2 months ago
Amsterdam, NetherlandsMid Level / Senior
H1B Sponsor
Responsibilities
- Build guardrails, AI-accelerated patterns, security tooling, and automation that make secure-by-default development scalable.
- Respond to emerging security threats.
- Contribute to threat modeling, design reviews, code reviews, and security testing for new features and services.
- Triage, reproduce, and validate bug bounty submissions and internal security reports.
- Prioritize genuine vulnerabilities amid SAST, secrets, and scanner findings and guide developers toward effective fixes.
- Partner with development teams to drive remediation and track issues through closure.
- Write and maintain security patterns, runbooks, developer guidelines, and security documentation.
- Monitor web and cloud security trends and incorporate relevant findings into product discussions.
Requirements
- 2–5 years of experience in product/application security or security-focused software development.
- Strong knowledge of web application security principles and common attack vectors, including the OWASP Top 10.
- Proficiency with application testing tools such as Burp Suite, OWASP ZAP, or browser developer tools.
- Working knowledge of at least one of Ruby, Java, Kotlin, TypeScript, JavaScript, or Python.
- Working knowledge of at least one major cloud provider: AWS, GCP, or Azure.
- Hands-on experience with SAST tools such as Cycode, Semgrep, or Snyk.
- Experience improving developer experience through security practices without slowing engineering teams.
- Clear, constructive communication of technical risk in writing, code review, and conversation.
- Collaborative approach to partnering with developers, SREs, and security peers.
- Comfort with security on-call rotation and work across security disciplines.
- Preferred: experience with bug bounty platforms, cloud infrastructure security, container technologies, CTF events, open-source security projects, threat modeling frameworks, secure SDLC practices, or internal developer security training.
Benefits
- Amsterdam office attendance 3 days per week.
- Daily catered lunches, breakfast, snacks, and soft drinks at the office.
- Home-office commuting costs covered for employees living outside Amsterdam.
- 25 vacation days for full-time employees.
- Employer-paid collective health insurance, including the basic package and available additional packages.
- Defined pension contribution scheme.
- Equity program for team members.
- Employee Assistance Program through Aetna Resources for Living.
- Parental leave benefits for mothers and partners.
Categories
About Flexport
Our mission is to make global trade so easy that there will be more of it.