Skip to sign up

Job matched to your search

Security Professional

IQ Staffing · Utrecht

Utrecht · On-siteFull-TimePosted Sep 2, 2026

Free · Join 5,000+ job seekers using Qarera

How well do you match this role?

Tap the skills you already have — then see your real match score, what’s missing, and your resume fixed for this job.

↑ tap the skills you have
Loading sign-in…
Free · no credit card · 30 seconds

Job description

Security Professional – External Fraud & Sanctions Detection

We are looking for a Medior Security Professional to strengthen the security posture of a technology area focused on External Fraud and Sanctions Detection.

This is not a purely advisory security role. You will work closely with engineers, architects, risk officers, product owners and security specialists to make sure security is built into solutions from the start and remains effective once those solutions are in production.

Your role is to be the security conscience of the area: identifying risks early, challenging designs, coordinating vulnerability remediation and helping delivery teams move from reactive security fixes towards a secure-by-design way of working.

The environment is highly regulated, technically complex and closely connected to fraud prevention, resilience and operational continuity.

What you will do

You will act as the main security point of contact for the area and help engineering and product teams make sound security decisions throughout the development lifecycle.

Your responsibilities will include:

  • Facilitating threat modelling sessions for applications, platforms and new capabilities
  • Reviewing technical designs from a security perspective
  • Defining security requirements and acceptance criteria during refinement and development
  • Supporting teams with secure coding, authentication, authorization, secrets management and access controls
  • Coordinating vulnerability reviews across applications and infrastructure
  • Driving remediation of high and critical security findings
  • Helping teams reduce recurring vulnerabilities through structural engineering improvements
  • Supporting SAST, DAST and Software Composition Analysis within CI/CD pipelines
  • Reviewing security controls around cloud platforms, infrastructure and applications
  • Supporting penetration tests, security assessments and risk reviews
  • Ensuring logging, monitoring, auditability and privileged access controls are properly implemented
  • Supporting incident investigations, root-cause analysis and corrective actions
  • Contributing to resilience, Business Continuity and Disaster Recovery activities
  • Supporting audits, risk assessments and security control documentation
  • Providing security posture updates, metrics and remediation reporting
  • Coaching engineering and product teams on secure-by-design and DevSecOps practices

Secure-by-design

A major part of the role is ensuring security is embedded throughout the delivery lifecycle rather than checked only at the end.

You will help teams incorporate security into:

Requirements

  • Security acceptance criteria
  • Abuse cases and attack scenarios
  • Security and compliance requirements

Architecture and design

  • Threat modelling
  • Zero Trust principles
  • Defense-in-Depth
  • Trust boundaries and external integrations
  • Least-privilege access

Development

  • Secure coding practices
  • Security-focused code reviews
  • Authentication and authorization
  • Secure management of credentials and secrets

Testing and deployment

  • SAST, DAST and dependency scanning
  • Vulnerability remediation
  • Penetration testing and security assessments

Operations

  • Security monitoring and logging
  • Auditability
  • Privileged access
  • Resilience, backup and recovery

What we are looking for

You have approximately 3–5 years of relevant professional experience within areas such as:

  • Cyber Security
  • Security Engineering
  • DevSecOps or Platform Engineering
  • IT Risk
  • Software Engineering with a strong security component

You should also have experience with:

  • Agile and DevOps environments
  • Vulnerability management and remediation
  • Security controls within technology environments
  • Working with engineers, architects, security specialists and risk stakeholders
  • Secure software development practices
  • Threat modelling
  • Identity and access management
  • Authentication and authorization
  • Security monitoring
  • CI/CD security controls
  • Risk-based security decision making

Strong communication skills are important. You should be comfortable challenging teams when necessary, explaining security risks clearly and influencing stakeholders without relying on formal authority.

Technical knowledge

Relevant knowledge includes:

  • Secure Software Development Lifecycle (SSDLC)
  • OWASP Top 10
  • Threat Modelling
  • Identity & Access Management
  • Authentication & Authorization
  • Encryption & Key Management
  • Vulnerability Management
  • Security Monitoring
  • Cloud Security
  • Zero Trust Architecture
  • Defense-in-Depth
  • Network Security
  • DevSecOps
  • CI/CD Security
  • Security Automation
  • Python and/or KQL

You do not need to be an expert in every area. The role requires enough technical depth to understand security risks, challenge engineering decisions and help teams implement practical solutions.

Frameworks and regulation

Experience with one or more of the following is valuable:

  • ISO 27001
  • NIST Cybersecurity Framework
  • DORA
  • Secure Software Development Lifecycle standards
  • Security policies within regulated organisations

Experience within banking, financial services, payments, fraud prevention, FEC or another regulated environment is strongly preferred.

Nice to have

Experience with:

  • Azure security
  • Penetration testing
  • Security assessments and audits
  • DevSecOps
  • Detection engineering
  • Digital fraud prevention
  • Incident response

Relevant certifications such as CISSP, CISM, CCSP, Security+, CEH, GIAC or Microsoft Security certifications are useful but not mandatory.

About you

You are technically credible, pragmatic and comfortable working between different disciplines. You understand that strong security is not about blocking delivery, but about helping teams make better engineering decisions before risks become incidents.

You can work independently, but you are also a team player who enjoys coaching others and raising security maturity across an organisation.

Don’t just read the job — see if you’ll get it.

Get your match score, a resume tailored to this exact role, and jobs like it — free.

Check my fit for this job
Loading sign-in…
Apply →

Hiring for a role like this? Join the employer waitlist.