Lead Application Security Engineer – Amsterdam (REMOTE)
(Individual Contributor | Own the AppSec Function)
I’m partnering with a rapidly scaling organisation in the digital assets / financial services space that is running a talent-led search for a Lead Application Security Engineer in Amsterdam.
This is a pure lead individual contributor role – no people management – where you will own the entire Application Security function end-to-end. My client is not hiring to a rigid job spec; they are looking for the best AppSec engineer in the market and are highly flexible on salary for a standout profile, with the ability to exceed current compensation to secure the right person.
You will act as the technical authority for application security, defining how AppSec is done across the organisation and embedding security deeply into engineering and product teams that build mission-critical trading and customer-facing platforms.
What you’ll own
- Be the sole owner and technical lead for Application Security across the company
- Perform deep-dive code reviews to uncover complex vulnerabilities (logic flaws, auth bypasses, race conditions, etc.)
- Partner with engineering and product to design secure architectures from day one
- Build, tune and run SAST, DAST and SCA pipelines across the SDLC
- Own and run the bug bounty programme, triaging and validating researcher findings
- Lead application security testing including black-box, grey-box and red/purple-team exercises
- Drive SOC 2, ISO 27001 and GDPR compliance from an application security standpoint
- Perform security due diligence on third-party vendors, APIs and integrations
What they’re looking for
- 8+ years in Application / Product Security in high-risk environments (fintech, crypto, trading, SaaS, etc.)
- Proven experience operating as a lead IC, owning AppSec without layers of management
- Deep expertise in secure coding, OWASP Top 10, threat modelling and modern application architectures
- Strong hands-on experience with AWS, Azure or GCP and Linux
- Experience building and automating a secure SDLC
- OSWE, OSCP, CSSLP or similar are highly desirable
- Confident influencing senior engineers and architects at a technical level
Talent-led compensation – salary and package are flexible and can exceed current earnings for the right person