Security Software Engineer (Junior)

Accountancy Gemak

Delft

On-site

EUR 40,000 - 60,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Hybrid working
Pension scheme
Vacation days (27 + 5 loyalty)
Home office setup
Learning & development
Hackathons & Tech Talks

Job summary

Exact zoekt een Security Software Engineer (Junior) voor het Security Operations-team. Je werkt aan beveiligingsengineering, IAM-functionaliteit en tooling die security-issues vroegtijdig detecteren en verhelpen.

Je leert bestaanbare fixes te vertalen naar engineers en werkt aan de shift-left beveiliging binnen SSDLC. Je maakt onderdeel uit van een team van security-minded engineers en werkt met Burp Suite en OWASP ZAP in een hybride werkomgeving met focus op groei en autonomie in Delft HQ en

Qualifications

  • Kennis van software engineering en security fundamentals.
  • Interesse in applicatiebeveiliging en pentest-technieken.
  • Inzicht in threat modeling (STRIDE) en beveiligingsprincipes.

Responsibilities

  • Bijdragen aan het bouwen van beveiligingsgereedschap en playbooks.
  • Uitzoeken van kwetsbaarheden en concrete fixes vanaf de bron uitleggen.
  • Ondersteunen van het security operations-team bij handmatige en geautomatiseerde tests.

Skills

Software engineering
Application security
Threat modeling
Code comprehension
Communication
Team collaboration

Tools

Burp Suite
OWASP ZAP

Job description

Bij Exact zoeken we een Security Software Engineer (Junior) voor het Security Operations-team.

The job

Security Operations is Exact's security engineering team, owning two areas: security across Exact's full product portfolio, and the development of Identity and Access Management (IAM) functionality used across Exact's products. The team builds secure tooling that integrates into engineering teams' existing workflows, bringing a security-first mindset into the development lifecycle (SSDLC). Automation covers what it can; manual, pentest-style testing covers what it can't.

Within the team, you write code across several fronts: building secure tooling and playbooks that make secure software the default, translating findings into concrete low-level fixes, and contributing to the development of Identity and Access Management (IAM) functionality.

  • When deeper investigation is needed, you take part in structured security campaigns: building an inventory of what needs to be checked, ranking findings by risk, investigating the highest-risk areas in depth, and reporting clearly on what was tested, what was found, and what remains open.
  • You help tackle low-level security issues and build tools that prevent insecure software patterns.
  • You help build and improve the team's shift-left security tooling and playbooks.
  • You contribute to the team's recurring scanning and testing program, following up with engineering teams on findings.
Your team

Security Operations is part of Technology, made up of security-minded software engineers who both build and break things: building secure tooling and IAM functionality, and testing systems the way an attacker would to see if they hold up. The team continuously refines its tooling, playbooks, and methods based on what it finds.

Tech stack
  • Exact's core products are primarily built in C#/.NET.
  • Across the wider Exact portfolio you will also encounter other languages, such as C, Python, and PHP — comfort reading unfamiliar code is useful, though you don't need to master every language.
  • The team relies on a combination of automated scanning and dependency tooling, AI-assisted analysis, and manual, pentest-style testing with tools such as Burp Suite or OWASP ZAP.
What you bring
  • A software engineering background (junior to medior level), you've written and shipped real code, ideally in C#/.NET or a comparable ecosystem.
  • Genuine interest in application security and classical penetration-testing techniques: you know your way around the OWASP Top 10 (injection, broken authentication, IDOR, SSRF, and similar) and want to go deeper.
  • A "trace it to the source" mindset: you want to understand not just that something is vulnerable, but why, and how an attacker would actually use it.
  • Basic awareness of threat modeling concepts (e.g., STRIDE) and interest in growing into attack-surface thinking.
  • Comfort reading code across different languages and frameworks.
  • Clear, structured communication: you can explain a technical finding to both an engineer and a non-technical stakeholder.
  • A collaborative, learning attitude: you are supported by senior colleagues and are expected to grow toward more autonomous work over time.
Nice to have (not required)
  • Familiarity with the OWASP Top 10 and OWASP ASVS.
  • CompTIA Security+ or an equivalent foundational security certification.
  • eJPT (eLearnSecurity Junior Penetration Tester) or a similar hands-on/practical entry-level pentest credential.
What you get
  • At Exact, we understand the importance of achieving a healthy balance between effort and relaxation, because it enhances both job satisfaction and well-being.
  • Over 2,000 colleagues worldwide, with technology colleagues across our offices in Delft (HQ), Utrecht, Eindhoven, Zwolle, and our Kuala Lumpur development center.
  • Hybrid working model: 2 days in the office, 3 days working from home.
  • A modern pension scheme.
  • 27 vacation days, plus up to 5 loyalty days (one extra day per full year of employment) and up to 3 "Giving Back" days for a charity of your choice.
  • Home office supplies to support your home working setup.
  • Access to LinkedIn Learning and Exact's own learning & development center to help you grow into this role.
  • Events such as a global hackathon and Tech Talks to develop and showcase your skills.
About Exact

Exact develops cloud software for small and medium-sized companies and their accountants. The products automate business processes in areas such as Finance and HR and provide specific ERP solutions for wholesale distribution, manufacturing, projects and construction. This saves time and provides insight. It enables customers to work efficiently, make informed decisions and continue growing.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Software Engineer (Junior)
Security Software Engineer (Junior)

Exact • Delft

On-site
EUR 60,000 - 90,000
Security Software Engineer (Junior)
Security Software Engineer (Junior)

Exact Software • Delft

Hybrid
EUR 45,000 - 65,000
Hybrid work model (2 dagen kantoor, 3‑
Thuiswerkregeling
Security Software Engineer (Junior)
Security Software Engineer (Junior)

United States Digital Space LLC • Delft

Hybrid
EUR 60,000 - 85,000
Thirteenth month salary
8% holiday allowance
Pension scheme
+5
Security Software Engineer (Junior)
Security Software Engineer (Junior)

Exact Software Germany GmbH • Delft

On-site
EUR 65,000 - 90,000
.NET Software Engineer product teams
.NET Software Engineer product teams

Exact Software • Delft

On-site
EUR 50,000 - 70,000
Competitive Salary
Thirteenth Month
Modern pension scheme
+5
Junior software engineer .NET
Junior software engineer .NET

Accountancy Gemak • Utrecht

Hybrid
EUR 45,000 - 65,000
Competitive salary
Thirteenth month
Pension scheme
+6
Junior software engineer .NET
Junior software engineer .NET

Exact Software • Utrecht

Hybrid
EUR 45,000 - 60,000
Hybrid work model
13th month salary
Pension scheme
+5
System/Cloud Engineer
System/Cloud Engineer

Exact Software • Delft

On-site
EUR 60,000 - 80,000
Competitive salary with 13th month
Flexibility in working hours
Fitness centre
+1
Product Security Engineer II
Product Security Engineer II

United States Digital Space LLC • Amsterdam

Hybrid
EUR 70,000 - 110,000
Health insurance
Daily catered lunches
Pension plan
+2
Security engineer
Security engineer

Axians NL • Capelle aan den IJssel

Hybrid
Salaris tussen de €3.000,- en €5.600
25 vakantiedagen en mogelijkheid om meer dagen op te bouwen
Premievrije pensioenregeling
+8