Domain Expert - Secure Coding - 10826782

ITProposal
Amsterdam, Netherlands
12 days ago

Role details

Contract type
Temporary contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
6 years minimum
Working hours
Regular working hours
Languages
Dutch, English

Tech stack

Kubernetes Security Java (Programming Language) JavaScript (Programming Language) Agile Methodology Artificial Intelligence Microsoft Azure C Sharp (Programming Language) Cloud Computing Cloud Computing Security Cyber Security Continuous Integration DevOps
+18 more
Github Python (Programming Language) Cisco Nexus Switches Fortify (Software) Secure Coding Software Engineering TypeScript Software Vulnerability Management Software Security Kubernetes Information Technology Github Enterprise Virtual Agents Devsecops Security Orchestration, Automation & Response Static Application Security Testing Vulnerability Analysis Programming Languages

Job description

  • Maintain and improve the organization’s software security posture.
  • Define, maintain, and improve secure coding standards and guidelines.
  • Support development teams in implementing secure software development practices.
  • Provide guidance on application security best practices.
  • Help teams understand security risks and implement effective remediation strategies.

Security Findings Analysis & Vulnerability Management

  • Analyze and triage security findings from tools such as:
  • Fortify (SAST)
  • Nexus Lifecycle (SCA)
  • Similar security scanning tools
  • Review, prioritize, and categorize vulnerabilities based on risk and business impact.
  • Help developers understand security findings and provide remediation guidance.
  • Support development teams in fixing vulnerabilities within applications.
  • Improve vulnerability remediation processes.

Security Tooling Improvement

  • Improve and optimize security tooling capabilities.
  • Fine-tune security rulesets to:
  • Reduce false positives
  • Improve detection accuracy
  • Increase security quality
  • Contribute to internally developed security tools, including Repository Scanner (RESC).
  • Support automation initiatives around application security processes.

DevSecOps & Development Enablement

  • Collaborate closely with development teams across the organization.
  • Integrate security practices into software development workflows.
  • Support secure CI/CD practices.
  • Promote security-by-design principles.
  • Share knowledge and educate engineering teams on secure development practices.

Emerging Security Topics

  • Research and contribute to new security challenges, including:
  • AI-driven security threats
  • Agentic AI development risks
  • Emerging application security vulnerabilities
  • Help define approaches for managing new technology risks.
  • Support innovation within secure software development practices.

Collaboration & Knowledge Sharing

  • Work closely with:
  • Software developers
  • DevOps teams
  • Security specialists
  • Platform engineering teams
  • Architecture teams
  • Provide security guidance and technical support.
  • Conduct knowledge-sharing sessions.
  • Help create a security-aware development culture.

Working Environment

You will join a multicultural Agile team responsible for improving software security across the organization.

The Development Services department provides expertise and standards for software development practices across the enterprise.

The team operates in a collaborative environment where:

  • Developers are the primary stakeholders.
  • Secure development practices are continuously improved.
  • Innovation and automation are encouraged.
  • Hybrid working is the standard.

Requirements

The ideal candidate will have strong experience in secure coding, application security, SAST/SCA tooling, software development, vulnerability management, and DevSecOps practices., * 6-8 years of experience in software development, application security, or secure coding.

  • Proven experience working with secure software development practices.
  • Strong understanding of application security principles.
  • Experience analyzing and resolving software vulnerabilities.
  • Experience working with developers to improve application security.
  • Experience working in large enterprise environments.
  • Ability to communicate complex security concepts clearly to technical teams.

Mandatory Technical Skills Application Security

  • Secure coding practices
  • Application Security (AppSec)
  • Vulnerability analysis
  • Security remediation
  • Secure Software Development Lifecycle (SSDLC)
  • DevSecOps practices

Security Testing Tools

Experience with:

  • Static Application Security Testing (SAST)
  • Software Composition Analysis (SCA)
  • Fortify
  • Nexus Lifecycle
  • Similar security scanning platforms

Development Skills

  • Strong software development experience in at least one programming language:
  • Python
  • Java
  • C#
  • JavaScript/TypeScript
  • Similar languages

Platform & Cloud Knowledge

Experience or understanding of:

  • Microsoft Azure
  • Kubernetes
  • GitHub Enterprise
  • CI/CD pipelines
  • Development tooling platforms

Nice-to-Have Skills

  • Experience with:
  • Repository security scanning
  • Security automation
  • Security policy enforcement
  • Cloud security practices
  • AI security risks
  • GitHub security features
  • Knowledge of container security.
  • Experience with Kubernetes security.li>
  • Experience in regulated industries such as banking or financial services.
  • Security certifications:
  • CISSP
  • CSSLP
  • Security+
  • CEH
  • Equivalent certifications

Key Competencies

  • Strong application security mindset
  • Analytical and problem-solving skills
  • Ability to investigate complex security issues
  • Strong communication and stakeholder management
  • Ability to collaborate with software engineers
  • Pragmatic approach to security
  • Knowledge-sharing mindset
  • Agile way of working

Language Requirements

  • English: Mandatory
  • Dutch language skills are advantageous but not required.

Education

Bachelor’s degree or equivalent experience in:

  • Computer Science
  • Software Engineering
  • Cyber Security
  • Information Technology
  • Application Security

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.jobbird.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:17 min

Mapping the maturity roadmap for scaled devops adoption

Dominik Krichbaum Dominik Krichbaum · WWC Europe 2026

6:36 min

Funding open source through GitHub Accelerator and Sponsors

Stormy Peters · WWC 2023

1:15 min

Key lessons learned from implementing automated mobile DevSecOps

Moataz Nabil Moataz Nabil · LIVE

10:42 min

Essential soft skills and evaluating security candidates

Kurt Eder · LIVE

3:18 min

Scaling global network engineering through DevOps culture

Stuart Clark · LIVE

1:22 min

Addressing the shortage of application security specialists

Joseph Katsioloudes Joseph Katsioloudes · WWC 2025

Videos

See all

Related articles

See all