
Security Engineer II
Booking.com
Security Engineer II
Booking.com's Application Security team is seeking a Security Engineer II to protect the world's largest travel platform. The role involves building and operating security tooling, automating remediation, and partnering with product teams to embed security throughout the software development lifecycle. Requires 3+ years of relevant experience and knowledge of application security.
Security Engineer II
Booking.com's Application Security team is seeking a Security Engineer II to protect the world's largest travel platform. The role involves building and operating security tooling, automating remediation, and partnering with product teams to embed security throughout the software development lifecycle. Requires 3+ years of relevant experience and knowledge of application security.
Salary
Core Qualifications
Technical (Must-have)
Soft Skills
Preferred Qualifications
Technical (Nice-to-have)
Key Responsibilities
- Review applications, APIs, and designs to identify basic security risks.
- Support secure code reviews and vulnerability assessments.
- Help teams understand and remediate common web vulnerabilities.
- Contribute to threat modelling and security requirements for new features.
- Help integrate and maintain security checks in CI/CD pipelines, such as SAST, DAST, software composition analysis, and secrets scanning.
- Support security reviews of AI- and LLM-enabled applications, where applicable.
- Help identify basic AI-specific risks such as prompt injection, sensitive information disclosure, insecure output handling, excessive agency, model or data poisoning, and unbounded consumption.
- Investigate security findings, assess their priority, and track remediation.
- Support the configuration and use of application security tools.
- Write simple scripts or automation to improve security processes.
- Document findings, security requirements, procedures, and recommendations.
- Work collaboratively with software engineers, platform teams, and security colleagues.
- Keep up to date with common application security threats and defensive practices.