EnglishWillDo

Senior Security Engineer

Brand New Day · Amsterdam-Zuidoost, Netherlands

Dutch is a plusPosted today
Apply for this job

You apply on the site where the job is posted. I never handle applications.

Senior Security Engineer

At Brand New Day, you’ll have the freedom and influence to make a visible difference to our security. As our Senior Security Engineer, you’ll take the lead in vulnerability management, advise technical teams and help make our services more secure from the start.

This is a hands-on role for an experienced security specialist who combines technical expertise with practical advice. You’ll work independently, collaborate with colleagues across IT and help us continuously improve our security capabilities.

What will you do as Senior Security Engineer?

You’ll lead our vulnerability management process: identifying and prioritising vulnerabilities, coordinating remediation and helping teams resolve security risks effectively. You’ll work closely with Development, DevOps, Data & AI, Cloud and IT Operations to improve how we detect, assess and address vulnerabilities across our technology landscape.

You’ll also be one of the organisation’s go-to technical security specialists. You’ll advise IT teams on security best practices, help embed security by design into projects, perform security reviews and contribute to technical policies and controls.

Your contribution goes beyond solving immediate security challenges. By coaching colleagues, sharing your expertise and improving our ways of working, you’ll help strengthen the technical security knowledge of both the security team and the wider organisation.

Your key activities and responsibilities in short:

  • Lead our vulnerability management process using tools such as Tenable, CAST Highlight and SonarCloud, and work with IT teams to ensure vulnerabilities are resolved on time.
  • Give IT teams practical security advice and help embed security by design into new solutions.
  • Improve the security of our Azure and Microsoft 365 environments through technical controls, policies, firewall reviews and ongoing improvements.
  • Contribute ideas and technical expertise to improve our security tooling, architecture and ways of working.
  • Share your knowledge with colleagues and help strengthen the technical expertise of the security team.

What you’ll receive from us

  • A pleasant salary between €5,000 and €6,000 with pension accrual on top
  • 25 vacation days + 1 extra day off for celebration!
  • The option to work from home two days per week and a week per year remote (two weeks for expats)
  • Training budget of €1,000 per year to stay up to date in your field
  • €25 per month benefit budget for 1,001 fun or useful things (via Alleo)
  • Every week a fully catered lunch at the company’s expense. (On other days, you’ll need to arrange your own, but no worries: we’re right next to the Amsterdamse Poort, so you’ll have plenty of options.)

Who are you?

You’re an experienced security specialist who takes ownership and turns technical risks into practical improvements. You’re comfortable working independently, but you also know that effective security depends on close collaboration with developers, cloud engineers, DevOps engineers and IT Operations specialists.

You communicate clearly, know how to influence stakeholders and are generous with your expertise. You help colleagues grow, look for ways to improve technology and processes, and leave systems more secure than you found them.

Furthermore:

  • You have at least five years of experience in cyber security or infrastructure security.
  • You have demonstrable experience with vulnerability management and driving remediation across multiple stakeholders.
  • You have hands-on experience with Azure, Microsoft 365 and modern cloud security concepts.
  • You have solid knowledge of networking, firewalls and infrastructure security.
  • Experience with tools such as Tenable, SonarCloud and CAST Highlight is a plus.
  • You have experience implementing Security by Design principles in cloud or software development environments.
  • You have experience defining and implementing technical security policies and controls.
  • You are fluent in English and aren't afraid to pick up some Dutch.
  • Certifications such as CISSP, AZ-500, SC-200, SC-100 or similar are considered a plus.

And one more thing: research shows that women and members of underrepresented groups often only apply if they meet 100% of the requirements. Does this sound familiar? If so, we encourage you to apply anyway. We look forward to meeting you!

Check out our diversity policy here.