Security Engineer

Yielddd

Utrecht

Hybrid

EUR 65,000 - 100,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

25 vacation days
Laptop provided
Hybrid work
Pension plan
Training budget and certifications
Office Utrecht Campus Werkspoor
Broad role with growth
Certifications support

Job summary

YieldDD is seeking a security assessment specialist to perform in-depth, code-guided penetration testing across client environments, including applications, APIs, and internal systems. You will combine manual and automated techniques to uncover real exposure beyond automated scans.

You will present findings to engineering teams and management, and contribute to the evolution of YieldDD's methodologies and tooling. Fluent Dutch and English are required, with hybrid work from Utrecht.

Qualifications

  • At least 3 years of experience in security assessments and penetration testing.
  • Proven experience with code-guided or white-box penetration testing.
  • Able to navigate an unfamiliar codebase quickly and independently under time pressure.
  • Knowledge of commonly used security AI tooling.
  • Proficiency in both manual techniques and automated tooling.
  • Experience with multiple programming languages.
  • Strong written and verbal communication skills for non-technical readers.
  • Fluency in Dutch and English, spoken and written.

Responsibilities

  • Execute code-guided penetration tests with full source code access.
  • Perform manual and automated penetration tests across apps, APIs and internal systems.
  • Conduct in-depth cloud configuration reviews and identify risks.
  • Perform recurring vulnerability assessments to prioritize exposures over time.
  • Apply SAST and DAST tooling and interpret results beyond tooling output.
  • Translate findings into risk-prioritized reports for engineers and leadership.
  • Participate in client debriefings to discuss findings and remediation decisions.
  • Contribute to YieldDD's security methodologies and tooling.
  • Share knowledge through tech sessions, training, and events.

Skills

Code-guided pentesting
White-box testing
Security assessments
Manual & automated testing
Programming languages
Technical reporting
Dutch & English fluency

Job description

The role

You carry out in-depth security assessments across a broad range of clients, from scale-ups and mid-market companies to enterprise organizations with business-critical software, as well as software systems in M&A processes. Your work goes beyond automated scans. You think like an attacker, look into the source code, and build a complete picture of real exposure.

Your findings are presented to engineering teams, management, and – where relevant – investors and legal advisors. Clarity and impact matter just as much as technical depth.

What will you do?
  • Execute code-guided penetration tests with full source code access, going deeper than any black-box approach can
  • Perform manual and automated penetration tests across applications, APIs and internal systems, following established methodologies including OWASP Top 10, SANS/CWE Top 25, WSTG and MASTG
  • Conduct in-depth cloud configuration reviews and identify security risks in cloud environments
  • Perform recurring vulnerability assessments to identify and prioritize new exposures over time
  • Apply SAST and DAST tooling and critically interpret results beyond what the tooling surfaces
  • Translate findings into clear, risk-prioritized reports for engineering teams, boards and investors
  • Participate in client debriefings to walk through findings, answer questions and support remediation decisions
  • Contribute to the ongoing development of YieldDD's security methodologies and tooling, working with a combination of established industry tools and tooling developed in-house
  • Contribute to YieldDD's positioning by sharing knowledge through tech sessions, training and speaking at industry events
What you bring

Must-haves

  • At least 3 years of experience in security assessments and penetration testing
  • Proven experience with code-guided or white-box penetration testing specifically
  • Able to navigate an unfamiliar codebase quickly and independently under time pressure
  • Knowledge of commonly used (security) AI tooling
  • Proficiency in both manual techniques and automated tooling
  • Experience with multiple programming languages
  • Strong written and verbal communication skills: your reports are clear and decision-ready for non-technical readers
  • Fluency in Dutch and English, spoken and written

Nice-to-haves

  • OSWE certification or equivalent
  • Experience with C# or Python
  • Knowledge of secure coding practices and common development anti-patterns
  • Affinity with M&A context or due diligence
  • Experience in sectors such as SaaS, financial services or PE-backed software companies
What we offer
  • 25 vacation days
  • Laptop and tooling of your choice
  • Hybrid working: focus days from home, collaborative days at the office
  • Premium-free pension plan with survivors’ pension
  • Budget for training, certifications and personal development
  • A brand-new office in the Houtfabriek at Campus Werkspoor, a fully sustainable timber building that opened inApril 2026. The campus has a restaurant and gym, and padel courts are planned for later this year
  • A role with genuine breadth: as part of a growing firm, you will contribute to more than just your own specialty
  • Active support for certifications and specialization
About YieldDD

YieldDD is the specialist in software due diligence and cyber security for M&A transactions, private equity investors, and organizations with business-critical software. From our office in Utrecht (Campus Werkspoor), we work with leading PE firms, M&A advisors, and technology companies across the Benelux and Europe.

We are a lean team of specialists who value directness, depth, and genuine ownership. Security at YieldDD is not about running scans; it is about understanding what is really at stake.

How the process works
  1. Send your CV and a short motivation
  2. Introductory meeting
  3. Assignment or technical assessment
  4. Closing interview
  5. Offer

Expected timeline: two to three weeks

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

AI Engineer
AI Engineer

Yielddd • Utrecht

Hybrid
EUR 70,000 - 100,000
25 vacation days
Hybrid work
Pension plan
+2
Senior Security & Assessments Sales Consultant
Senior Security & Assessments Sales Consultant

Yielddd • Netherlands

On-site
Code-Guided Security Engineer — Hybrid
Code-Guided Security Engineer — Hybrid

Yielddd • Utrecht

Hybrid
EUR 65,000 - 100,000
25 vacation days
Laptop provided
Hybrid work
+5
New Business Developer
New Business Developer

DEFION • Netherlands

Hybrid
EUR 60,000 - 90,000
Lease car
Laptop
Phone
+2
Cyber Security (Senior) Consultant & Manager, Technology Consulting, Amsterdam
Cyber Security (Senior) Consultant & Manager, Technology Consulting, Amsterdam

Gryphon Search • Amsterdam

Hybrid
EUR 70,000 - 90,000
Room for development
Challenging projects
Global network
Security Consultant
Security Consultant

Software Search • Netherlands

Hybrid
EUR 102,000 - 122,000
Permanent contract
Project variety and autonomy
Competitive compensation
+4
Junior Security Engineer
Junior Security Engineer

Accountancy Gemak • Delft

On-site
EUR 42,000 - 52,000
Thirteenth month
Holiday allowance 8%
Pension scheme
+6
Senior Security Specialist
Senior Security Specialist

DEFION • Netherlands

Hybrid
EUR 70,000 - 110,000
Permanent contract after probation
Mobility budget or lease car
High-end laptop and phone
+1
Junior Security Engineer
Junior Security Engineer

Exact Software • Delft

Hybrid
EUR 42,000 - 54,000
Hybrid work model
27 vacation days
5 loyalty days
+3
IT Security Lead
IT Security Lead

NUNC Capital • Amsterdam

Hybrid
EUR 56,000 - 67,000
Gross monthly salary €5,000–€6,000
8% holiday allowance
25 vacation days
+5