Security Test Engineer
Blyce · Deventer, Netherlands
Also hiring for this role in
You apply on the site where the job is posted. I never handle applications.
Your Challenge as Security Test Engineer
Are you ready to help strengthen the security and quality of software solutions that support governments and societies around the world? Blyce is looking for a Security Test Engineer to join our Product Development and testing organization, working closely with the Security team and development stakeholders. This is a full-time role, preferably based in Medellín, while we are also open to strong candidates in Curaçao or, where needed, the Netherlands. Strong English communication skills are required.
In this role, you will play a key part in identifying, validating, and helping resolve application security risks across web applications, APIs, platforms, enhancements, and software solutions. You will test from a security perspective, document findings clearly, follow up on remediation, and support the move toward stronger, non-negotiable security gates in the software delivery process.
Every day, you will combine analytical thinking, hands-on security testing, stakeholder collaboration, and practical problem solving to help Blyce deliver secure and reliable products. You will work in a cross-functional, international environment where security is becoming more deeply embedded into development and testing processes.
Key Responsibilities
Security Testing & Vulnerability Assessment
- Perform hands-on security testing for web applications, APIs, portals, platforms, software solutions, and product enhancements.
- Identify and validate vulnerabilities related to OWASP risks, authentication, authorization, APIs, XSS, SQL injection, blind SQL injection, exposed hashes, security details, and related application security topics.
- Use tools such as Burp Suite, Nmap, vulnerability scanners, and other security-testing utilities to support testing activities.
- Manually validate findings, distinguish genuine vulnerabilities from false positives, and assess the business impact of security risks. Apply knowledge of security-testing methodologies and standards, including OWASP Top 10, the OWASP Testing Guide, and PTES.
Reporting, Follow-up & Remediation
- Prepare clear and accurate security test reports with supporting evidence, risk ratings, and practical remediation recommendations.
- Share findings with requesters and relevant stakeholders in a clear, constructive, and actionable way.
- Follow up on remediation actions, review change logs, retest fixes, and confirm whether identified gaps have been closed.
- Escalate risks or unresolved findings when needed and help drive security findings to closure across teams.
Security in the Development Lifecycle
- Support the implementation and improvement of automated security testing within CI/CD pipelines.
- Help embed security checks, static or security scans, and security gates into the software delivery process.
- Collaborate with Product Development, testing teams, and Security stakeholders to strengthen application security practices.
- Contribute to a culture where security is addressed proactively, practically, and consistently throughout development and release cycles.
Stakeholder Collaboration & Ownership
- Review security test requests submitted through internal templates and Jira boards, including scope, links, and relevant context.
- Communicate clearly with technical and non-technical stakeholders about risks, findings, impact, and possible solutions.
- Take ownership of assigned security testing activities from intake through reporting, follow-up, retesting, and closure.
- Act with professional integrity and handle confidential information responsibly.
We Offer an Attractive Benefits Package Including:
-
A competitive salary.
-
28 vacation days, with the option to buy or sell 8 additional days each year;
-
8.33% vacation pay;
-
A gross variable compensation equivalent to an extra month’s salary per year, paid out per month;
-
A gross fixed expense allowance of €300,- per month;
-
An annual reward, linked to company results;
-
Full coverage of your basic health insurance, plus a strong pension plan via a.s.r.;
-
A hybrid working policy that supports flexibility and balance;
-
A company laptop and all necessary IT tools;
-
A full-time position—though we’re open to part-time arrangements if that better suits your life;
-
Continuous development opportunities, guided by our Talent Development Specialist;
-
A fun and connected culture, with team events, dinners, and sports activities;
-
A warm, collaborative atmosphere within the Blyce family.
-
Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or a comparable field or equivalent practical experience.
-
At least 3 years of experience in security testing, penetration testing, application security, or a related role.
-
Practical experience testing web applications, APIs, networks, and common authentication and authorization controls.
-
Knowledge of security-testing methodologies and standards, including OWASP Top 10, OWASP Testing Guide, and PTES.
-
Experience using tools such as Burp Suite, Nmap, vulnerability scanners, and related security-testing utilities.
-
Ability to manually identify and validate vulnerabilities, distinguish genuine findings from false positives, and assess business impact.
-
Working knowledge of Windows, Linux, TCP/IP networking, HTTP, databases, and cloud-based environments.
-
Basic scripting skills in a language such as Python, PowerShell, Bash, or JavaScript.
-
Ability to produce clear, accurate reports containing evidence, risk ratings, and practical remediation recommendations.
-
Strong analytical, problem-solving, and communication skills.
-
Professional integrity and the ability to handle confidential information responsibly.
-
Good command of written and spoken English.
Preferred qualifications
- A relevant certification such as OSCP, PNPT, eWPT, CREST, CEH, or Security+.
- Experience testing Microsoft-based environments, Azure, Microsoft 365, or other cloud platforms.
- Familiarity with secure software-development practices, source-code review, CI/CD pipelines, and DevSecOps.
- Experience conducting security retests and working directly with development and infrastructure teams to resolve findings.
- Familiarity with recognized risk-rating methods such as CVSS.
Competencies
- Analytical thinking: systematically investigates complex systems and identifies security weaknesses.
- Attention to detail: recognizes subtle vulnerabilities, configuration errors, and inconsistencies.
- Risk awareness: prioritizes findings according to likelihood, impact, and business context.
- Problem-solving: develops effective test approaches when standard methods are insufficient.
- Clear communication: explains technical risks and recommendations to both technical and non-technical stakeholders.
- Collaboration: works constructively with developers, testers, infrastructure specialists, and product teams.
- Professional integrity: acts ethically and handles sensitive information with discretion.
- Ownership: takes responsibility for test quality, reporting, follow-up, and retesting.
- Learning agility: keeps skills current as technologies, threats, and testing methods evolve.
- Pragmatism: recommends proportionate, achievable improvements that balance security and business needs.
About Blyce
For over 40 years, Blyce has been at the forefront of digitizing governments and societies worldwide. Our innovative software solutions in taxes, social security, permits, and licenses impact communities in more than 20+ countries. We pride ourselves on our multicultural team of 175+ professionals working from Curaçao, the Netherlands, Colombia, Bonaire and Bali.
Join us in shaping the future of public service digitization with cutting-edge technology and a passionate, collaborative team!
If you’re ready to make a difference, apply now by sharing your LinkedIn profile or leaving your contact details via the button below. Have questions about this vacancy? Feel free to reach out to our Talent Acquisition Specialists, at recruitment@blyce.com.