17 сен

application security engineer for travel experiences

ориентир по рынку
вакансия зп не указана
в среднем 351 041 ₽
Загрузи резюме, чтобы видеть мэтчи с вакансией

подготовьтесь к отклику

ai-инструменты

Чтобы адаптировать резюме под вакансию или составить сопроводительное письмо, загрузите резюме

описание

FareHarbor creates reservation software and operational tools for tours, activities, attractions, and other experience-based businesses. The company serves over 20,000 clients across more than 90 countries and operates as part of Booking Holdings.

задачи

  • Collaborate with product, platform, and security teams to integrate security into the SDLC;
  • Perform application security reviews, code reviews, threat modeling, and design reviews;
  • Promote application security practices across engineering teams;
  • Identify, assess, and help remediate vulnerabilities in applications, APIs, services, and GitLab CI/CD pipelines;
  • Implement and maintain security policies, SAST, DAST, SCA, container scanning, and other CI/CD security controls;
  • Support remediation of penetration test, bug bounty, vulnerability scan, and audit findings with technical input, documentation, and evidence;
  • Write and maintain code and automation for application security workflows, security tooling, vulnerability management, detection, and CI/CD security controls;
  • Guide engineering teams on secure coding, application architecture, authentication, authorization, API security, secrets management, and secure deployment patterns;
  • Support IAM and AWS WAF initiatives;
  • Fine-tune security monitoring and detection capabilities, including Elastic SIEM rules, WAF policies, alerting logic, logging improvements, and security automation;
  • Participate in security alert triage, investigations, and incident response activities;
  • Participate in the security on-call rotation.

требования

  • Strong experience in application security and secure SDLC;
  • Strong knowledge of web and API security, common vulnerabilities, and OWASP Top 10 mitigation strategies;
  • Experience with application security reviews, code reviews, design reviews, threat modeling, and remediation of findings from penetration tests, vulnerability scans, and security audits;
  • Experience implementing GitLab CI/CD security controls, including SAST, DAST, SCA, secret scanning, IaC scanning, and dependency scanning;
  • Strong hands-on programming experience in Python, Go, Java, or another high-level language;
  • Ability to independently write, review, debug, and maintain code;
  • Good understanding of AWS security concepts, IAM, WAF, Kubernetes, containers, and infrastructure as code;
  • Experience with security monitoring, alert tuning, SIEM use cases, logging, detection engineering, or WAF rule tuning;
  • Ability to assess risk, prioritize vulnerabilities, and balance security requirements with business needs and engineering realities;
  • Familiarity with NIST, PCI DSS, GDPR, SOC 2, SOX, or similar security and compliance frameworks;
  • Good understanding of incident response, security investigations, and technical incident management;
  • Experience with API security, microservices security, and distributed application architectures;
  • Experience with AI-assisted security automation for AppSec triage, vulnerability assessment, detection tuning, and security monitoring workflows;
  • Strong communication, problem-solving, decision-making, and relationship-building skills;
  • Ability to work effectively with product, engineering, platform, infrastructure, and security teams;
  • Ability to operate independently and take ownership of security initiatives from discovery through implementation;
  • Ability to provide practical security guidance that enables teams to move quickly and securely;
  • Nice to have: Pentesting experience, security certifications such as OSCP, OSWE, OSWA, GWAPT, GWEB, CISSP, CCSP, Security+, AWS Certified Security Specialty, experience with bug bounty programs and third-party vulnerability remediation, Terraform, infrastructure as code, configuration management, policy-as-code frameworks, internal security tooling, developer-facing security automation, security community contributions through research, blog posts, conference talks, open-source tools, or responsible disclosures.

условия

  • Candidates must be located in the Netherlands;
  • 22 Weeks of paid parental leave;
  • 2 Weeks of paid grandparent leave;
  • Extended care and bereavement leave;
  • Life insurance policy;
  • Pension plan;
  • Central Amsterdam location;
  • Discounted CZ insurance;
  • Commuting allowance for public transport and subsidized lunch;
  • Wellness benefits, including Headspace subscription and wellness webinars;
  • Work-from-home assistance;
  • Educational opportunities and individual skill development and growth programming;
  • Social hours, events, and team-building;
  • 26 Vacation days per year;
  • Pre-employment screening is required before any offer of work.

Если просят выйти из iCloud, прислать код из SMS, запустить или установить что-то, перевести деньги — не соглашайтесь: это мошенничество.

Про зарплаты

Анонимные данные по зарплатам и грейдам.
Можно сверить вилку с рынком.

Посмотреть зарплаты

Если просят выйти из iCloud, прислать код из SMS, запустить или установить что-то, перевести деньги — не соглашайтесь: это мошенничество.