Если вы раньше входили через Google, сбросьте пароль для своей Gmail-почты через кнопку «Забыли пароль?» на экране входа. Затем войдите по email и новому паролю.
Если аккаунта ещё нет, зарегистрируйтесь с Gmail-почтой, после подтверждения почты мы предложим задать пароль.
Что нового
Загружаю обновления...
Что нового
Загружаю обновления...
Работа найдется быстрее с подпискойКандидат найдётся быстрее с подпиской
application security engineer for travel experiences
ориентир по рынку
вакансия
зп не указана
в среднем
351 041 ₽
мэтч
Загрузи резюме, чтобы видеть мэтчи с вакансией
подготовьтесь к отклику
ai-инструменты
Чтобы адаптировать резюме под вакансию или составить сопроводительное письмо, загрузите резюме
описание
FareHarbor creates reservation software and operational tools for tours, activities, attractions, and other experience-based businesses. The company serves over 20,000 clients across more than 90 countries and operates as part of Booking Holdings.
задачи
Collaborate with product, platform, and security teams to integrate security into the SDLC;
Promote application security practices across engineering teams;
Identify, assess, and help remediate vulnerabilities in applications, APIs, services, and GitLab CI/CD pipelines;
Implement and maintain security policies, SAST, DAST, SCA, container scanning, and other CI/CD security controls;
Support remediation of penetration test, bug bounty, vulnerability scan, and audit findings with technical input, documentation, and evidence;
Write and maintain code and automation for application security workflows, security tooling, vulnerability management, detection, and CI/CD security controls;
Guide engineering teams on secure coding, application architecture, authentication, authorization, API security, secrets management, and secure deployment patterns;
Support IAM and AWS WAF initiatives;
Fine-tune security monitoring and detection capabilities, including Elastic SIEM rules, WAF policies, alerting logic, logging improvements, and security automation;
Participate in security alert triage, investigations, and incident response activities;
Participate in the security on-call rotation.
требования
Strong experience in application security and secure SDLC;
Strong knowledge of web and API security, common vulnerabilities, and OWASP Top 10 mitigation strategies;
Experience with application security reviews, code reviews, design reviews, threat modeling, and remediation of findings from penetration tests, vulnerability scans, and security audits;
Experience implementing GitLab CI/CD security controls, including SAST, DAST, SCA, secret scanning, IaC scanning, and dependency scanning;
Strong hands-on programming experience in Python, Go, Java, or another high-level language;
Ability to independently write, review, debug, and maintain code;
Good understanding of AWS security concepts, IAM, WAF, Kubernetes, containers, and infrastructure as code;
Experience with security monitoring, alert tuning, SIEM use cases, logging, detection engineering, or WAF rule tuning;
Ability to assess risk, prioritize vulnerabilities, and balance security requirements with business needs and engineering realities;
Familiarity with NIST, PCI DSS, GDPR, SOC 2, SOX, or similar security and compliance frameworks;
Good understanding of incident response, security investigations, and technical incident management;
Experience with API security, microservices security, and distributed application architectures;
Experience with AI-assisted security automation for AppSec triage, vulnerability assessment, detection tuning, and security monitoring workflows;
Strong communication, problem-solving, decision-making, and relationship-building skills;
Ability to work effectively with product, engineering, platform, infrastructure, and security teams;
Ability to operate independently and take ownership of security initiatives from discovery through implementation;
Ability to provide practical security guidance that enables teams to move quickly and securely;
Nice to have: Pentesting experience, security certifications such as OSCP, OSWE, OSWA, GWAPT, GWEB, CISSP, CCSP, Security+, AWS Certified Security Specialty, experience with bug bounty programs and third-party vulnerability remediation, Terraform, infrastructure as code, configuration management, policy-as-code frameworks, internal security tooling, developer-facing security automation, security community contributions through research, blog posts, conference talks, open-source tools, or responsible disclosures.
условия
Candidates must be located in the Netherlands;
22 Weeks of paid parental leave;
2 Weeks of paid grandparent leave;
Extended care and bereavement leave;
Life insurance policy;
Pension plan;
Central Amsterdam location;
Discounted CZ insurance;
Commuting allowance for public transport and subsidized lunch;
Wellness benefits, including Headspace subscription and wellness webinars;
Work-from-home assistance;
Educational opportunities and individual skill development and growth programming;
Social hours, events, and team-building;
26 Vacation days per year;
Pre-employment screening is required before any offer of work.