> Markdown version of [/jobs/ext/3189374-security-engineer-ii](https://www.wearedevelopers.com/jobs/ext/3189374-security-engineer-ii). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer II - **Company:** Booking.com - **Location:** Amsterdam, Netherlands - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Artificial Intelligence, User Authentication, Bash Shell, Hypertext Transfer Protocols (HTTP), Python (Programming Language), Open Web Application Security, Secure Coding, Web Application Security, Software Engineering, Software Vulnerability Management, Data Logging, Scripting, Retrieval-Augmented Generation, Large Language Models, Software Security, Rate Limiting, Information Technology, Tenable Nessus, Api Management, Static Application Security Testing, Vulnerability Analysis, Programming Languages, Microservices, Dynamic Application Security Testing - **Published:** September 2, 2026 - **Apply:** https://nl.indeed.com/viewjob?jk=ddd848861c1a4031 ## About the Role * Basic to intermediate knowledge of application and web security. * 3+ years of relevant industry experience * Familiarity with common risks such as injection, broken access control, authentication failures, security misconfiguration, cross-site scripting, and insecure dependencies. * Understanding of the OWASP Top 10 and basic secure coding principles. * Familiarity with HTTP, APIs, authentication, authorization, and TLS. * Ability to read and understand code in at least one programming language. * Basic scripting or automation skills in Python, Bash, or a similar language. * Some experience with application security tools, such as SAST, DAST, software composition analysis, vulnerability scanners, or secrets-scanning tools. * Basic understanding of how LLM applications work, including prompts, model inputs and outputs, retrieval-augmented generation, and tool or API integrations. * Basic understanding of how to secure LLM applications through input and output validation, data minimisation, access control, least privilege, rate limiting, logging, and human approval for high-impact actions. * Ability to communicate security findings clearly and constructively. * Analytical mindset, attention to detail, and willingness to learn. * Ability to work effectively with developers and other technical teams. * Bachelor's or Master's degree in Computer Science or a related field. Nice to have * Experience with cloud platforms, containers, or infrastructure as code. * Familiarity with API security or microservices. * Experience or interest in securing AI or LLM-enabled applications. * Experience with threat modelling or security testing. * Familiarity with vulnerability management or incident response. * Knowledge of privacy or security requirements relevant to software development. * Security certifications or relevant practical projects. ## Description * Review applications, APIs, and designs to identify basic security risks. * Support secure code reviews and vulnerability assessments. * Help teams understand and remediate common web vulnerabilities. * Contribute to threat modelling and security requirements for new features. * Help integrate and maintain security checks in CI/CD pipelines, such as SAST, DAST, software composition analysis, and secrets scanning. * Support security reviews of AI- and LLM-enabled applications, where applicable. * Help identify basic AI-specific risks such as prompt injection, sensitive information disclosure, insecure output handling, excessive agency, model or data poisoning, and unbounded consumption. * Investigate security findings, assess their priority, and track remediation. * Support the configuration and use of application security tools. * Write simple scripts or automation to improve security processes. * Document findings, security requirements, procedures, and recommendations. * Work collaboratively with software engineers, platform teams, and security colleagues. * Keep up to date with common application security threats and defensive practices., * You identify and explain common application security risks. * Development teams receive practical remediation guidance. * Security checks are applied consistently during software development. * Findings are documented, prioritised, and followed through to resolution. * You build deeper application security expertise through hands-on work and continuous learning. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Crypto-secure Data Management with In-Database Blockchain](https://www.wearedevelopers.com/videos/632-crypto-secure-data-management-with-in-database-blockchain) - [Old tools, new tricks](https://www.wearedevelopers.com/videos/1916-old-tools-new-tricks) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [Can Machines Dream of Secure Code? Emerging AI Security Risks in LLM-driven Developer Tools](https://www.wearedevelopers.com/videos/1217-can-machines-dream-of-secure-code-emerging-ai-security-risks-in-llm-driven-developer-tools) - [Build Delightful Mobile Experiences with Kotlin, Realm, and Atlas Device Sync](https://www.wearedevelopers.com/videos/694-build-delightful-mobile-experiences-with-kotlin-realm-and-atlas-device-sync) ## Related Articles - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)