Jobs / engineering
Application Security Engineer
FareHarbor · Amsterdam
What you will do
FareHarbor is looking for a full time Application Security Engineer to join our Security Engineering team in Amsterdam. This role will primarily focus on application security and secure SDLC initiatives, while also supporting security monitoring efforts. We are looking for someone who can work closely with our Senior Application Security Engineer on application security reviews, secure development practices, CI/CD security controls, application vulnerability remediation, and broader security engineering initiatives. The ideal candidate is comfortable operating across multiple areas of security, with strong application security expertise and the ability to contribute to automation, detection engineering, and incident response.
What you will do
- Work closely with product, platform, and security teams to ensure security is an integral part of our SDLC
- Perform application security reviews, code reviews, threat modeling, and design reviews for new and existing features, promote application security practices across engineering teams
- Identify, assess, and help remediate vulnerabilities in applications, APIs, services, and GitLab CI/CD pipelines by implementing and maintaining application security controls such as security policies, SAST, DAST, SCA, container scanning, and other CI/CD security controls
- Support assessment and remediation such as for penetration test findings, bug bounty findings, vulnerability scan results, internal or external audit by providing technical input, documentation, and evidence
- Write and maintain code and automation to support application security workflows, security tooling, vulnerability management, detection, and CI/CD security controls.
- Work with engineering teams to provide guidance on secure coding practices, application architecture, authentication, authorization, API security, secrets management, and secure deployment patterns
- Support security initiatives, such as IAM, AWS WAF, Help fine-tune security monitoring and detection capabilities, including Elastic SIEM rules, WAF policies, alerting logic, logging improvements, and security automation
- Participate in security alert triage, investigation, and incident response activities when needed
- Participate in the security on-call rotation