This = the job Security Operations is Exact's security engineering team, owning two areas: security across Exact's full product portfolio, and the development of Identity and Access Management (IAM) functionality used across Exact's products. The team builds secure tooling that integrates into engineering teams' existing workflows, bringing a security-first mindset into the development lifecycle (SSDLC). Automation covers what it can; manual, pentest-style testing covers what it can't.This = the job that you aspire to Within the team, you write code across several fronts: building secure tooling and playbooks that make secure software the default, translating findings into concrete low-level fixes, and contributing to the development of Identity and Access Management (IAM) functionality. When deeper investigation is needed, you take part in structured security campaigns: building an inventory of what needs to be checked, ranking findings by risk, investigating the highest-risk areas in depth, and reporting clearly on what was tested, what was found, and what remains open. You help tackle low-level security issues and build tools that prevent insecure software patterns. You help build and improve the team's shift-left security tooling and playbooks. You contribute to the team's recurring scanning and testing program, following up with engineering teams on findings. This = your team Security Operations is part of Technology, made up of security-minded software engineers who both build and break things: building secure tooling and IAM functionality, and testing systems the way an attacker would to see if they hold up. The team continuously refines its tooling, playbooks, and methods based on what it finds.This = our tech stack Exact's core products are primarily built in C#/.NET. Across the wider Exact portfolio you will also encounter other languages, such as C, Python, and PHP — comfort reading unfamiliar code is useful, though you don't need to master every language. The team relies on a combination of automated scanning and dependency tooling, AI-assisted analysis, and manual, pentest-style testing with tools such as Burp Suite or OWASP ZAP. This = what you bring A software engineering background (junior to medior level), you've written and shipped real code, ideally in C#/.NET or a comparable ecosystem. Genuine interest in application security and classical penetration-testing techniques: you know your way around the OWASP Top 10 (injection, broken authentication, IDOR, SSRF, and similar) and want to go deeper. A "trace it to the source" mindset: you want to understand not just that something is vulnerable, but why, and how an attacker would actually use it. Basic awareness of threat modeling concepts (e.g., STRIDE) and interest in growing into attack-surface thinking. Comfort reading code across different languages and frameworks. Clear, structured communication: you can explain a technical finding to both an engineer and a non-technical stakeholder. A collaborative, learning attitude: you are supported by senior colleagues and are expected to grow toward more autonomous work over time. Nice to have (not required): Familiarity with the OWASP Top 10 and OWASP ASVS. CompTIA Security+ or an equivalent foundational security certification. eJPT (eLearnSecurity Junior Penetration Tester) or a similar hands-on/practical entry-level pentest credential.
Bekijk vacature