|
English version below — de Engelse vacaturetekst staat verderop op deze pagina. Je hoeft geen Nederlands te spreken om te solliciteren. Wel geldt: je woont in Nederland en bent EU-/EER-burger of beschikt over een geldige duurzame verblijfs- en werkvergunning. Sollicitaties die hier niet aan voldoen, nemen we niet in behandeling. |
Je vindt wat anderen missen en vertaalt het naar inzichten die aanzetten tot actie. Bij YieldDD is security geen vinkje, maar een materiële risicofactor en een hefboom voor waarde — ook in M&A-transacties waar jouw bevindingen direct meewegen in de uitkomst van een deal.
|
Salaris €65.000 – €82.000 |
Ervaring 3 – 6 jaar |
Locatie Utrecht · Hybride |
Uren 32 – 40 uur |
De rol
Als medior security engineer voer je diepgaande security-assessments uit voor een brede groep klanten: van scale-ups en middelgrote bedrijven tot organisaties met bedrijfskritische software. Je werk gaat verder dan geautomatiseerde scans — je denkt als een aanvaller, kijkt in de broncode en bouwt een compleet beeld van de werkelijke blootstelling.
Je werkt onder begeleiding van ervaren specialisten en groeit binnen 12 tot 24 maanden gestructureerd door naar het M&A-due-diligence-werk: assessments waarbij investeerders en juridisch adviseurs aan tafel zitten. Dat groeipad is expliciet onderdeel van deze rol — je start met wat je kunt en bouwt aantoonbaar door naar waar je naartoe wilt.
Wat ga je doen?
- Uitvoeren van code-guided penetratietests met volledige toegang tot de broncode — dieper dan een black-boxaanpak
- Handmatige en geautomatiseerde penetratietests op applicaties, API's en interne systemen, volgens OWASP Top 10, SANS/CWE Top 25, WSTG en MASTG
- Reviews van cloudconfiguraties en het identificeren van securityrisico's in cloudomgevingen
- Periodieke vulnerability assessments om nieuwe risico's te identificeren en te prioriteren
- Toepassen van SAST- en DAST-tools en de resultaten kritisch interpreteren, voorbij wat tooling zelf laat zien
- Bevindingen vertalen naar heldere, op risico geprioriteerde rapportages voor softwareontwikkelteams en management
- Deelnemen aan klantdebriefings samen met een senior collega, met een groeipad naar zelfstandige delivery
- Bijdragen aan de doorontwikkeling van YieldDD's securitymethodologieën en eigen tooling
Wat je meebrengt
Must-haves
- 3 tot 6 jaar ervaring met security assessments en penetratietesten
- Ervaring met of aantoonbare affiniteit met code-guided of white-box penetratietesten
- In staat om zelfstandig een onbekende codebase te doorgronden, ook onder tijdsdruk
- Ervaring met zowel handmatige technieken als geautomatiseerde tooling, inclusief moderne (security-)AI-tools
- Ervaring met meerdere programmeertalen
- Heldere schriftelijke en mondelinge communicatie: je rapportages zijn geschikt voor besluitvorming, ook voor niet-technische lezers
- Vloeiend Engels, mondeling en schriftelijk; vloeiend Nederlands is een sterke pre
- Woonachtig in Nederland en EU-/EER-burger, of in het bezit van een geldige duurzame verblijfs- en werkvergunning
Nice-to-haves
- OSCP-certificering, of OSWE in progress — YieldDD ondersteunt het OSWE-traject actief met budget en tijd
- Ervaring met C#, Python of een vergelijkbaar dev-fundament
- Kennis van secure coding practices en veelvoorkomende development anti-patterns
- Affiniteit met M&A-context, due diligence of PE-backed softwarebedrijven
Salaris & transparantie
Deze rol kent een salarisrange van €65.000 tot €82.000 bruto per jaar op fulltime basis, afhankelijk van ervaring en certificering. Deze range is gepositioneerd in het midden van de Nederlandse markt voor penetration testers met 3 tot 6 jaar ervaring (VigIT Cybersecurity Salarisbenchmark 2026) — geen ondergrens-lokkertje, maar een reële band waarbinnen je aanbod valt.
Wat wij bieden
- Een gestructureerd groeipad naar M&A-due-diligence-werk, met begeleiding van identificeerbare technische seniors
- Budget voor training en certificeringen, met actieve ondersteuning van het OSCP/OSWE-traject
- Laptop en tooling naar keuze — en de kans om mee te bouwen aan YieldDD's eigen methodologie en tooling
- Premievrij pensioen met nabestaandenpensioen
- 25 vakantiedagen en hybride werken: focusdagen thuis, samenwerkingsdagen op kantoor
- Interne kennissessies en CTF-events waar je zelf aan meebouwt
- Een gloednieuw kantoor in de Houtfabriek op Campus Werkspoor (Utrecht): volledig duurzaam hout, restaurant, gym en binnenkort padelbanen
Over YieldDD
YieldDD is specialist in software due diligence en cybersecurity voor M&A-transacties, private equity-investeerders en organisaties met bedrijfskritische software. Vanuit Utrecht werkt het compacte team van specialisten samen met toonaangevende PE-partijen, M&A-adviseurs en technologiebedrijven in de Benelux en Europa. Security draait hier niet om het draaien van scans, maar om begrijpen wat er echt op het spel staat. Met 11 specialisten telt elke aanstelling — en telt elke collega.
Het proces
Kennismakingsgesprek → technisch assessment of opdracht → eindgesprek → aanbod. Verwachte doorlooptijd: twee tot drie weken. Het assessment toetst op feitelijke vaardigheid, niet op interview-handigheid.
Deze search wordt exclusief uitgevoerd door VigIT People. Twijfel je of dit profiel bij je past, of zit je qua ervaring net boven deze band? Neem vertrouwelijk contact op — er staat ook een senior variant van deze rol open. Ref.nr. YDD-2026-SEC-A
|
English version — Security Engineer, Application Security & M&A Tech-DD (Medior) You do not need to speak Dutch to apply. You must, however, be living in the Netherlands and be an EU/EEA citizen or hold a valid long-term residence and work permit. Applications that do not meet this requirement will not be processed. Visa sponsorship is not available. |
You find what others miss and translate it into insights that drive action. At YieldDD, security is not a checkbox — it is a material risk factor and a lever for value, including in M&A transactions where your findings weigh directly on the outcome of a deal.
|
Salary €65,000 – €82,000 |
Experience 3 – 6 years |
Location Utrecht · Hybrid |
Hours 32 – 40 hrs |
The role
As a medior security engineer you carry out in-depth security assessments for a broad client base: from scale-ups and mid-sized companies to organisations running business-critical software. Your work goes well beyond automated scans — you think like an attacker, read the source code and build a complete picture of the real exposure.
You work under the guidance of experienced specialists and grow, within 12 to 24 months, into the M&A due-diligence practice: assessments where investors and legal advisors sit at the table. That growth path is an explicit part of this role — you start with what you can do today and build demonstrably towards where you want to be.
What you will do
- Perform code-guided penetration tests with full access to the source code — going deeper than a black-box approach
- Run manual and automated penetration tests on applications, APIs and internal systems, following OWASP Top 10, SANS/CWE Top 25, WSTG and MASTG
- Review cloud configurations and identify security risks in cloud environments
- Conduct periodic vulnerability assessments to identify and prioritise new risks
- Apply SAST and DAST tooling and critically interpret the results, beyond what the tooling itself shows
- Translate findings into clear, risk-prioritised reports for software development teams and management
- Join client debriefings alongside a senior colleague, with a growth path towards independent delivery
- Contribute to the further development of YieldDD's security methodologies and proprietary tooling
What you bring
Must-haves
- 3 to 6 years of experience with security assessments and penetration testing
- Experience with, or demonstrable affinity for, code-guided or white-box penetration testing
- Able to independently work your way through an unfamiliar codebase, including under time pressure
- Experience with both manual techniques and automated tooling, including modern (security) AI tools
- Experience with multiple programming languages
- Clear written and verbal communication: your reports support decision-making, also for non-technical readers
- Fluent English, spoken and written; fluent Dutch is a strong plus
- Resident in the Netherlands and an EU/EEA citizen, or holding a valid long-term residence and work permit
Nice-to-haves
- OSCP certification, or OSWE in progress — YieldDD actively supports the OSWE track with budget and time
- Experience with C#, Python or a comparable development foundation
- Knowledge of secure coding practices and common development anti-patterns
- Affinity with M&A, due diligence or PE-backed software companies
Salary & transparency
This role carries a salary range of €65,000 to €82,000 gross per year on a full-time basis, depending on experience and certification. The range is positioned in the middle of the Dutch market for penetration testers with 3 to 6 years of experience (VigIT Cybersecurity Salary Benchmark 2026) — not a teaser floor, but a realistic band your offer will actually fall within.
What we offer
- A structured growth path into M&A due-diligence work, guided by identifiable technical seniors
- Budget for training and certifications, with active support for the OSCP/OSWE track
- Laptop and tooling of your choice — plus the opportunity to co-build YieldDD's own methodology and tooling
- Non-contributory pension including survivor's pension
- 25 days of annual leave and hybrid working: focus days at home, collaboration days at the office
- Internal knowledge sessions and CTF events you help build yourself
- A brand-new office in the Houtfabriek at Campus Werkspoor (Utrecht): fully sustainable timber construction, restaurant, gym and padel courts coming soon
About YieldDD
YieldDD specialises in software due diligence and cybersecurity for M&A transactions, private equity investors and organisations running business-critical software. From Utrecht, the compact team of specialists works with leading PE firms, M&A advisors and technology companies across the Benelux and Europe. Security here is not about running scans — it is about understanding what is genuinely at stake. With 11 specialists, every hire counts, and so does every colleague.
The process
Introductory meeting → technical assessment or assignment → final interview → offer. Expected lead time: two to three weeks. The assessment tests actual skill, not interview polish.
This search is conducted exclusively by VigIT People. Not sure whether this profile fits, or is your experience just above this band? Get in touch confidentially — a senior variant of this role is also open. Ref. no. YDD-2026-SEC-A