Skip to content

Security Engineer

Booking.com
mid-level
Location

Amsterdam, Netherlands

Work Type

Onsite

Seniority

mid-level

Posted

September 6, 2026


Total Compensation
€130,000
Yearly Savings (Comfortable)
€52,000
Want to apply for this job?

Subscribe to access the application link and 15,000+ more jobs

Job Description

  • As an Application Security Engineer, you will play a key role in safeguarding the security and privacy of Booking.com customers.
  • You will build and operate advanced security tooling, automate remediation, analyze security indicators, and partner with product teams to embed security throughout the software development lifecycle
  • Your expertise will directly contribute to the detection, prevention, and response to application security threats across Booking.com’s global platform
  • Review applications, APIs, and designs to identify basic security risks
  • Support secure code reviews and vulnerability assessments
  • Help teams understand and remediate common web vulnerabilities
  • Contribute to threat modelling and security requirements for new features
  • Help integrate and maintain security checks in CI/CD pipelines, such as SAST, DAST, software composition analysis, and secrets scanning
  • Support security reviews of AI- and LLM-enabled applications, where applicable
  • Help identify basic AI-specific risks such as prompt injection, sensitive information disclosure, insecure output handling, excessive agency, model or data poisoning, and unbounded consumption
  • Investigate security findings, assess their priority, and track remediation
  • Support the configuration and use of application security tools
  • Write simple scripts or automation to improve security processes
  • Document findings, security requirements, procedures, and recommendations
  • Work collaboratively with software engineers, platform teams, and security colleagues
  • Keep up to date with common application security threats and defensive practices
  • What success looks like;
  • You identify and explain common application security risks
  • Development teams receive practical remediation guidance
  • Security checks are applied consistently during software development
  • Findings are documented, prioritised, and followed through to resolution
  • You build deeper application security expertise through hands-on work and continuous learning

Benefits

  • Health insurance
  • Free access to Headspace for you and your loved ones
  • Global Employee Assistance Program
  • Meditation and Breastfeeding rooms at the office
  • Booking Cares - 2 days per year to volunteer and learn
  • Life insurance
  • Disability insurance
  • Pension plan
  • Annual paid time off
  • Parental leave - 22 weeks
  • Grandparent leave - 10 days
  • Care leave - 10 days
  • Bereavement leave - up to 4 weeks
  • Anniversary leave
  • Working from Home Furniture and Ergonomic Support
  • Working from Abroad - up to 20 days per year
  • Discounts & Wallet credits to spend on our products
  • Upgrade to Booking.com Genius Level 3
  • Friends & Family Booking.com discount vouchers
  • Free access to online learning platforms
  • Development and mentorship programs to support career growth
  • Access to trainings and workshops
  • Team development opportunities
  • Local discount programs
  • Game rooms in offices
  • On-site meals, coffee and snacks including vegan options- Some experience with application security tools, such as SAST, DAST, software composition analysis, vulnerability scanners, or secrets-scanning tools
  • Bachelor’s or Master’s degree in Computer Science or a related field
  • 3+ years of relevant industry experience
  • Familiarity with common risks such as injection, broken access control, authentication failures, security misconfiguration, cross-site scripting, and insecure dependencies
  • Ability to work effectively with developers and other technical teams
  • Ability to communicate security findings clearly and constructively
  • Basic to intermediate knowledge of application and web security
  • Familiarity with HTTP, APIs, authentication, authorization, and TLS
  • Analytical mindset, attention to detail, and willingness to learn
  • Basic scripting or automation skills in Python, Bash, or a similar language
  • Basic understanding of how LLM applications work, including prompts, model inputs and outputs, retrieval-augmented generation, and tool or API integrations
  • Understanding of the OWASP Top 10 and basic secure coding principles
  • Ability to read and understand code in at least one programming language
  • Basic understanding of how to secure LLM applications through input and output validation, data minimisation, access control, least privilege, rate limiting, logging, and human approval for high-impact actions
  • Experience with cloud platforms, containers, or infrastructure as code
  • Familiarity with API security or microservices
  • Experience with threat modelling or security testing
  • Experience or interest in securing AI or LLM-enabled applications
  • Familiarity with vulnerability management or incident response
  • Knowledge of privacy or security requirements relevant to software development
  • Security certifications or relevant practical projects
More Jobs You Might Like
Named Account Executive (Media AE 2)

Salesforce

London

Helpful Resources
Salary & Savings Calculator

Compare salaries across European cities and calculate your potential savings. Understand cost of living and take-home pay for tech jobs in Europe.

Career Guides

Expert advice on landing high-paying tech jobs in Europe. Tips on interviews, salary negotiation, and career growth from The European Engineer.

Access 15,000+ High-Paying Tech Jobs

Get unlimited access to our full database of 15,000+ jobs with advanced filters, salary comparisons, and exclusive career guides from The European Engineer.