Application Security Engineer
About the assignment
You protect critical applications against evolving threats by integrating security seamlessly into the development cycle. Your role ensures code is secure, resilient, and compliant before deployment.
You work closely with development teams, architects, and security teams to identify vulnerabilities early, establish secure coding standards, and automate security controls. You balance speed with security, enabling teams to ship safely.
Your responsibilities
- Conduct code reviews and static analysis to identify security flaws before production
- Design and implement application security controls aligned with OWASP standards
- Perform threat modeling and design reviews on new applications and features
- Develop and maintain secure coding guidelines and training for development teams
- Automate security testing in CI/CD pipelines to shift security left
- Investigate and remediate reported vulnerabilities with development teams
- Evaluate third-party dependencies and manage open-source software risk
- Collaborate with architects to embed security requirements in application design
Tech Stack & Tools
Platforms & Tooling
Frameworks & Standards
Cloud & Infrastructure
Methodologies
Certifications (preferred)
Must-haves
- 5+ years application security or secure development experience
- Strong knowledge of secure coding practices and OWASP Top 10
- Hands-on experience with SAST and DAST tools
- Understanding of CI/CD pipelines and DevOps environments
- Experience integrating security into development workflows
Nice-to-haves
- Experience with threat modeling frameworks (STRIDE, Attack Trees)
- Knowledge of container security and Kubernetes hardening
- Certification in application security (OSCP, GWAPT, GSEC)
- Background in software development or secure code review
What we offer
- Work with cutting-edge development and security tools
- Influence secure architecture across critical applications
- Collaborate with talented developers and security professionals
- Continuous learning through threat landscape shifts
- Impact application security posture across the organisation
- Personal guidance from a dedicated MVPeople consultant who knows your niche
The process
Introduction
Phone call with your MVPeople consultant (within 24 hours)
Match & Brief
We discuss the assignment in detail and prepare you
Client meeting
Introduction to the client
Start
Contracting and onboarding
Details
Type
Permanent
Location
Amsterdam
Work model
Hybrid
Level
Medior
Industry
overige
Posted
24 March 2026
Contact
MVPeople Group
jobs@mvpeoplegroup.com