|
English version below — de Engelse vacaturetekst staat verderop op deze pagina. Je hoeft geen Nederlands te spreken om te solliciteren. Wel geldt: je woont in Nederland en bent EU-/EER-burger of beschikt over een geldige duurzame verblijfs- en werkvergunning. Sollicitaties die hier niet aan voldoen, nemen we niet in behandeling. |
Jij bent de specialist die een onbekende codebase doorgrondt, de werkelijke blootstelling blootlegt én het verhaal helder op tafel legt bij investeerders, bestuurders en juristen. In M&A-context heeft een kwetsbaarheid niet alleen technische gevolgen — die weegt direct mee in de uitkomst van een transactie.
|
Salaris €95.000 – €115.000 |
Ervaring 6 – 12 jaar |
Locatie Utrecht · Hybride |
Uren 32 – 40 uur |
De rol
Als senior security engineer voer je zelfstandig diepgaande, code-guided security-assessments uit voor softwaresystemen in M&A-trajecten en voor organisaties met bedrijfskritische software. Je presenteert je bevindingen niet alleen aan engineeringteams en management, maar ook aan investeerders en juridisch adviseurs — helderheid en impact tellen hier net zo zwaar als technische diepgang.
Je bent daarnaast mede-eigenaar van de securitymethodologie: je bouwt actief mee aan YieldDD's eigen tooling en aanpak, en vertegenwoordigt het bedrijf via techsessies, trainingen en presentaties op events. Dit is een rol met echte breedte binnen een boutique waar jouw naam op het werk staat — geen radertje in een Big4-machine.
Wat ga je doen?
- Zelfstandig uitvoeren van code-guided penetratietests met volledige toegang tot de broncode, in wisselende technologielandschappen per opdracht
- Security-assessments in M&A-due-diligence-trajecten, met rapportages die door kopers, investeerders en W&I-verzekeraars worden gelezen
- Handmatige en geautomatiseerde penetratietests volgens OWASP Top 10, SANS/CWE Top 25, WSTG en MASTG
- Diepgaande reviews van cloudconfiguraties en het duiden van securityrisico's op architectuurniveau
- Leiden van klantdebriefings: bevindingen toelichten aan C-level, investeerders en juristen, en ondersteunen bij herstelmaatregelen
- Mede-ontwikkelen van YieldDD's securitymethodologieën en eigen tooling — als eigenaar, niet als gebruiker
- Begeleiden van medior collega's in hun groei naar het M&A-werk
- Bijdragen aan de marktpositionering via techsessies, trainingen, CTF-events en presentaties
Wat je meebrengt
Must-haves
- 6 tot 12 jaar gecombineerde ervaring in software development en security — een substantieel dev-fundament (bijv. C#/.NET, Java of Python) gevolgd door applicatie- of cloudsecurity
- Aantoonbare ervaring met code-guided of white-box penetratietesten op seniorniveau
- Comfortabel met C-suite delivery: presenteren aan investeerders, bestuurders en juridisch adviseurs
- In staat om snel en zelfstandig een onbekende codebase te doorgronden, ook onder deal-tijdsdruk
- Ervaring met handmatige technieken, geautomatiseerde tooling en moderne (security-)AI-tools
- Rapportages op besluitvormingsniveau: helder, op risico geprioriteerd, leesbaar voor niet-technische stakeholders
- Vloeiend Engels, mondeling en schriftelijk; vloeiend Nederlands is een sterke pre
- Woonachtig in Nederland en EU-/EER-burger, of in het bezit van een geldige duurzame verblijfs- en werkvergunning
Nice-to-haves
- OSWE-certificering of vergelijkbaar advanced niveau
- Ervaring in M&A, due diligence of met PE-backed softwarebedrijven
- Ervaring in sectoren zoals SaaS of financiële dienstverlening
- Zichtbaarheid in de security-community (talks, publicaties, CTF's)
Salaris & transparantie
Deze rol kent een salarisrange van €95.000 tot €115.000 bruto per jaar op fulltime basis. Voor profielen met OSWE-certificering én aantoonbare M&A-ervaring is ruimte tot €120.000. Deze band is gepositioneerd boven de brede seniormarkt voor penetration testers (VigIT Cybersecurity Salarisbenchmark 2026), omdat deze rol meer vraagt dan pentesten: C-suite delivery, methodologie-eigenaarschap en M&A-context rechtvaardigen een premie — en die betalen we dus ook.
Wat wij bieden
- Medewerkersparticipatie: YieldDD zet momenteel een employee participation programma op — equity-upside in een groeiende boutique, waar de Big4 alleen cash biedt. De contouren bespreek je in het proces
- Methodologie-eigenaarschap: jouw handtekening onder de aanpak en tooling waarmee YieldDD zich onderscheidt
- Directe deal-exposure: wisselende technologielandschappen, geen compliance-loop
- Budget voor training, certificeringen en persoonlijke ontwikkeling, met actieve ondersteuning bij specialisatie
- Laptop en tooling naar keuze
- Premievrij pensioen met nabestaandenpensioen, 25 vakantiedagen en hybride werken met focusdagen thuis
- Een gloednieuw kantoor in de Houtfabriek op Campus Werkspoor (Utrecht): volledig duurzaam hout, restaurant, gym en binnenkort padelbanen
Over YieldDD
YieldDD is specialist in software due diligence en cybersecurity voor M&A-transacties, private equity-investeerders en organisaties met bedrijfskritische software. Onderdeel van de Betabit Group, met een track record van circa 20% groei per jaar — vijf jaar op rij, dwars door macro-tegenwind heen. Het team van 11 specialisten werkt vanuit Utrecht samen met toonaangevende PE-partijen, M&A-adviseurs en technologiebedrijven in de Benelux en Europa. Directheid, diepgang en eigenaarschap zijn hier geen wandtegeltjes maar werkwijze: elke aanstelling is 9% van de organisatie, en dat voel je in hoe serieus selectie én onboarding worden genomen.
Het proces
Kennismakingsgesprek → technisch assessment of opdracht → eindgesprek → aanbod. Verwachte doorlooptijd: twee tot drie weken. Het assessment toetst op feitelijke vaardigheid — jouw code review-diepte en delivery-kwaliteit, niet je interview-handigheid.
Deze search wordt exclusief en vertrouwelijk uitgevoerd door VigIT People. Ook interessant voor kandidaten die momenteel bij een Big4 of pentest-boutique zitten en toe zijn aan eigenaarschap in plaats van uurtjes schrijven. Ref.nr. YDD-2026-SEC-B
|
English version — Senior Security Engineer, M&A Tech Due Diligence You do not need to speak Dutch to apply. You must, however, be living in the Netherlands and be an EU/EEA citizen or hold a valid long-term residence and work permit. Applications that do not meet this requirement will not be processed. Visa sponsorship is not available. |
You are the specialist who works through an unfamiliar codebase, uncovers the real exposure — and then puts the story clearly on the table for investors, board members and lawyers. In an M&A context a vulnerability is never just technical: it weighs directly on the outcome of a transaction.
|
Salary €95,000 – €115,000 |
Experience 6 – 12 years |
Location Utrecht · Hybrid |
Hours 32 – 40 hrs |
The role
As a senior security engineer you independently carry out in-depth, code-guided security assessments of software systems in M&A processes and for organisations running business-critical software. You present your findings not only to engineering teams and management, but also to investors and legal advisors — clarity and impact count as much as technical depth here.
You are also a co-owner of the security methodology: you actively help build YieldDD's proprietary tooling and approach, and represent the firm through tech sessions, training and event presentations. This is a role with genuine breadth in a boutique where your name is on the work — not a cog in a Big4 machine.
What you will do
- Independently perform code-guided penetration tests with full source-code access, across a different technology landscape per engagement
- Security assessments in M&A due-diligence processes, producing reports read by buyers, investors and W&I underwriters
- Manual and automated penetration testing following OWASP Top 10, SANS/CWE Top 25, WSTG and MASTG
- In-depth cloud configuration reviews and interpreting security risk at architecture level
- Leading client debriefings: explaining findings to C-level, investors and lawyers, and supporting remediation
- Co-developing YieldDD's security methodologies and proprietary tooling — as an owner, not a user
- Coaching medior colleagues in their growth towards M&A work
- Contributing to market positioning through tech sessions, training, CTF events and presentations
What you bring
Must-haves
- 6 to 12 years of combined experience in software development and security — a substantial development foundation (e.g. C#/.NET, Java or Python) followed by application or cloud security
- Demonstrable senior-level experience with code-guided or white-box penetration testing
- Comfortable with C-suite delivery: presenting to investors, board members and legal advisors
- Able to quickly and independently work through an unfamiliar codebase, including under deal pressure
- Experience with manual techniques, automated tooling and modern (security) AI tools
- Decision-grade reporting: clear, risk-prioritised, readable for non-technical stakeholders
- Fluent English, spoken and written; fluent Dutch is a strong plus
- Resident in the Netherlands and an EU/EEA citizen, or holding a valid long-term residence and work permit
Nice-to-haves
- OSWE certification or a comparable advanced level
- Experience in M&A, due diligence or with PE-backed software companies
- Experience in sectors such as SaaS or financial services
- Visibility in the security community (talks, publications, CTFs)
Salary & transparency
This role carries a salary range of €95,000 to €115,000 gross per year on a full-time basis. For profiles combining OSWE certification with demonstrable M&A experience there is room up to €120,000. This band sits above the broad Dutch senior market for penetration testers (VigIT Cybersecurity Salary Benchmark 2026), because the role asks for more than pentesting: C-suite delivery, methodology ownership and M&A context justify a premium — and we pay it.
What we offer
- Employee participation: YieldDD is currently setting up an employee participation programme — equity upside in a growing boutique, where the Big4 offer cash only. You will discuss the outline during the process
- Methodology ownership: your signature on the approach and tooling that set YieldDD apart
- Direct deal exposure: a different technology landscape per engagement, no compliance treadmill
- Budget for training, certifications and personal development, with active support for specialisation
- Laptop and tooling of your choice
- Non-contributory pension including survivor's pension, 25 days of annual leave and hybrid working with focus days at home
- A brand-new office in the Houtfabriek at Campus Werkspoor (Utrecht): fully sustainable timber construction, restaurant, gym and padel courts coming soon
About YieldDD
YieldDD specialises in software due diligence and cybersecurity for M&A transactions, private equity investors and organisations running business-critical software. Part of the Betabit Group, with a track record of roughly 20% year-on-year growth — five years in a row, straight through macro headwinds. The team of 11 specialists works from Utrecht with leading PE firms, M&A advisors and technology companies across the Benelux and Europe. Directness, depth and ownership are not wall tiles here but a way of working: every hire equals 9% of the organisation, and you can tell by how seriously both selection and onboarding are taken.
The process
Introductory meeting → technical assessment or assignment → final interview → offer. Expected lead time: two to three weeks. The assessment tests actual skill — your code-review depth and delivery quality, not interview polish.
This search is conducted exclusively and confidentially by VigIT People. Also relevant for candidates currently at a Big4 or pentest boutique who are ready for ownership instead of writing billable hours. Ref. no. YDD-2026-SEC-B