Security Engineer - API and AI Security

ABN AMRO Bank N.V.
Amstelveen, Netherlands
1 day ago
Apply on www.werkenbijabnamro.nl
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Working hours
Regular working hours

Tech stack

JavaScript (Programming Language) Application Programming Interfaces (APIs) Amazon Web Services Application Layers Microsoft Azure Code Review Cyber Security Corona (Software Development Kit) Data Governance Python (Programming Language) Network Security OAuth
+9 more
OpenID Windows PowerShell Scrum Methodology Secure Coding Large Language Models Software Security Containerization Kubernetes Api Gateway

Job description

Role purpose: Strengthen the security of modern applications by protecting APIs and AI-enabled systems, reducing risk across the software development lifecycle, and enabling secure product delivery through practical engineering and guidance., * Design and implement security controls for API security (authentication/authorization, rate limiting, schema validation, abuse prevention).

  • Assess and mitigate risks in AI/ML and LLM-integrated applications, including prompt injection, data leakage, and model supply-chain threats.
  • Build and maintain secure-by-default patterns, reference architectures, and reusable libraries for development teams.
  • Perform threat modeling, security architecture reviews, and code reviews for high-impact services.
  • Integrate security testing into CI/CD (SAST, DAST, SCA, secrets scanning) and drive remediation to closure.
  • Define and monitor security requirements, logging, and alerting for APIs and AI features in production.
  • Partner with engineering, product, and compliance teams to align security with delivery timelines and business goals., Rather than functioning as a passive reviewer, you actively collaborate with development and platform teams. You analyze real-time telemetry from our API security platforms, translate complex vulnerability findings into practical, developer-friendly remediation guidance, and review API architectures-including emerging frontiers like AI and Model Context Protocol (MCP) platform security. You’ll spend your time tuning Web Application Firewalls (WAF), API and AI secuerity platforms, assisting with firewall change approvals, and consulting directly with feature teams to ensure security is built into products from the start., You are a security engineer who understands both sides of the coin: the intricate mechanics of network defense and the fast-paced reality of modern software development. You excel at taking complex threat telemetry and turning it into clear, empathetic guidance that developers can actually act on.

Requirements

  • Hands-on application security experience with modern web services, microservices, and REST/GraphQL APIs.
  • Strong knowledge of OAuth2/OIDC, JWT, mTLS, API gateways, and identity/access patterns.
  • Familiarity with AI security concepts (LLM threat models, data governance, secure evaluation, red teaming).
  • Proficiency in at least one programming language (e.g., Python, Java, Go, JavaScript) and secure coding practices.
  • Experience with cloud platforms and containerized deployments (e.g., AWS/Azure/GCP, Kubernetes)., * Proactive problem-solver: You thrive in an Agile/Scrum team, briging continuous improvement midnest and a passion for data-driven decision making
  • AppSec & API Security Expertise: You bring hands-on experience with dedicated API security tooling (such as Salt, Noname/Akamai, or Sequence) alongside modern WAF solutions. You know how to inspect API traffic, evaluate specs, and secure application endpoints.
  • Developer Empathy & Advisory Skills: You don’t just throw vulnerability reports over the fence. You communicate clearly with development teams, providing practical, developer-friendly remediation steps that keep velocity high while protecting the bank.
  • Solid Network & Cloud Foundation: You understand enterprise network security architecture, hybrid cloud environments (Microsoft Azure, VMware), and industry frameworks like NIST, CIS Controls, and MITRE ATT&CK.
  • Curious Cyber Defender Mindset: You stay ahead of emerging tech trends-from AI integrations to new API protocols-and bring a continuous learning attitude, scripting capabilities (Python/PowerShell), and a knack for analytical problem-solving.

Benefits & conditions

We believe it is important to be a good employer. Joining us means stepping into a role with impact, supported by excellent employment conditions that foster your job satisfaction, development, and wellbeing.

In addition, we offer:

  • An attractive gross monthly salary based on a 36-hour work week, including holiday allowanceand a flexible benefit budget.
  • An excellent pension scheme, ensuring that you are well prepared for the future.
  • Flexibility in working: working from home is possible in consultation with your team and depending on your role. We will provide an ergonomic home office setup for you.
  • Plenty of room for relaxation with five weeks of vacation per year, supplemented by two mandatory days off. You can also purchase up to four additional weeks of vacation annually.
  • Five “Banking for better days”: extra days off that you can use for personal development or volunteer work.
  • Personal development is key: you receive a development budget of €1,000 per year, which can accumulate up to €3,000.
  • An annual public transport pass with free public transportation throughout the Netherlands for both business and private use.

About the company

You’ll join the CISO department, which connects client, bank, and societal interests through information security. With about 500 global staff, CISO ensures the bank’s security and pursues innovative solutions in a fast-changing, international environment. The office is in Amstelveen near Amsterdam, and English is the main language. Within CISO, the Cyber Defence department has around 150 employees across 7 sub-departments.

We offer you the opportunity to contribute to the future of the cyber security of ABN AMRO. While using your known skills, you will learn to use the newest tools and gain knowledge from your co-workers. Besides learning new hard skills, we will also focus on your personal (soft) skills that you would like to improve. We offer training opportunities, lots of growing opportunities and fun times with colleagues.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.werkenbijabnamro.nl
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:49 min

Adopting OAuth best practices and removing outdated grants

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

4:35 min

Setting up passwordless federated identity configuring OpenID Connect patterns

Marcel Lupo · LIVE

2:28 min

Understanding Kubernetes architecture and core cluster components

Marc Nimmerrichter · World Congress 2022

1:22 min

Addressing the shortage of application security specialists

Joseph Katsioloudes Joseph Katsioloudes · World Congress 2025

2:22 min

Adapting OpenID Connect for decentralized data sharing

Adam Larter Adam Larter · World Congress 2024

1:34 min

Analyzing vulnerabilities in standard OAuth 2.0 authorization flows

Alexander Schwartz Alexander Schwartz · World Congress 2026 Europe

Videos

See all

Related articles

See all