Application Security Engineer
Role details
Job location
Tech stack
Job description
FareHarbor is looking for a full time Application Security Engineer to join our Security Engineering team in Amsterdam. This role will primarily focus on application security and secure SDLC initiatives, while also supporting security monitoring efforts. We are looking for someone who can work closely with our Senior Application Security Engineer on application security reviews, secure development practices, CI/CD security controls, application vulnerability remediation, and broader security engineering initiatives. The ideal candidate is comfortable operating across multiple areas of security, with strong application security expertise and the ability to contribute to automation, detection engineering, and incident response., * Work closely with product, platform, and security teams to ensure security is an integral part of our SDLC
- Perform application security reviews, code reviews, threat modeling, and design reviews for new and existing features, promote application security practices across engineering teams
- Identify, assess, and help remediate vulnerabilities in applications, APIs, services, and GitLab CI/CD pipelines by implementing and maintaining application security controls such as security policies, SAST, DAST, SCA, container scanning, and other CI/CD security controls
- Support assessment and remediation such as for penetration test findings, bug bounty findings, vulnerability scan results, internal or external audit by providing technical input, documentation, and evidence
- Work with engineering teams to provide guidance on secure coding practices, application architecture, authentication, authorization, API security, secrets management, and secure deployment patterns
- Support security initiatives, such as IAM, AWS WAF, Help fine-tune security monitoring and detection capabilities, including Elastic SIEM rules, WAF policies, alerting logic, logging improvements, and security automation
- Participate in security alert triage, investigation, and incident response activities when needed
- Participate in the security on-call rotation
Requirements
- Senior engineer with strong experience in application security, secure SDLC, strong technical knowledge of web/API security, common vulnerabilities, and practical mitigation strategies for OWASP Top 10.
- Proven experience performing application security reviews, including code reviews, design reviews, and threat modeling, as well as supporting the remediation of security findings from penetration tests, vulnerability scans, and security audits.
- Experience implementing security controls in GitLab CI/CD pipeline, such as SAST, DAST, SCA, secret scanning, IaC scanning, dependency scanning etc.
- Proficiency in Python or other high-level language such as Go, Java, or similar
- Good understanding of AWS security concepts, including IAM, WAF, Kubernetes, containers, and infrastructure as code
- Experience with security monitoring, alert tuning, SIEM use cases, logging, detection engineering, or WAF rule tuning
- Pentesting experience is a plus
- Ability to assess risk, prioritize vulnerabilities, and balance security requirements with business needs and engineering realities
- Familiarity with security and compliance frameworks such as NIST, PCI DSS, GDPR, SOC 2, SOX, or similar
- Good understanding of incident response, security investigations, and technical incident management
- Experience with API security, microservices security, and distributed application architectures
- Experience with AI-assisted security automation for AppSec triage, vulnerability assessment, detection tuning, and security monitoring workflows using tools such as Cursor, Tines, Elastic, or similar., * Strong communication skills, able to explain technical security risks clearly to both technical and non-technical stakeholders
- Able to work effectively with product, engineering, platform, infrastructure, and security teams
- Proactive attitude, always on the look-out for improving your and our way of working
- Strong problem-solving skills and ability to analyze complex systems and make decisions based on risk, data, and best practices
- Strong relationship building skills across diverse cross-functional teams
- Comfortable operating independently and taking ownership of security initiatives from discovery through implementation
- Able to provide practical security guidance that enables teams to move quickly and securely, * Security certifications such as OSCP, OSWE, OSWA, GWAPT, GWEB, CISSP, CCSP, Security+, AWS Certified Security Specialty, or similar
- Experience with bug bounty programs and coordinating vulnerability remediation with third party
- Experience with Terraform, infrastructure as code, configuration management, and policy-as-code frameworks
- Experience building internal security tooling or developer-facing security automation
- Contributions to the security community through research, blog posts, conference talks, open-source tools, or responsible disclosures
This role is available to candidates located in the Netherlands and requires ability to work in a hybrid setup with in-office presence..
Benefits & conditions
- Global leave benefit
- 22 weeks paid parental leave
- 2 weeks paid grandparent leave
- Extended care and bereavement leave
- Life insurance policy
- Pension Plan
- Central Amsterdam Location
- Discount CZ insurance
- Working in a multicultural environment - 45 different nationalities
- Commuting allowance for public transport & subsidized lunch
- Wellness benefits (Headspace subscription & wellness webinars)
- Hybrid friendly
- Work-from-home assistance
- Educational Opportunities
- Individual skill development & growth programming
- Social hours & events and team-building
- 26 vacation days per year