Senior Application Security Engineer (SnelStart).
SnelStart's SaaS software helps thousands of entrepreneurs with their daily business operations and, in doing so, processes sensitive business data. As a Senior Application Security Engineer, you ensure that security is part of SnelStart's products from the very first design — not just as a check or fix at the end.
You work directly with the development teams. You read code, investigate vulnerabilities, and help developers resolve issues at the source. At the same time, you improve the process around it: from threat modeling and security requirements to automated checks in CI/CD.
So you won't become a gatekeeper who forwards scan reports from the sidelines. You think along, test yourself, and build together with developers, architects, SRE, AI Foundry, the CTO, CISO, and SnelStart's external SOC on software that becomes demonstrably more secure without unnecessarily slowing down development.
What you will do.
The core of the work is application and product security. You will, among other things:
- perform security reviews on designs, code, APIs, authentication and authorization flows, and CI/CD pipelines;
- develop threat models, abuse cases, and concrete security acceptance criteria for new and existing functionality;
- reproduce and prioritize vulnerabilities based on exploitability and real impact on customers and the organization;
- practically support developers with secure coding and structural solutions, including around input validation, secrets, dependencies, sessions, and access rights;
- further integrate SAST, DAST, SCA, secret scanning, and container scanning, and set them up so teams get usable signals instead of just more alerts;
- translate findings from pentests and security tests into improvements that prevent recurrence;
- work with cloud, platform, and SOC colleagues to strengthen logging, detection, and response scenarios around the applications;
- where relevant, assess the security of AI functionality and automated workflows, for example regarding prompt injection, data leaks, insecure tool access, and overly broad agent permissions.
You don't need to be a specialist in every security domain. Application security is your foundation. Experience with cloud, offensive security, detection, or AI security helps you assess risks in their broader context.
What you're building.
In your first year, you help establish a recognizable and workable AppSec approach. Think of:
- a clear picture of the main risks in the applications, APIs, and software supply chain;
- fixed, lightweight security checkpoints in design, development, and release;
- well-aligned security tools in the pipelines, with clear follow-up on findings;
- practical standards and reusable patterns that enable teams to build more securely on their own;
- increased security knowledge within development through coaching, reviews, and hands-on sessions.
The goal is not to introduce as many checks as possible. The goal is that relevant vulnerabilities are found earlier, resolved faster, and recur less often.
What you bring.
You combine technical depth with the ability to bring other engineers along. This includes:
- at least five years of relevant experience in software development, application or product security, DevSecOps, ethical hacking, or a similar hands-on role;
- experience reading and reviewing modern application code, for example in .NET/C#, Java, JavaScript/TypeScript, or Python;
- solid knowledge of web and API security, including OWASP Top 10, OWASP ASVS, CWE, and common vulnerability patterns;
- knowledge of authentication and authorization, for example OAuth 2.0, OIDC, SAML, JWT, RBAC, and least privilege;
- practical experience with security testing and assessing findings — manually and with tooling;
- experience integrating or improving security controls in development and CI/CD processes;
- the ability to clearly explain technical risks to developers, architects, product owners, and management;
- a curious, critical, and pragmatic attitude: you want to test, understand, and improve things yourself.
Experience with cloud-native security in Azure, AWS, or GCP, threat modeling, offensive testing, detection engineering, or AI security is a plus. A relevant certification, such as OSWE, Burp Suite Certified Practitioner, CSSLP, or AZ-500, can also be a plus. Demonstrable practical experience weighs more heavily than certificates.
Don't meet every single point, but do you recognize yourself in the core of the role? Then it's worth applying.
What the organization offers.
- a key role with direct influence on the security of products that thousands of entrepreneurs use daily;
- room and mandate to further shape application security and secure software development;
- close collaboration with development, architecture, cloud, SRE, AI Foundry, privacy, compliance, and the external SOC;
- a salary of € 80,000 to € 110,000 gross per month based on 40 hours, depending on experience;
- a position of 32 to 40 hours per week;
- hybrid working: an average of 60% at the locations in Amersfoort and/or Alkmaar and 40% from home;
- 30 vacation days based on 40 hours;
- a well-arranged pension and monthly payout of vacation pay;
- training opportunities and budget for relevant certifications;
- a laptop and a good workspace, including a sit-stand desk and ergonomic office chair;
- 220 colleagues who together build reliable software for entrepreneurs.
A screening and assessment are part of the recruitment and selection procedure.
Apply now.
Your details go straight into our system — no middlemen, no mailing lists.