * Work with engineering teams to provide guidance on secure coding practices, application architecture, authentication, authorization, API security, secrets management, and secure deployment patterns * Support security initiatives, such as IAM, AWS WAF, Help fine-tune security monitoring and detection capabilities, including Elastic SIEM rules, WAF policies, alerting logic, logging improvements, and security automation * Participate in security alert triage, investigation, and incident response activities when needed * Participate in the security on-call rotation ## Related Videos - [Infrastructure as Code: The Developer's Secret Weapon](https://www.wearedevelopers.com/videos/1221-infrastructure-as-code-the-developer-s-secret-weapon) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Implementing Feature Environments with AWS and Terraform](https://www.wearedevelopers.com/videos/531-implementing-feature-environments-with-aws-and-terraform) - [Real-World Security for Busy Developers](https://www.wearedevelopers.com/videos/1545-real-world-security-for-busy-developers) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Terraform for Developers](https://www.wearedevelopers.com/videos/3-terraform-for-developers) ## Related Articles - [How to land a developer job in Amsterdam](https://www.wearedevelopers.com/magazine/36-how-to-land-a-developer-job-in-amsterdam) - [How to Find Tech Jobs in Amsterdam](https://www.wearedevelopers.com/magazine/279-how-to-find-tech-jobs-in-amsterdam) - [Software Developer Salary in The Netherlands [2023]](https://www.wearedevelopers.com/magazine/217-software-developer-salary-in-the-netherlands-2023) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Where To Find Software Engineering Jobs](https://www.wearedevelopers.com/magazine/396-where-to-find-software-engineering-jobs)