Skip to content
MVPeople Group Logo
MVPeopleGroup
Application Security

Application Security Engineer

AmsterdamPermanentHybridMedioroverige

About the assignment

You protect critical applications against evolving threats by integrating security seamlessly into the development cycle. Your role ensures code is secure, resilient, and compliant before deployment.

You work closely with development teams, architects, and security teams to identify vulnerabilities early, establish secure coding standards, and automate security controls. You balance speed with security, enabling teams to ship safely.

Your responsibilities

  • Conduct code reviews and static analysis to identify security flaws before production
  • Design and implement application security controls aligned with OWASP standards
  • Perform threat modeling and design reviews on new applications and features
  • Develop and maintain secure coding guidelines and training for development teams
  • Automate security testing in CI/CD pipelines to shift security left
  • Investigate and remediate reported vulnerabilities with development teams
  • Evaluate third-party dependencies and manage open-source software risk
  • Collaborate with architects to embed security requirements in application design

Tech Stack & Tools

Platforms & Tooling

Burp SuiteSonarQubeOWASP ZAPSnykCheckmarxVeracode

Frameworks & Standards

OWASP Top 10OWASP ASVSOWASP SAMMCWESANS Top 25

Cloud & Infrastructure

DockerKubernetesAWS CodePipelineAzure DevOpsGitLab CI/CD

Methodologies

Secure SDLCThreat modelingCode reviewStatic application security testing (SAST)Dynamic application security testing (DAST)Shift-left security

Certifications (preferred)

OSCPGWAPTGSECCEHCCSK

Must-haves

  • 5+ years application security or secure development experience
  • Strong knowledge of secure coding practices and OWASP Top 10
  • Hands-on experience with SAST and DAST tools
  • Understanding of CI/CD pipelines and DevOps environments
  • Experience integrating security into development workflows

Nice-to-haves

  • Experience with threat modeling frameworks (STRIDE, Attack Trees)
  • Knowledge of container security and Kubernetes hardening
  • Certification in application security (OSCP, GWAPT, GSEC)
  • Background in software development or secure code review

What we offer

  • Work with cutting-edge development and security tools
  • Influence secure architecture across critical applications
  • Collaborate with talented developers and security professionals
  • Continuous learning through threat landscape shifts
  • Impact application security posture across the organisation
  • Personal guidance from a dedicated MVPeople consultant who knows your niche

The process

1

Introduction

Phone call with your MVPeople consultant (within 24 hours)

2

Match & Brief

We discuss the assignment in detail and prepare you

3

Client meeting

Introduction to the client

4

Start

Contracting and onboarding

Details

Type

Permanent

Location

Amsterdam

Work model

Hybrid

Level

Medior

Industry

overige

Posted

24 March 2026


Contact

Apply nowMore information
Apply now