Build your career on Magnet.me
Create a profile and receive smart job recommendations based on your liked jobs.
You patch vulnerabilities before the bad guys find them. As an Ethical Hacker, you probe every corner of bol’s digital landscape to identify and eliminate potentially exploitable weaknesses. Your offensive security work directly protects 13.7 million customers and 47,000 partners by ensuring real attackers never have a chance. Professional paranoia with a purpose: you assume everything can be hacked, then prove or disprove that assumption systematically.
The biggest challenge
Risk prioritization in a fast-moving environment. You can’t test everything simultaneously, so which system deserves your attention first? The new checkout flow handling millions in daily revenue, or the internal tooling that could expose employee data? How do you balance thorough penetration testing with the reality that product teams need to ship new features? You make these judgment calls, fully cognizant of the impact of false alarms and missed threats.
What you'll do as Ethical Hacker
You’re joining the Security Operations team – a purple squad where red team offense and blue team defense collaborate to ensure bulletproof platform protection. The team includes six security specialists: you, a fellow ethical hacker, and five security engineers focused on the defensive side. Together, you secure bol’s entire technology landscape, from customer apps to our cloud infrastructure and warehouse conveyor belt control systems.
As an Ethical Hacker, you’re the offensive specialist. You conduct penetration tests, both at the request of product teams and on your own initiative, prioritizing based on risk levels rather than political pressure. High-risk environments are at the top of the list; low-risk systems can wait their turn. Beyond active testing, you participate in ‘break stuff on paper’ sessions where teams proffer technical designs for you to rip to shreds before a single line of code gets written. You perform vulnerability assessments across applications, systems, and networks, and help product teams with threat modeling to assess risks inherent in their solutions. The Security Operations team also owns incident management, maintaining visibility into bol’s overall security posture and running company-wide security awareness initiatives. When a security alert triggers, you’re expected to step up.
Key responsibilities:
Why you can make a difference
You combine proven ethical hacking experience across diverse technologies with the rare ability to explain security risks without making people defensive. Your technical depth spans internet-facing web applications, cloud-native environments (ideally GCP with Kubernetes), and traditional infrastructures. You’re equally comfortable conducting rapid security checks as you are diving into week-long penetration tests, knowing instinctively which approach fits which scenario.
Your experience in engineering-driven environments where open-source tooling dominates means you understand bol’s build-it-ourselves culture. We leverage existing libraries and frameworks, but most of our solutions are homegrown. Familiarity with our stack (Linux, Tomcat, Java, Spring microservices) is valuable, but more important is your ability to spot what others miss: that overlooked edge case, that subtle flaw, that chained exploit nobody considered. You’re a self-starter who organizes work effectively (Jira, Kanban, Scrum – whatever gets the job done) and views being ‘always available’ as an opportunity to prevent issues, not a burden.
3 reasons why this is (not) for you
Where you'll work
You’ll join our Security Operations team at bol’s Utrecht headquarters, working alongside a fellow ethical hacker and five security engineers who handle defensive systems and incident response. The atmosphere is pragmatic and tech-driven: we love what we do, welcome new ideas, and treat everyone as equals regardless of tenure. We are passionate about security, so expect strong opinions easily dislodged by facts and healthy debates about the best approaches. Our security landscape constantly evolves – there’s always something new demanding attention, which means there’s never a dull moment. We challenge ourselves and each other to find optimal solutions, not perfect ones. Ready to professionally break things before the bad guys do?
Perks of having a blue heart
Flexible working
We bring the best of both worlds together by working 50% at the office and 50% at home. This way, we find a balance between organisational and individual needs.
The culture and the office
Our colleagues work hard to make the daily lives of our customers easier and more fun. But of course, we do this in an inspiring and creative environment!
Travel expenses
Whether you travel by public transport or car, we’ve got you covered with reimbursement and electric car charging facilities.
Bij bol leveren onze collega’s een unieke bijdrage om het dagelijks leven makkelijker te maken. Vrijheid en verantwoordelijkheid zorgen ervoor dat we samen de volgende stap voor bol, het team, en onszelf kunnen vormgeven. Door te pionieren brengen we bol verder, met elkaar zijn wij verantwoordelijk voor deze gezamenlijke missie.
View what's on offer:
Change language to: Dutch
This page is optimised for people from the Netherlands. View the version optimised for people from the UK.