Back to jobs

    About Bynder

    Bynder enables brands to deliver exceptional content experiences that drive business impact. In an era of exploding content volume and complexity, world-renowned brands like Spotify, Campari, and Lacoste trust Bynder as their single source of truth for creative content. Our industry-leading DAM platform serves as the strategic engine for brand governance and control. We are leading the shift from management to AI-powered content orchestration, integrating human-led, customizable AI Agents into our enterprise-grade infrastructure. This allows brands to augment their workforce and intelligently automate high-effort workflows without sacrificing brand integrity, turning creative content into intelligent assets that accelerate personalization and drive measurable business outcomes.

    About the Position

    Introduction

    At Bynder, we believe security should never be an afterthought. We are looking for a Security Engineer who thrives in a growth-oriented environment, seeing security as a starting point, not the finish line. If you are hands-on by nature, energized by breadth, and serious about building security that scales in a cloud-native SaaS environment, you’ll feel right at home here.

    Bynder’s Security team is pragmatic, sharp, and focused on enabling secure growth. We prioritize automation over repetition, integrations over point solutions, and smart security design over checkbox compliance.

    Responsibilities

    • Plan and (help) execute penetration tests against web applications, APIs, and cloud infrastructure, and manage external pentest engagements including scoping, vendor coordination, and remediation tracking.
    • Embed security across the full SDLC: leading threat modeling, security assessments, and vulnerability remediation in close collaboration with our engineering and product teams.
    • Own and evolve our cloud security posture across our AWS environment, working with Wiz (CSPM, CNS, Code, AI Security) to drive risk prioritization, misconfiguration remediation, and shift-left security workflows.
    • Champion security controls within our CI/CD pipelines, from IaC scanning and SAST integration to secure deployment practices, working closely with DevOps and development teams.
    • Support security incident response, investigation, containment guidance, and post-incident review and help mature our detection and response workflows over time.
    • Translate compliance requirements (SOC2, ISO 42001, GDPR) into concrete technical controls and act as a technical point of contact for customer security discussions, questionnaires, and enterprise onboarding.
    • Conduct vendor and third-party security risk assessments to protect our supply chain and advise on emerging AI/ML security risks as these technologies become more deeply embedded in our product.
    • Share knowledge and raise the craft, naturally becoming a technical anchor for your teammate and a collaborative voice across engineering on what good security looks like in practice.

    Requirements

    • 3–7 years of hands-on experience in application security, cloud security (AWS), or a broad security engineering role.
    • Proven experience conducting penetration tests on web applications, APIs, and/or cloud environments, with a solid grip on OWASP Top 10 and common vulnerability classes.
    • Solid understanding of AWS security: IAM, VPC design, cloud-native architecture, and a clear intuition for what secure cloud infrastructure looks like.
    • Familiarity with application security testing tools (SAST, DAST) and a practical understanding of DevSecOps: you know where to plug in and how to make it stick with developers.
    • Strong communication skills, able to explain security risks clearly to both engineers and non-technical stakeholders, and you don’t default to “no” when there’s a smarter path forward.
    • A growth mindset and genuine curiosity, comfortable operating across domains, actively building skills you don’t yet have, and seeing a broad scope as an opportunity, not a burden.

    Nice to Have

    • Hands-on experience with Wiz, or other CSPM/CNAPP platforms.
    • Offensive security certification (OSCP or similar) or contributions to bug bounty programs.
    • Experience with AI/ML security risks and frameworks (OWASP LLM Top 10, MITRE ATLAS).
    • Ability to write security scripts, tinker with tools, or maintain a personal GitHub with automation or research projects.
    • Experience with Terraform or IaC security scanning.
    • Hands-on experience with Kubernetes and container security.
    • Familiarity with common programming languages (e.g., Python, Java, Scala) and ability to read and reason about code to support security reviews.

    Benefits

    • Challenging and inspiring work environment
    • Learning and Development budget
    • Commuting budget
    • Mental Health and Well-being Support
    • Bynder Love "stipend”
    • Unlimited vacation policy
    • Volunteer Time Off
    • Team and Company activities
    • Complimentary Lunches and Snacks
    • Offices in Amsterdam or Rotterdam (this role is for Rotterdam)

    About Company

    Bynder enables brands to deliver exceptional content experiences that drive business impact. In an era of exploding content volume and complexity, world-renowned brands like Spotify, Campari, and Lacoste trust Bynder as their single source of truth for creative content. Our industry-leading DAM platform serves as the strategic engine for brand governance and control. We are leading the shift from management to AI-powered content orchestration, integrating human-led, customizable AI Agents into our enterprise-grade infrastructure. This allows brands to augment their workforce and intelligently automate high-effort workflows without sacrificing brand integrity, turning creative content into intelligent assets that accelerate personalization and drive measurable business outcomes.

    How to Apply

    If you don’t tick every box but you’re the kind of person who figures things out, speaks up, and raises the standard around you, we’d still love to hear from you. Apply directly via the provided link.

    Apply Now

    Your data is only shared with Bynder

    Location

    Rotterdam

    Type

    Full-Time

    Keywords

    AI
    Security Engineering
    Application Security
    Cloud Security
    AWS
    Penetration Testing
    OWASP Top 10
    SDLC
    Threat Modeling
    Vulnerability Management
    DevSecOps
    CI/CD Security
    SAST
    D AST
    IAM
    VPC
    Wiz
    CSPM
    CNS
    AI Security
    Incident Response
    SOC2
    ISO 42001
    GDPR
    Vendor Risk Assessment
    AI/ML Security
    Terraform
    IaC Security
    Kubernetes
    Container Security
    Python
    Java
    Scala
    Verified Company

    Security Engineer

    Bynder