Steven Van Der Baan is a seasoned web application security leader with over a decade of hands-on and strategic experience, currently serving as Global Practice Lead at NCC Group from Greater Cambridge. He designs and matures service lines—spanning product, delivery, training, and commercial strategy—while also managing teams as a line manager and executive principal consultant. Steven’s background as a practitioner (penetration testing, architecture reviews, secure SDLC) and former Java architect gives him rare empathy for developers and practical insight into secure design and remediation. He’s an active contributor to the security community as project manager and primary author of the OWASP Capture the Flag framework and challenge set, enabling security education at conferences worldwide. Colleagues describe him as someone who bridges technical depth and business performance, improving practice maturity and FY outcomes. His career blends consultancy, product-centric practice leadership, and community-driven tooling to make security both actionable and scalable.
12 years of coding experience
11 years of employment as a software developer
BSc Software Engineering and Databases, BSc Software Engineering and Databases at De Haagse Hogeschool / The Hague University of Applied Sciences
The Penetration Testers Framework (PTF) is a way for modular support for up-to-date tools.
Contributions:4 PRs, 30 pushes, 3 branches in 6 years 7 months
bugbountysecuritypenetrationtesterspentest
Find and Hire Top DevelopersWe’ve analyzed the programming source code of over 60 million software developers on GitHub and scored them by 50,000 skills. Sign-up on Prog,AI to search for software developers.