> Markdown version of [/jobs/ext/12905-security-researcher-ethical-hacker](https://www.wearedevelopers.com/jobs/ext/12905-security-researcher-ethical-hacker). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Researcher / Ethical Hacker - **Company:** Sqills - **Location:** Enschede, Netherlands - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Java (Programming Language), Amazon Web Services, Amazon S3, Software System Penetration Testing, Burp Suite, Software as a Service, Cloud Computing Security, Code Review, Cyber Security, DevOps, Open Source Technology, Open Web Application Security, PCI Data Security Standards, Red Team (Cyber Security), Kotlin, Kubernetes, Static Application Security Testing, Golang, Dynamic Application Security Testing - **Published:** May 24, 2026 - **Apply:** https://nl.indeed.com/viewjob?jk=258cd0a7101e6e37 ## About the Role Do you have a Master's degree?, * Bachelor and/or master degree in IT, preferably in cyber security, security management or related (minors in this field are also an option). * Enjoys participating in CTFs or likes to "pwn" a box at HackTheBox; * 3+ years of end-to-end offensive security experience (penetration tester, bug bounty hunter, security researcher) and a hacker's mindset, comfortable with the OWASP Top 10 and exploit development. * Solid grasp of cloud security, specifically AWS and Kubernetes, and the ability to read and review code (Java, Kotlin, Golang). * Working knowledge of compliance frameworks, including PCI DSS, and familiarity with modern offensive tools like Burp Suite, Caido, OWASP ZAP, Nuclei, etc.. * Must be able to work independently, and communicate clearly with both technical and non-technical stakeholders in English. Nice to have: * Relevant certifications such as OSCP, OSCE, OSWE, CRTO, AWS Security Specialty. * Experience contributing to open-source security tooling, CVE disclosures or public research. * Background in the public-transport, fintech or other regulated SaaS space. This is a challenging opportunity to work on a product with a significant impact and make a significant contribution to the rail- and bus transport industry. If you are a talented and driven ethical hacker or security researcher, we would love to hear from you., We can only consider applications from Dutch, EU/EEA or Swiss citizens, or from individuals who already hold a valid residence and work permit for the Netherlands. ## Description S3 Passenger powers ticketing for some of the largest rail and bus operators in the world (SNCF, VIA Rail, PT Kai, Eurostar and more). That comes with a serious attack surface, real payment flows, PCI DSS scope, and a fully cloud-native AWS/Kubernetes stack that is in production 24/7. We are looking for an ethical hacker to join our internal Red Team. You will be one of a small group of dedicated security engineers, part offensive specialist, part trusted advisor to our DevOps teams, part technical counterpart to our external auditors. You enjoy breaking things, but you equally enjoy the long game of making sure they cannot be broken again. What will you do? * Your role involves performing internal penetration tests and supporting external security audits (PCI DSS, ASV scans). * You will secure our cloud and infrastructure (AWS/Kubernetes), review source code, and tune our SAST/DAST security pipelines. * Key responsibilities also include security incident response, threat modeling, challenging the security awareness program, implementing security automation, and researching new vulnerabilities., * An enthusiastic, young, and diverse group of ~250 colleagues worldwide. * A flat hierarchy with a lot of individual responsibility and room for your ideas. * An open and challenging environment for ambitious professionals. * Great benefits including a FlexBudget, supplementary pension, and lunch in our Grand Café. * Inspiring company outings and Friday drinks on our roof terrace. ## Related Videos - [Go with the Flow: Stop the Leaks Before Your Memory's a Waterfall!](https://www.wearedevelopers.com/videos/100073-go-with-the-flow-stop-the-leaks-before-your-memory-s-a-waterfall) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [Kotlin Multiplatform - True power of native code reuse](https://www.wearedevelopers.com/videos/4-kotlin-multiplatform-true-power-of-native-code-reuse) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [#90DaysOfDevOps - The DevOps Learning Journey](https://www.wearedevelopers.com/videos/548-90daysofdevops-the-devops-learning-journey) - [Scoring 2000 Products per Request: Performance Pitfalls in Golang](https://www.wearedevelopers.com/videos/2073-scoring-2000-products-per-request-performance-pitfalls-in-golang) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Best Companies in the Netherlands: Top 25 Companies in 2023 ](https://www.wearedevelopers.com/magazine/193-best-companies-in-the-netherlands-top-25-companies-in-2023) - [Where To Find Software Engineering Jobs](https://www.wearedevelopers.com/magazine/396-where-to-find-software-engineering-jobs) - [Where to Find Entry-Level Software Engineering Jobs](https://www.wearedevelopers.com/magazine/397-where-to-find-entry-level-software-engineering-jobs) - [How to Find Tech Jobs in Amsterdam](https://www.wearedevelopers.com/magazine/279-how-to-find-tech-jobs-in-amsterdam) - [Find a Developer Job: 12 Best Job Sites For Developers](https://www.wearedevelopers.com/magazine/165-find-a-developer-job-12-best-job-sites-for-developers)