Jobs / engineering
Security Researcher / Ethical Hacker
Sqills Products · Enschede
What they look for
Bachelor and/or master degree in IT, preferably in cyber security, security management or related (minors in this field are also an option).
Enjoys participating in CTFs or likes to "pwn" a box at HackTheBox;
3+ years of end-to-end offensive security experience (penetration tester, bug bounty hunter, security researcher) and a hacker's mindset, comfortable with the OWASP Top 10 and exploit development.
Solid grasp of cloud security, specifically AWS and Kubernetes, and the ability to read and review code (Java, Kotlin, Golang).
Working knowledge of compliance frameworks, including PCI DSS, and familiarity with modern offensive tools like Burp Suite, Caido, OWASP ZAP, Nuclei, etc..
Must be able to work independently, and communicate clearly with both technical and non-technical stakeholders in English.
Nice to have
Relevant certifications such as OSCP, OSCE, OSWE, CRTO, AWS Security Specialty.
Experience contributing to open-source security tooling, CVE disclosures or public research.
Background in the public-transport, fintech or other regulated SaaS space.
This is a challenging opportunity to work on a product with a significant impact and make a significant contribution to the rail- and bus transport industry. If you are a talented and driven ethical hacker or security researcher, we would love to hear from you.