Overview
Information Security Engineer Jobs in Amsterdam, North Holland, Netherlands at Blue Lynx
Title: Information Security Engineer
Company: Blue Lynx
Location: Amsterdam, North Holland, Netherlands
Our client is an innovative software development company that provides effective workflow solutions for other businesses by creating a great experience and increasing productivity. They are currently looking for an Information Security Engineer to join their expanding team in Amsterdam. In the role, you will handle high-impact security vulnerabilities, investigate internal systems for duplication or remediation plans, and track security issues in collaboration with engineering teams.
Job Profile for Information Security Engineer
- Triage security findings submitted through customer channels by validating exploitability, assessing affected scope, evaluating risk, and determining appropriate remediation actions
- Analyse platform-level vulnerabilities across web applications, APIs, and server-side attack surfaces, including SSRF, IDOR, SQL injection, blind injection, XSS, GraphQL abuse, privilege escalation, and other related attack vectors
- Prepare customer-facing security assessments that provide sufficient technical depth for security leadership while remaining clear and actionable for account teams
- Collaborate with engineering teams on defect tracking, remediation planning, backport decisions, patch validation, and vulnerability resolution
- Reproduce and validate reported vulnerabilities in lab environments, including cloud instances, Personal Developer Instances (PDIs), and local deployments
- Review JavaScript and Java code to trace attack paths, identify root causes, and verify the completeness and effectiveness of security fixes
Candidate Profile for Information Security Engineer
- Must be fluent in English, both written and spoken
- 3+ years of experience in application security, penetration testing, bug bounty, or product security engineering
- Experience writing technical security reports for engineering teams, security leadership, and executive stakeholders
- Experience triaging vulnerability reports from bug bounty platforms such as HackerOne or Bugcrowd is preferable
- Strong knowledge of web application security principles, including the OWASP Top 10 and advanced attack vectors such as prototype pollution, server-side injection, SSRF, IDOR,GraphQL abuse, and privilege escalation
- Strong understanding of the company’s security mechanisms, including ACLs, roles, scoped applications, Business Rules, Scripted REST APIs, GlideRecord, Table API, and platform data access patterns
- Strong understanding of CVSS scoring methodology and the ability to accurately assess and justify vulnerability severity
- Ability to reproduce customer-reported security issues in lab environments by mirroring production scenarios
- Ability to trace client-side and server-side code paths to identify root causes and clearly communicate vulnerability scope and impact
What Our Client Offers
- 25 vacation days annually and additional company – wide days off
- Pension scheme
- Opportunity to collaborate with stakeholders of various backgrounds/levels
- Opportunity to join a highly innovative company with a dynamic atmosphere
Please note: Candidates may be required to present references and diplomas, and have a background check