Junior Security Engineer

Exact Software

Delft

Hybrid

EUR 42,000 - 54,000

Full time

4 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Hybrid work model
27 vacation days
5 loyalty days
Giving Back days
Home office setup
Learning & development access

Job summary

Exact Software Delft is seeking a Junior Security Engineer to help secure our software suite. You will write code to build secure tooling, contribute to IAM features, and participate in security campaigns to identify and fix high‑risk areas.

You'll gain hands-on experience with Burp Suite and OWASP ZAP, learn from senior engineers, and grow toward more autonomous work within a security‑minded team.

Qualifications

  • Software engineering background with real code experience.
  • Understanding of OWASP Top 10 and pentest mindset.
  • Ability to trace vulnerabilities to root cause.

Responsibilities

  • Write code to build secure tooling and IAM functionality.
  • Participate in structured security campaigns and risk ranking.
  • Tackle low-level security issues and build secure patterns.

Skills

C#/.NET
Software engineering
OWASP Top 10
Threat modeling
Communication
Code reading

Tools

Burp Suite
OWASP ZAP

Job description

Junior Security Engineer

Starters
Netherlands, DelftDevelopmentNetherlands

This = the job

Security Operations is Exact's security engineering team, owning two areas: security across Exact's full product portfolio, and the development of Identity and Access Management (IAM) functionality used across Exact's products. The team builds secure tooling that integrates into engineering teams' existing workflows, bringing a security-first mindset into the development lifecycle (SSDLC). Automation covers what it can; manual, pentest-style testing covers what it can't.

This = the job that you aspire to
  • Within the team, you write code across several fronts: building secure tooling and playbooks that make secure software the default, translating findings into concrete low-level fixes, and contributing to the development of Identity and Access Management (IAM) functionality.
  • When deeper investigation is needed, you take part in structured security campaigns: building an inventory of what needs to be checked, ranking findings by risk, investigating the highest-risk areas in depth, and reporting clearly on what was tested, what was found, and what remains open.
  • You help tackle low-level security issues and build tools that prevent insecure software patterns.
  • You help build and improve the team's shift-left security tooling and playbooks.
  • You contribute to the team's recurring scanning and testing program, following up with engineering teams on findings.
This = your team

Security Operations is part of Technology, made up of security-minded software engineers who both build and break things: building secure tooling and IAM functionality, and testing systems the way an attacker would to see if they hold up. The team continuously refines its tooling, playbooks, and methods based on what it finds.

This = our tech stack

Exact's core products are primarily built in C#/.NET. Across the wider Exact portfolio you will also encounter other languages, such as C, Python, and PHP — comfort reading unfamiliar code is useful, though you don't need to master every language. The team relies on a combination of automated scanning and dependency tooling, AI-assisted analysis, and manual, pentest-style testing with tools such as Burp Suite or OWASP ZAP.

This = what you bring
  • A software engineering background (junior to medior level), you've written and shipped real code, ideally in C#/.NET or a comparable ecosystem.
  • Genuine interest in application security and classical penetration-testing techniques: you know your way around the OWASP Top 10 (injection, broken authentication, IDOR, SSRF, and similar) and want to go deeper.
  • A "trace it to the source" mindset: you want to understand not just that something is vulnerable, but why, and how an attacker would actually use it.
  • Basic awareness of threat modeling concepts (e.g., STRIDE) and interest in growing into attack-surface thinking.
  • Comfort reading code across different languages and frameworks.
  • Clear, structured communication: you can explain a technical finding to both an engineer and a non-technical stakeholder.
  • A collaborative, learning attitude: you are supported by senior colleagues and are expected to grow toward more autonomous work over time.

Nice to have (not required):

  • Familiarity with the OWASP Top 10 and OWASP ASVS.
  • CompTIA Security+ or an equivalent foundational security certification.
  • eJPT (eLearnSecurity Junior Penetration Tester) or a similar hands-on/practical entry-level pentest credential.
This = what you get
  • At Exact, we understand the importance of achieving a healthy balance between effort and relaxation, because it enhances both job satisfaction and well-being.
  • Over 2,000 colleagues worldwide, with technology colleagues across our offices in Delft (HQ), Utrecht, Eindhoven, Zwolle, and our Kuala Lumpur development center.
  • A 40-hour workweek on a permanent (indefinite) contract.
  • Hybrid working model: 2 days in the office, 3 days working from home.
  • Competitive salary, a thirteenth month, and 8% holiday allowance.
  • A modern pension scheme.
  • 27 vacation days, plus up to 5 loyalty days (one extra day per full year of employment) and up to 3 "Giving Back" days for a charity of your choice.
  • Home office supplies to support your home working setup.
  • Access to LinkedIn Learning and Exact's own learning & development center to help you grow into this role.
  • Events such as a global hackathon and Tech Talks to develop and showcase your skills.
About Exact

Exact develops cloud software for small and medium-sized companies and their accountants. The products automate business processes in areas such as Finance and HR and provide specific ERP solutions for wholesale distribution, manufacturing, projects and construction.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Junior Security Engineer
Junior Security Engineer

Accountancy Gemak • Delft

On-site
EUR 42,000 - 52,000
Thirteenth month
Holiday allowance 8%
Pension scheme
+6
Security Software Engineer (Junior)
Security Software Engineer (Junior)

Exact • Delft

On-site
EUR 60,000 - 90,000
.NET Software Engineer product teams
.NET Software Engineer product teams

Exact Software • Delft

On-site
EUR 50,000 - 70,000
Competitive Salary
Thirteenth Month
Modern pension scheme
+5
PHP Software Engineer
PHP Software Engineer

Exact Software • Delft

On-site
EUR 45,000 - 65,000
Access to LinkedIn Learning
Competitive compensation
Training sessions
+1
System/Cloud Engineer
System/Cloud Engineer

Exact Software • Delft

On-site
EUR 60,000 - 80,000
Competitive salary with 13th month
Flexibility in working hours
Fitness centre
+1
Security Engineer
Security Engineer

Software Search • Netherlands

Hybrid
EUR 100,000 - 123,000
Permanent contract
Training budget and security community
Software Engineering Team Lead
Software Engineering Team Lead

Exact • Delft

Hybrid
EUR 70,000 - 90,000
13th month
Pension
Permanent contract
+5
PHP Back-end Engineer
PHP Back-end Engineer

Exact Software • Delft

On-site
EUR 55,000 - 75,000
Competitive salary
27 vacation days with an extra day for each year worked
3 Giving back days for charity volunteering
+4
Technical writer
Technical writer

Exact • Delft

Hybrid
One-year employment contract with a prospect for a permanent contract
Salary range €2800 - €4200 gross
13th month salary and 8% holiday allowance
+3
Microsoft Infrastructure & Cloud Engineer
Microsoft Infrastructure & Cloud Engineer

Exact • Utrecht

Hybrid
EUR 65,000 - 90,000
13th month salary
8% holiday allowance
Hybrid work environment
+1