Security Software Engineer (Junior)
Exact · Delft, Netherlands
You apply on the site where the job is posted. I never handle applications.
Netherlands, Delft Technology Netherlands
This = the job
Security Operations is Exact's security engineering team, owning two areas: security across Exact's full product portfolio, and the development of Identity and Access Management (IAM) functionality used across Exact's products. The team builds secure tooling that integrates into engineering teams' existing workflows, bringing a security-first mindset into the development lifecycle (SSDLC). Automation covers what it can; manual, pentest-style testing covers what it can't.
This = the job that you aspire to
Within the team, you write code across several fronts: building secure tooling and playbooks that make secure software the default, translating findings into concrete low-level fixes, and contributing to the development of Identity and Access Management (IAM) functionality.
- When deeper investigation is needed, you take part in structured security campaigns: building an inventory of what needs to be checked, ranking findings by risk, investigating the highest-risk areas in depth, and reporting clearly on what was tested, what was found, and what remains open.
- You help tackle low-level security issues and build tools that prevent insecure software patterns.
- You help build and improve the team's shift-left security tooling and playbooks.
- You contribute to the team's recurring scanning and testing program, following up with engineering teams on findings.
This = your team
Security Operations is part of Technology, made up of security-minded software engineers who both build and break things: building secure tooling and IAM functionality, and testing systems the way an attacker would to see if they hold up. The team continuously refines its tooling, playbooks, and methods based on what it finds.
This = our tech stack
- Exact's core products are primarily built in C#/.NET.
- Across the wider Exact portfolio you will also encounter other languages, such as C, Python, and PHP — comfort reading unfamiliar code is useful, though you don't need to master every language. The team relies on a combination of automated scanning and dependency tooling, AI-assisted analysis, and manual, pentest-style testing with tools such as Burp Suite or OWASP ZAP.
This = what you bring
- A software engineering background (junior to medior level), you've written and shipped real code, ideally in C#/.NET or a comparable ecosystem.
- Genuine interest in application security and classical penetration-testing techniques: you know your way around the OWASP Top 10 (injection, broken authentication, IDOR, SSRF, and similar) and want to go deeper.
- A "trace it to the source" mindset: you want to understand not just that something is vulnerable, but why, and how an attacker would actually use it.
- Basic awareness of threat modeling concepts (e.g., STRIDE) and interest in growing into attack-surface thinking.
- Comfort reading code across different languages and frameworks.
- Clear, structured communication: you can explain a technical finding to both an engineer and a non-technical stakeholder.
- A collaborative, learning attitude: you are supported by senior colleagues and are expected to grow toward more autonomous work over time.
Nice to have (not required):
- Familiarity with the OWASP Top 10 and OWASP ASVS.
- CompTIA Security+ or an equivalent foundational security certification.
- eJPT (eLearnSecurity Junior Penetration Tester) or a similar hands-on/practical entry-level pentest credential.
This = what you bring
- A software engineering background (junior to medior level), you've written and shipped real code, ideally in C#/.NET or a comparable ecosystem.
- Genuine interest in application security and classical penetration-testing techniques: you know your way around the OWASP Top 10 (injection, broken authentication, IDOR, SSRF, and similar) and want to go deeper.
- A "trace it to the source" mindset: you want to understand not just that something is vulnerable, but why, and how an attacker would actually use it.
- Basic awareness of threat modeling concepts (e.g., STRIDE) and interest in growing into attack-surface thinking.
- Comfort reading code across different languages and frameworks.
- Clear, structured communication: you can explain a technical finding to both an engineer and a non-technical stakeholder.
- A collaborative, learning attitude: you are supported by senior colleagues and are expected to grow toward more autonomous work over time.
Nice to have (not required):
- Familiarity with the OWASP Top 10 and OWASP ASVS.
- CompTIA Security+ or an equivalent foundational security certification.
- eJPT (eLearnSecurity Junior Penetration Tester) or a similar hands-on/practical entry-level pentest credential.
This = what you get
- At Exact, we understand the importance of achieving a healthy balance between effort and relaxation, because it enhances both job satisfaction and well-being.
- Over 2,000 colleagues worldwide, with technology colleagues across our offices in Delft (HQ), Utrecht, Eindhoven, Zwolle, and our Kuala Lumpur development center.
- A 40-hour workweek on a permanent (indefinite) contract.
- Hybrid working model: 2 days in the office, 3 days working from home.
- Competitive salary, a thirteenth month, and 8% holiday allowance.
- A modern pension scheme.
- 27 vacation days, plus up to 5 loyalty days (one extra day per full year of employment) and up to 3 "Giving Back" days for a charity of your choice.
- Home office supplies to support your home working setup.
- Access to LinkedIn Learning and Exact's own learning & development center to help you grow into this role.
- Events such as a global hackathon and Tech Talks to develop and showcase your skills.
About Exact
Exact develops cloud software for small and medium-sized companies and their accountants. The products automate business processes in areas such as Finance and HR and provide specific ERP solutions for wholesale distribution, manufacturing, projects and construction. This saves time and provides insight. It enables customers to work efficiently, make informed decisions and continue growing. More than 675,000 companies primarily in the Netherlands, Belgium and Germany already rely on Exact's software. Exact was founded in 1984 in Delft, the Netherlands, which is still the location of our head office. Every day, more than 2,000 ambitious professionals work on innovation. Driving responsible business, with respect for each other, the environment and society is central to this. For more information, visit www.exact.com.
Ready to Join Us?
We're excited to hear from you.
After you apply, one of our Talent Acquisition Specialists will contact you to answer any questions and discuss your experience and ambitions. The selection process typically includes:
1. An introductory conversation.
2. A coding challenge.
3. A technical and team interview.
4. Offer stage
If there's a match on both sides, we'll be delighted to welcome you to the Fiscal Accountancy Engineering team.
Vragen?
Contact Jan Willem van der Most
Call +31 15 711 5100 Call + 31 630 35 18 04 E-mail jan.willem.van.der.most@exact.com