- Location
- Amsterdam
- Department
- Engineering
Description
About FareHarbor
At FareHarbor, our mission is to make experiences better for everyone. Founded in 2013 in Hawaii and acquired by Booking Holdings in 2018, FareHarbor creates powerful tools that enable our clients (think boat rentals, museums, food tours, events and more!) to operate and grow.
With over 20,000 clients across 90+ countries—we’re the largest in our industry and shaping the future of travel, together.
Our team is an ‘Ohana of 700+ people around the world. We’re passionate about pioneering an industry, embracing challenges with open arms, and delivering value to the experiences industry.
FareHarbor Core Values:
- Think Client First
- We Are One ‘Ohana
- Be Curious and Learn
- Own It.
- Act With Integrity
- Embrace the Challenge
Why FareHarbor?
Founding FareHarbor required unwavering passion. Turning a start-up into the world’s leading and largest reservation software for tours, activities, and attractions required relentless dedication and vision. To date, we’ve helped over 20,000 global businesses operate successfully and are proud to have played a role in enabling business owners to live their dreams.
And since day one, we’ve known that our real success lies in our people—the Ohana.
With each new feature launched and new client onboarded, there is a team of incredible people behind the scenes who are full of dedication, passion, energy, and the will to succeed. We encourage everyone to bring their whole selves to work—to believe in their abilities, to freely express their creativity, and to contribute with their own uniqueness by wearing their true colors. We take care of one another and always prioritize health and wellbeing. We give our people the space and trust to learn, to try, to succeed, to collaborate, to think outside of the box, to make mistakes, and even to fail. And then we come together to try again.
From the minute you join, you have a voice. You find your space. You make an impact. We celebrate our victories, shout our successes, and are always eager to tackle new challenges. And we can’t wait to see all that’s to come.
About the Role
FareHarbor is looking for a full time Application Security Engineer to join our Security Engineering team in Amsterdam. This role will primarily focus on application security and secure SDLC initiatives, while also supporting security monitoring efforts. We are looking for someone who can work closely with our Senior Application Security Engineer on application security reviews, secure development practices, CI/CD security controls, application vulnerability remediation, and broader security engineering initiatives. The ideal candidate is comfortable operating across multiple areas of security, with strong application security expertise and the ability to contribute to automation, detection engineering, and incident response.
What you will do:
- Work closely with product, platform, and security teams to ensure security is an integral part of our SDLC
- Perform application security reviews, code reviews, threat modeling, and design reviews for new and existing features, promote application security practices across engineering teams
- Identify, assess, and help remediate vulnerabilities in applications, APIs, services, and GitLab CI/CD pipelines by implementing and maintaining application security controls such as security policies, SAST, DAST, SCA, container scanning, and other CI/CD security controls
- Support assessment and remediation such as for penetration test findings, bug bounty findings, vulnerability scan results, internal or external audit by providing technical input, documentation, and evidence
- Work with engineering teams to provide guidance on secure coding practices, application architecture, authentication, authorization, API security, secrets management, and secure deployment patterns
- Support security initiatives, such as IAM, AWS WAF, Help fine-tune security monitoring and detection capabilities, including Elastic SIEM rules, WAF policies, alerting logic, logging improvements, and security automation
- Participate in security alert triage, investigation, and incident response activities when needed
- Participate in the security on-call rotation
Required Skills and Experience:
Technical skills:
- Senior engineer with strong experience in application security, secure SDLC, strong technical knowledge of web/API security, common vulnerabilities, and practical mitigation strategies for OWASP Top 10.
- Proven experience performing application security reviews, including code reviews, design reviews, and threat modeling, as well as supporting the remediation of security findings from penetration tests, vulnerability scans, and security audits.
- Experience implementing security controls in GitLab CI/CD pipeline, such as SAST, DAST, SCA, secret scanning, IaC scanning, dependency scanning etc.
- Proficiency in Python or other high-level language such as Go, Java, or similar
- Good understanding of AWS security concepts, including IAM, WAF, Kubernetes, containers, and infrastructure as code
- Experience with security monitoring, alert tuning, SIEM use cases, logging, detection engineering, or WAF rule tuning
- Pentesting experience is a plus
- Ability to assess risk, prioritize vulnerabilities, and balance security requirements with business needs and engineering realities
- Familiarity with security and compliance frameworks such as NIST, PCI DSS, GDPR, SOC 2, SOX, or similar
- Good understanding of incident response, security investigations, and technical incident management
- Experience with API security, microservices security, and distributed application architectures
- Experience with AI-assisted security automation for AppSec triage, vulnerability assessment, detection tuning, and security monitoring workflows using tools such as Cursor, Tines, Elastic, or similar.
Soft skills:
- Strong communication skills, able to explain technical security risks clearly to both technical and non-technical stakeholders
- Able to work effectively with product, engineering, platform, infrastructure, and security teams
- Proactive attitude, always on the look-out for improving your and our way of working
- Strong problem-solving skills and ability to analyze complex systems and make decisions based on risk, data, and best practices
- Strong relationship building skills across diverse cross-functional teams
- Comfortable operating independently and taking ownership of security initiatives from discovery through implementation
- Able to provide practical security guidance that enables teams to move quickly and securely
Nice to Haves:
- Security certifications such as OSCP, OSWE, OSWA, GWAPT, GWEB, CISSP, CCSP, Security+, AWS Certified Security Specialty, or similar
- Experience with bug bounty programs and coordinating vulnerability remediation with third party
- Experience with Terraform, infrastructure as code, configuration management, and policy-as-code frameworks
- Experience building internal security tooling or developer-facing security automation
- Contributions to the security community through research, blog posts, conference talks, open-source tools, or responsible disclosures
This role is available to candidates located in the Netherlands and requires ability to work in a hybrid setup with in-office presence..
Benefits
- Global leave benefit
- 22 weeks paid parental leave
- 2 weeks paid grandparent leave
- Extended care and bereavement leave
- Life insurance policy
- Pension Plan
- Central Amsterdam Location
- Discount CZ insurance
- Working in a multicultural environment - 45 different nationalities
- Commuting allowance for public transport & subsidized lunch
- Wellness benefits (Headspace subscription & wellness webinars)
- Hybrid friendly
- Work-from-home assistance
- Educational Opportunities
- Individual skill development & growth programming
- Social hours & events and team-building
- 26 vacation days per year
FareHarbor is committed to creating a diverse environment, and we are an equal opportunity employer. We do not discriminate on the basis of race, color, religion, gender, gender identity, sexual orientation, national origin, disability, age, or veteran status. We welcome talent that can offer us new insights and perspectives on challenges that we face, and we take measures to eliminate unconscious bias throughout the interview and hiring process. In tandem, we work to cultivate an inclusive culture in which all of our employees can be their authentic selves.
To learn more about how we use your information, see our Privacy Statement for Applicants. By submitting your application, you confirm that you understand and agree that your information will be processed in accordance with our Privacy Statement for Applicants.
Any offer of work (e.g. employment, assignment) will be subjected to the successful completion of pre-employment screening.