Application Security Engineer
Fareharbor — Netherlands · Posted ~1 day ago
🔓 Log in to save this job, tailor your resume & track your apply process — 7 days free, no card needed.
Log in to add to target listDescription
About FareHarbor
At FareHarbor, our mission is to make experiences better for everyone.
Founded in 2013 in Hawaii and acquired by Booking Holdings in 2018, FareHarbor creates powerful tools that enable our clients (think boat rentals, museums, food tours, events and more!) to operate and grow.
With over 20,000 clients across 90+ countries—we’re the largest in our industry and shaping the future of travel, together.
Our team is an ‘Ohana of 700+ people around the world.
We’re passionate about pioneering an industry, embracing challenges with open arms, and delivering value to the experiences industry.
FareHarbor Core Values
Think Client FirstWe Are One ‘OhanaBe Curious and LearnOwn It.Act With IntegrityEmbrace the Challenge
Why FareHarbor?
Founding FareHarbor required unwavering passion.
Turning a start-up into the world’s leading and largest reservation software for tours, activities, and attractions required relentless dedication and vision.
To date, we’ve helped over 20,000 global businesses operate successfully and are proud to have played a role in enabling business owners to live their dreams.
And since day one, we’ve known that our real success lies in our people—the Ohana.
With each new feature launched and new client onboarded, there is a team of incredible people behind the scenes who are full of dedication, passion, energy, and the will to succeed.
We encourage everyone to bring their whole selves to work—to believe in their abilities, to freely express their creativity, and to contribute with their own uniqueness by wearing their true colors.
We take care of one another and always prioritize health and wellbeing.
We give our people the space and trust to learn, to try, to succeed, to collaborate, to think outside of the box, to make mistakes, and even to fail.
And then we come together to try again.
From the minute you join, you have a voice.
You find your space.
You make an impact.
We celebrate our victories, shout our successes, and are always eager to tackle new challenges.
And we can’t wait to see all that’s to come.
About The Role
FareHarbor is looking for a full time Application Security Engineer to join our Security Engineering team in Amsterdam.
This role will primarily focus on application security and secure SDLC initiatives, while also supporting security monitoring efforts.
We are looking for someone who can work closely with our Senior Application Security Engineer on application security reviews, secure development practices, CI/CD security controls, application vulnerability remediation, and broader security engineering initiatives.
The ideal candidate is comfortable operating across multiple areas of security, with strong application security expertise and the ability to contribute to automation, detection engineering, and incident response.
What You Will Do
Work closely with product, platform, and security teams to ensure security is an integral part of our SDLCPerform application security reviews, code reviews, threat modeling, and design reviews for new and existing features, promote application security practices across engineering teamsIdentify, assess, and help remediate vulnerabilities in applications, APIs, services, and GitLab CI/CD pipelines by implementing and maintaining application security controls such as security policies, SAST, DAST, SCA, container scanning, and other CI/CD security controlsSupport assessment and remediation such as for penetration test findings, bug bounty findings, vulnerability scan results, internal or external audit by providing technical input, documentation, and evidenceWork with engineering teams to provide guidance on secure coding practices, application architecture, authentication, authorization, API security, secrets management, and secure deployment patternsSupport security initiatives, such as IAM, AWS WAF, Help fine-tune security monitoring and detection capabilities, including Elastic SIEM rules, WAF policies, alerting logic, logging improvements, and security automationParticipate in security alert triage, investigation, and incident response activities when neededParticipate in the security on-call rotation
Technical Skills
Required Skills and Experience:
Senior engineer with strong experience in application security, secure SDLC, strong technical knowledge of web/API security, common vulnerabilities, and practical mitigation strategies for OWASP Top 10.Proven experience performing application security reviews, including code reviews, design reviews, and threat modeling, as well as supporting the remediation of security findings from penetration tests, vulnerability scans, and security audits.Experience implementing security controls in GitLab CI/CD pipeline, such as SAST, DAST, SCA, secret scanning, IaC scanning, dependency scanning etc.Proficiency in Python or other high-level language such as Go, Java, or similarGood understanding of AWS security concepts, including IAM, WAF, Kubernetes, containers, and infrastructure as codeExperience with security monitoring, alert tuning, SIEM use cases, logging, detection engineering, or WAF rule tuningPentesting experience is a plusAbility to assess risk, prioritize vulnerabilities, and balance security requirements with business needs and engineering realitiesFamiliarity with security and compliance frameworks such as NIST, PCI DSS, GDPR, SOC 2, SOX, or similarGood understanding of incident response, security investigations, and technical incident managementExperience with API security, microservices security, and distributed application architecturesExperience with AI-assisted security automation for AppSec triage, vulnerability assessment, detection tuning, and security monitoring workflows using tools such as Cursor, Tines, Elastic, or similar.
Soft Skills
Strong communication skills, able to explain technical security risks clearly to both technical and non-technical stakeholdersAble to work effectively with product, engineering, platform, infrastructure, and security teamsProactive attitude, always on the look-out for improving your and our way of workingStrong problem-solving skills and ability to analyze complex systems and make decisions based on risk, data, and best practicesStrong relationship building skills across diverse cross-functional teamsComfortable operating independently and taking ownership of security initiatives from discovery through implementationAble to provide practical security guidance that enables teams to move quickly and securely
Nice To Haves
Security certifications such as OSCP, OSWE, OSWA, GWAPT, GWEB, CISSP, CCSP, Security+, AWS Certified Security Specialty, or similarExperience with bug bounty programs and coordinating vulnerability remediation with third partyExperience with Terraform, infrastructure as code, configuration management, and policy-as-code frameworksExperience building internal security tooling or developer-facing security automationContributions to the security community through research, blog posts, conference talks, open-source tools, or responsible disclosures
This role is available to candidates located in the Netherlands and requires ability to work in a hybrid setup with in-office presence..
Benefits
Global leave benefit22 weeks paid parental leave 2 weeks paid grandparent leave Extended care and bereavement leaveLife insurance policy Pension PlanCentral Amsterdam LocationDiscount CZ insuranceWorking in a multicultural environment - 45 different nationalities Commuting allowance for public transport & subsidized lunchWellness benefits (Headspace subscription & wellness webinars) Hybrid friendlyWork-from-home assistanceEducational OpportunitiesIndividual skill development & growth programmingSocial hours & events and team-building 26 vacation days per year
FareHarbor is committed to creating a diverse environment, and we are an equal opportunity employer.
We do not discriminate on the basis of race, color, religion, gender, gender identity, sexual orientation, national origin, disability, age, or veteran status.
We welcome talent that can offer us new insights and perspectives on challenges that we face, and we take measures to eliminate unconscious bias throughout the interview and hiring process.
In tandem, we work to cultivate an inclusive culture in which all of our employees can be their authentic selves.
To learn more about how we use your information, see our Privacy Statement for Applicants.
By submitting your application, you confirm that you understand and agree that your information will be processed in accordance with our Privacy Statement for Applicants.
Any offer of work (e.g.
employment, assignment) will be subjected to the successful completion of pre-employment screening.
We have 61,487 jobs that might be an even better fit for you
DontApply's real value goes far beyond a single job link or company name. Just upload your resume — in under a minute we'll analyze all 61,487 jobs and tell you exactly which ones you should apply to right now.
Upload My Resume