Security Test Engineer

BearingPoint Caribbean

Rotterdam

On-site

EUR 70,000 - 95,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Blyce is seeking a Security Test Engineer to strengthen the security and quality of software solutions used worldwide. The role involves identifying and validating security risks across web apps and APIs, documenting findings, and driving remediation with stakeholders.

You will work in a cross-functional, international environment, contributing to secure software delivery and CI/CD security practices. Strong English communication is required.

Qualifications

  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or equivalent practical experience.
  • 3+ years of experience in security testing, penetration testing, or application security.
  • Experience testing web applications, APIs, networks, and common auth controls.
  • Knowledge of security-testing methodologies and standards (OWASP Top 10/GT/PTES).
  • Experience using Burp Suite, Nmap, vulnerability scanners and related tools.
  • Ability to produce clear security reports with evidence and remediation guidance.
  • Strong analytical, problem-solving and communication skills.
  • Good command of English, written and spoken.

Responsibilities

  • Perform hands-on security testing for web apps, APIs, portals, platforms, and product enhancements.
  • Identify and validate vulnerabilities related to OWASP risks and authentication/authorization.
  • Use security testing tools and manually validate findings, assess business impact.
  • Prepare clear security test reports with risk ratings and remediation recommendations.
  • Follow up on remediation, retest fixes, and drive findings to closure.
  • Support implementation of automated security testing in CI/CD pipelines.

Skills

Security testing
Vulnerability assessment
Penetration testing
OWASP
APIs
Web apps

Education

Bachelor's degree

Tools

Burp Suite
Nmap
Vulnerability scanners

Job description

Blyce is looking for a Security Test Engineer to join our Product Development and testing organization, working closely with the Security team and development stakeholders.

Job description

Are you ready to help strengthen the security and quality of software solutions that support governments and societies around the world? Blyce is looking for a Security Test Engineer to join our Product Development and testing organization, working closely with the Security team and development stakeholders. This is a full-time role, preferably based in Medellín, while we are also open to strong candidates in Curaçao or, where needed, the Netherlands. Strong English communication skills are required.

In this role, you will play a key part in identifying, validating, and helping resolve application security risks across web applications, APIs, platforms, enhancements, and software solutions. You will test from a security perspective, document findings clearly, follow up on remediation, and support the move toward stronger, non-negotiable security gates in the software delivery process.

Every day, you will combine analytical thinking, hands‑on security testing, stakeholder collaboration, and practical problem solving to help Blyce deliver secure and reliable products. You will work in a cross-functional, international environment where security is becoming more deeply embedded into development and testing processes.

Key Responsibilities

Security Testing & Vulnerability Assessment

  • Perform hands‑on security testing for web applications, APIs, portals, platforms, software solutions, and product enhancements.
  • Identify and validate vulnerabilities related to OWASP risks, authentication, authorization, APIs, XSS, SQL injection, blind SQL injection, exposed hashes, security details, and related application security topics.
  • Use tools such as Burp Suite, Nmap, vulnerability scanners, and other security‑testing utilities to support testing activities.
  • Manually validate findings, distinguish genuine vulnerabilities from false positives, and assess the business impact of security risks.
  • Apply knowledge of security‑testing methodologies and standards, including OWASP Top 10, the OWASP Testing Guide, and PTES.

Reporting, Follow‑up & Remediation

  • Prepare clear and accurate security test reports with supporting evidence, risk ratings, and practical remediation recommendations.
  • Share findings with requesters and relevant stakeholders in a clear, constructive, and actionable way.
  • Follow up on remediation actions, review change logs, retest fixes, and confirm whether identified gaps have been closed.
  • Escalate risks or unresolved findings when needed and help drive security findings to closure across teams.

Security in the Development Lifecycle

  • Support the implementation and improvement of automated security testing within CI/CD pipelines.
  • Help embed security checks, static or security scans, and security gates into the software delivery process.
  • Collaborate with Product Development, testing teams, and Security stakeholders to strengthen application security practices.
  • Contribute to a culture where security is addressed proactively, practically, and consistently throughout development and release cycles.

Stakeholder Collaboration & Ownership

  • Review security test requests submitted through internal templates and Jira boards, including scope, links, and relevant context.
  • Communicate clearly with technical and non‑technical stakeholders about risks, findings, impact, and possible solutions.
  • Take ownership of assigned security testing activities from intake through reporting, follow‑up retesting, and closure.
  • Act with professional integrity and handle confidential information responsibly.
Job requirements
  • Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or a comparable field or equivalent practical experience.
  • At least 3 years of experience in security testing, penetration testing, application security, or a related role.
  • Practical experience testing web applications, APIs, networks, and common authentication and authorization controls.
  • Knowledge of security‑testing methodologies and standards, including OWASP Top 10, OWASP Testing Guide, and PTES.
  • Experience using tools such as Burp Suite, Nmap, vulnerability scanners, and related security‑testing utilities.
  • Ability to manually identify and validate vulnerabilities, distinguish genuine findings from false positives, and assess business impact.
  • Working knowledge of Windows, Linux, TCP/IP networking, HTTP, databases, and cloud-based environments.
  • Basic scripting skills in a language such as Python, PowerShell, Bash, or JavaScript.
  • Ability to produce clear, accurate reports containing evidence, risk ratings, and practical remediation recommendations.
  • Strong analytical, problem‑solving, and communication skills.
  • <
  • Professional integrity and the ability to handle confidential information responsibly.
  • Good command of written and spoken English.

Preferred qualifications

  • A relevant certification such as OSCP, PNPT, eWPT, CREST, CEH, or Security+.
  • Experience testing Microsoft‑based environments, Azure, Microsoft 365, or other cloud platforms.
  • Familiarity with secure software‑development practices, source‑code review, CI/CD pipelines, and DevSecOps.
  • Experience conducting security retests and working directly with development and infrastructure teams to resolve findings.
  • Familiarity with recognized risk‑rating methods such as CVSS.

Competencies

  • Analytical thinking: systematically investigates complex systems and identifies security weaknesses.
  • Attention to detail: recognizes subtle vulnerabilities, configuration errors, and inconsistencies.
  • Risk awareness: prioritizes findings according to likelihood, impact, and business context.
  • Problem‑solving: develops effective test approaches when standard methods are insufficient.
  • Clear communication: explains technical risks and recommendations to both technical and non‑technical stakeholders.
  • Collaboration: works constructively with developers, testers, infrastructure specialists, and product teams.
  • Professional integrity: acts ethically and handles sensitive information with discretion.
  • Ownership: takes responsibility for test quality, reporting, follow‑up, and retesting.
  • Learning agility: keeps skills current as technologies, threats, and testing methods evolve.
  • Pragmatism: recommends proportionate, achievable improvements that balance security and business needs.

About Blyce

Blyce develops software solutions in taxes, social security, permits, and licenses that support governments and societies worldwide. The company works with a multicultural team of professionals across Curaçao, the Netherlands, Colombia, Bonaire and Bali.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Test Engineer
Security Test Engineer

BearingPoint Caribbean • Deventer

Hybrid
EUR 60,000 - 75,000
Security Testing Engineer: Web & API Security
Security Testing Engineer: Web & API Security

BearingPoint Caribbean • Deventer

Hybrid
EUR 60,000 - 75,000
Security Test Engineer
Security Test Engineer

Blyce • Deventer

Hybrid
EUR 45,000 - 59,000
Gross monthly salary €4,000–€5,325 (NL
28 vacation days (+8 with buy/sell)
8.33% vacation pay
+9
Security Test Engineer
Security Test Engineer

Blyce • Rotterdam

On-site
EUR 45,000 - 59,000
Competitive salary
Pension plan
Health insurance
+3
Security Test Engineer: Web & API Security Specialist
Security Test Engineer: Web & API Security Specialist

Blyce • Rotterdam

Hybrid
EUR 45,000 - 59,000
Competitive salary
Pension plan
Health insurance
+3
Hands-on Security Test Engineer (OWASP & Pentest)
Hands-on Security Test Engineer (OWASP & Pentest)

BearingPoint Caribbean • Rotterdam

On-site
EUR 70,000 - 95,000
Performance Test Engineer
Performance Test Engineer

Blyce • Rotterdam

Hybrid
EUR 70,000 - 90,000
Competitive salary
28 vacation days with options to buy/sell
Fixed expense allowance
+5
Software Test Engineer
Software Test Engineer

United States Digital Space LLC • Noord-Holland

On-site
EUR 60,000 - 100,000
Competitive salary and benefits
Team activities and company events
Fresh team lunches 3x per week
Security Engineer
Security Engineer

Bynder • Rotterdam

Hybrid
EUR 70,000 - 90,000
Unlimited vacation policy
Competitive salary and benefits
Apple gear and daily lunch
International Inside Sales Consultant
International Inside Sales Consultant

Bureau Veritas Cybersecurity • Amsterdam

Hybrid
EUR 35,000 - 40,000
Compensation
Connectivity allowance
Holidays 28 days
+7