Overview

Information Security Engineer Jobs in Amsterdam, North Holland, Netherlands at Blue Lynx

Title: Information Security Engineer

Company: Blue Lynx

Location: Amsterdam, North Holland, Netherlands

Our client is an innovative software development company that provides effective workflow solutions for other businesses by creating a great experience and increasing productivity. They are currently looking for an Information Security Engineer to join their expanding team in Amsterdam. In the role, you will handle high-impact security vulnerabilities, investigate internal systems for duplication or remediation plans, and track security issues in collaboration with engineering teams.

Job Profile for Information Security Engineer

  • Triage security findings submitted through customer channels by validating exploitability, assessing affected scope, evaluating risk, and determining appropriate remediation actions
  • Analyse platform-level vulnerabilities across web applications, APIs, and server-side attack surfaces, including SSRF, IDOR, SQL injection, blind injection, XSS, GraphQL abuse, privilege escalation, and other related attack vectors
  • Prepare customer-facing security assessments that provide sufficient technical depth for security leadership while remaining clear and actionable for account teams
  • Collaborate with engineering teams on defect tracking, remediation planning, backport decisions, patch validation, and vulnerability resolution
  • Reproduce and validate reported vulnerabilities in lab environments, including cloud instances, Personal Developer Instances (PDIs), and local deployments
  • Review JavaScript and Java code to trace attack paths, identify root causes, and verify the completeness and effectiveness of security fixes

Candidate Profile for Information Security Engineer

  • Must be fluent in English, both written and spoken
  • 3+ years of experience in application security, penetration testing, bug bounty, or product security engineering
  • Experience writing technical security reports for engineering teams, security leadership, and executive stakeholders
  • Experience triaging vulnerability reports from bug bounty platforms such as HackerOne or Bugcrowd is preferable
  • Strong knowledge of web application security principles, including the OWASP Top 10 and advanced attack vectors such as prototype pollution, server-side injection, SSRF, IDOR,GraphQL abuse, and privilege escalation
  • Strong understanding of the company’s security mechanisms, including ACLs, roles, scoped applications, Business Rules, Scripted REST APIs, GlideRecord, Table API, and platform data access patterns
  • Strong understanding of CVSS scoring methodology and the ability to accurately assess and justify vulnerability severity
  • Ability to reproduce customer-reported security issues in lab environments by mirroring production scenarios
  • Ability to trace client-side and server-side code paths to identify root causes and clearly communicate vulnerability scope and impact

What Our Client Offers

  • 25 vacation days annually and additional company – wide days off
  • Pension scheme
  • Opportunity to collaborate with stakeholders of various backgrounds/levels
  • Opportunity to join a highly innovative company with a dynamic atmosphere

Please note: Candidates may be required to present references and diplomas, and have a background check

Upload your CV/resume or any other relevant file. Max. file size: 800 MB.