Job matched to your search
Security Professional
IQ Staffing · Utrecht
Free · Join 5,000+ job seekers using Qarera
How well do you match this role?
Tap the skills you already have — then see your real match score, what’s missing, and your resume fixed for this job.
Job description
Security Professional – External Fraud & Sanctions Detection
We are looking for a Medior Security Professional to strengthen the security posture of a technology area focused on External Fraud and Sanctions Detection.
This is not a purely advisory security role. You will work closely with engineers, architects, risk officers, product owners and security specialists to make sure security is built into solutions from the start and remains effective once those solutions are in production.
Your role is to be the security conscience of the area: identifying risks early, challenging designs, coordinating vulnerability remediation and helping delivery teams move from reactive security fixes towards a secure-by-design way of working.
The environment is highly regulated, technically complex and closely connected to fraud prevention, resilience and operational continuity.
What you will do
You will act as the main security point of contact for the area and help engineering and product teams make sound security decisions throughout the development lifecycle.
Your responsibilities will include:
- Facilitating threat modelling sessions for applications, platforms and new capabilities
- Reviewing technical designs from a security perspective
- Defining security requirements and acceptance criteria during refinement and development
- Supporting teams with secure coding, authentication, authorization, secrets management and access controls
- Coordinating vulnerability reviews across applications and infrastructure
- Driving remediation of high and critical security findings
- Helping teams reduce recurring vulnerabilities through structural engineering improvements
- Supporting SAST, DAST and Software Composition Analysis within CI/CD pipelines
- Reviewing security controls around cloud platforms, infrastructure and applications
- Supporting penetration tests, security assessments and risk reviews
- Ensuring logging, monitoring, auditability and privileged access controls are properly implemented
- Supporting incident investigations, root-cause analysis and corrective actions
- Contributing to resilience, Business Continuity and Disaster Recovery activities
- Supporting audits, risk assessments and security control documentation
- Providing security posture updates, metrics and remediation reporting
- Coaching engineering and product teams on secure-by-design and DevSecOps practices
Secure-by-design
A major part of the role is ensuring security is embedded throughout the delivery lifecycle rather than checked only at the end.
You will help teams incorporate security into:
Requirements
- Security acceptance criteria
- Abuse cases and attack scenarios
- Security and compliance requirements
Architecture and design
- Threat modelling
- Zero Trust principles
- Defense-in-Depth
- Trust boundaries and external integrations
- Least-privilege access
Development
- Secure coding practices
- Security-focused code reviews
- Authentication and authorization
- Secure management of credentials and secrets
Testing and deployment
- SAST, DAST and dependency scanning
- Vulnerability remediation
- Penetration testing and security assessments
Operations
- Security monitoring and logging
- Auditability
- Privileged access
- Resilience, backup and recovery
What we are looking for
You have approximately 3–5 years of relevant professional experience within areas such as:
- Cyber Security
- Security Engineering
- DevSecOps or Platform Engineering
- IT Risk
- Software Engineering with a strong security component
You should also have experience with:
- Agile and DevOps environments
- Vulnerability management and remediation
- Security controls within technology environments
- Working with engineers, architects, security specialists and risk stakeholders
- Secure software development practices
- Threat modelling
- Identity and access management
- Authentication and authorization
- Security monitoring
- CI/CD security controls
- Risk-based security decision making
Strong communication skills are important. You should be comfortable challenging teams when necessary, explaining security risks clearly and influencing stakeholders without relying on formal authority.
Technical knowledge
Relevant knowledge includes:
- Secure Software Development Lifecycle (SSDLC)
- OWASP Top 10
- Threat Modelling
- Identity & Access Management
- Authentication & Authorization
- Encryption & Key Management
- Vulnerability Management
- Security Monitoring
- Cloud Security
- Zero Trust Architecture
- Defense-in-Depth
- Network Security
- DevSecOps
- CI/CD Security
- Security Automation
- Python and/or KQL
You do not need to be an expert in every area. The role requires enough technical depth to understand security risks, challenge engineering decisions and help teams implement practical solutions.
Frameworks and regulation
Experience with one or more of the following is valuable:
- ISO 27001
- NIST Cybersecurity Framework
- DORA
- Secure Software Development Lifecycle standards
- Security policies within regulated organisations
Experience within banking, financial services, payments, fraud prevention, FEC or another regulated environment is strongly preferred.
Nice to have
Experience with:
- Azure security
- Penetration testing
- Security assessments and audits
- DevSecOps
- Detection engineering
- Digital fraud prevention
- Incident response
Relevant certifications such as CISSP, CISM, CCSP, Security+, CEH, GIAC or Microsoft Security certifications are useful but not mandatory.
About you
You are technically credible, pragmatic and comfortable working between different disciplines. You understand that strong security is not about blocking delivery, but about helping teams make better engineering decisions before risks become incidents.
You can work independently, but you are also a team player who enjoys coaching others and raising security maturity across an organisation.
More jobs in Utrecht
Browse related jobs
Don’t just read the job — see if you’ll get it.
Get your match score, a resume tailored to this exact role, and jobs like it — free.
Check my fit for this job