Security Engineer II

Booking.com
Amsterdam, Netherlands
about 1 month ago
Apply on nl.indeed.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Working hours
Regular working hours
Job source

Tech stack

Application Programming Interfaces (APIs) Artificial Intelligence User Authentication Bash Shell Hypertext Transfer Protocols (HTTP) Python (Programming Language) Open Web Application Security Secure Coding Web Application Security Software Engineering Software Vulnerability Management Data Logging
+13 more
Scripting Retrieval-Augmented Generation Large Language Models Software Security Rate Limiting Information Technology Tenable Nessus Api Management Static Application Security Testing Vulnerability Analysis Programming Languages Microservices Dynamic Application Security Testing

Job description

  • Review applications, APIs, and designs to identify basic security risks.
  • Support secure code reviews and vulnerability assessments.
  • Help teams understand and remediate common web vulnerabilities.
  • Contribute to threat modelling and security requirements for new features.
  • Help integrate and maintain security checks in CI/CD pipelines, such as SAST, DAST, software composition analysis, and secrets scanning.
  • Support security reviews of AI- and LLM-enabled applications, where applicable.
  • Help identify basic AI-specific risks such as prompt injection, sensitive information disclosure, insecure output handling, excessive agency, model or data poisoning, and unbounded consumption.
  • Investigate security findings, assess their priority, and track remediation.
  • Support the configuration and use of application security tools.
  • Write simple scripts or automation to improve security processes.
  • Document findings, security requirements, procedures, and recommendations.
  • Work collaboratively with software engineers, platform teams, and security colleagues.
  • Keep up to date with common application security threats and defensive practices., * You identify and explain common application security risks.
  • Development teams receive practical remediation guidance.
  • Security checks are applied consistently during software development.
  • Findings are documented, prioritised, and followed through to resolution.
  • You build deeper application security expertise through hands-on work and continuous learning.

Requirements

  • Basic to intermediate knowledge of application and web security.
  • 3+ years of relevant industry experience
  • Familiarity with common risks such as injection, broken access control, authentication failures, security misconfiguration, cross-site scripting, and insecure dependencies.
  • Understanding of the OWASP Top 10 and basic secure coding principles.
  • Familiarity with HTTP, APIs, authentication, authorization, and TLS.
  • Ability to read and understand code in at least one programming language.
  • Basic scripting or automation skills in Python, Bash, or a similar language.
  • Some experience with application security tools, such as SAST, DAST, software composition analysis, vulnerability scanners, or secrets-scanning tools.
  • Basic understanding of how LLM applications work, including prompts, model inputs and outputs, retrieval-augmented generation, and tool or API integrations.
  • Basic understanding of how to secure LLM applications through input and output validation, data minimisation, access control, least privilege, rate limiting, logging, and human approval for high-impact actions.
  • Ability to communicate security findings clearly and constructively.
  • Analytical mindset, attention to detail, and willingness to learn.
  • Ability to work effectively with developers and other technical teams.
  • Bachelor’s or Master’s degree in Computer Science or a related field.

Nice to have

  • Experience with cloud platforms, containers, or infrastructure as code.
  • Familiarity with API security or microservices.
  • Experience or interest in securing AI or LLM-enabled applications.
  • Experience with threat modelling or security testing.
  • Familiarity with vulnerability management or incident response.
  • Knowledge of privacy or security requirements relevant to software development.
  • Security certifications or relevant practical projects.

Benefits & conditions

Booking.com’s Total Rewards Philosophy is not only about compensation but also about benefits. We offer a competitive compensation and benefits package, as well unique-to-Booking.com benefits which include:

  • Annual paid time off and generous paid leave scheme including: parent, grandparent, bereavement, and care leave
  • Hybrid working including flexible working arrangements, and up to 20 days per year working from abroad (home country)
  • Industry leading product discounts - up to 1400 per year - for yourself, including automatic Genius Level 3 status and Booking.com wallet credit
  • Living and working in Amsterdam, one of the most cosmopolitan cities in Europe
  • Contributing to a high scale, complex, world renowned product and seeing real-time impact of your work on millions of travelers worldwide
  • Working in a fast-paced and performance driven culture
  • Opportunity to utilize technical expertise, leadership capabilities and entrepreneurial spirit
  • Promote and drive impactful and innovative engineering solutions
  • Technical, behavioral and interpersonal competence advancement via on-the-job opportunities, experimental projects, hackathons, conferences and active community participation
  • Competitive compensation and benefits package and some great added perks of working in the home city of Booking.com

About the company

About Us: At Booking.com, data drives our decisions. Technology is at our core. And innovation is everywhere. But our company is more than datasets, lines of code or A/B tests. We’re the thrill of the first night in a new place. The excitement of the next morning. The friends you encounter. The journeys you take. The sights you see. And the memories you make. Through our products, partners and people, we make it easier for everyone to experience the world.

About the team: Booking.com’s Application Security team is responsible for protecting the world’s largest travel platform against attacks targeting our application stack. The team develops and maintains the signals, tools, and infrastructure used to secure Booking.com products and defines secure coding practices for all developers. We work closely with product and engineering teams to ensure customer data remains safe through secure-by-design software architecture., Diversity, Equity & Inclusion have been a core part of our company culture since day one. This ongoing journey starts with our very own employees, who represent over 140 nationalities and a wide range of ethnic and social backgrounds, genders and sexual orientations.

Take it from our Chief People Officer, Paulo Pisano: “At Booking.com, the diversity of our people doesn’t just build an outstanding workplace, it also creates a better and more inclusive travel experience for everyone. Inclusion is at the heart of everything we do. It’s a place where you can make your mark and have a real impact in travel and tech.”

We ensure that colleagues with disabilities are provided the adjustments and tools they need to participate in the job application and interview process, to perform crucial job functions, and to receive other benefits and privileges of employment.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on nl.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:04 min

Introduction to Bitcoin script parsing tools

Steve Shadders · LIVE

2:12 min

Integrating tool definitions for local bash shell execution

Michał Michalczuk Michał Michalczuk · Europe 2026 Virtual

1:10 min

Exposing sensitive information through partial search logs

Dennis Schulz Dennis Schulz +1 · World Congress 2026 Europe

26:47 min

Exploring pathways to application security careers and research workflows

Vandana Verma Sehgal · LIVE

1:53 min

Evaluating traditional scripting languages for modern development tasks

Jens Knipper Jens Knipper · Europe 2026 Virtual

2:47 min

Leveraging older LLMs defensively for vulnerability hunting

Adrian Mouat Adrian Mouat · World Congress 2026 Europe

Videos

See all

Related articles

See all