
Veritaz AB · Sverige
Veritaz is a leading IT staffing solutions provider in Sweden, committed to advancing individual careers and aiding employers in ensuring the perfect talent fit...
Veritaz is a leading IT staffing solutions provider in Sweden, committed to advancing individual careers and aiding employers in ensuring the perfect talent fit. With a proven track record of successful partnerships with top companies, we have rapidly grown our presence in the USA, Europe, and Sweden as a dependable and trusted resource within the IT industry.
Assignment Description
We are looking for an experienced Senior Application Security Coordinator
What You Will Work On
Coordinate remediation of findings from penetration tests and vulnerability assessments
Manage and track security findings through their complete lifecycle
Assess and prioritize vulnerabilities based on business risk
Coordinate remediation activities across business and technical teams
Work closely with application owners, infrastructure teams, and security stakeholders
Establish and maintain governance, reporting, and remediation processes
Monitor progress and ensure timely resolution of identified vulnerabilities
Facilitate communication between multiple stakeholders
Improve visibility and control of the organization's vulnerability landscape
Support compliance with internal security standards and external regulatory requirements
Drive continuous improvements in vulnerability management processes
Ensure effective collaboration across cross-functional teams
What You Bring
Experience working with Jira
Experience coordinating remediation of security findings
Strong ability to assess risks and prioritize remediation activities
Experience driving structured remediation and follow-up processes
Good understanding of application security and infrastructure security
Experience handling results from vulnerability scanning and penetration testing
Knowledge of CVE, CWE, and CVSS
Strong stakeholder management and communication skills
Experience coordinating work across multiple technical and business teams
Strong organizational and planning skills
Experience with security governance and reporting
Ability to work independently in complex environments
Analytical, structured, and proactive approach to problem-solving
Veritaz is a leading IT staffing solutions provider in Sweden, committed to advancing individual careers and aiding employers in ensuring the perfect talent fit. With a proven track record of successful partnerships with top companies, we have rapidly grown our presence in the USA, Europe, and Sweden as a dependable and trusted resource within the IT industry. Assignment Description We are looking for an experienced Application Manager – Payment Solutions What You Will Work On Manage and continuously improve existing Payment Solutions Take ownership of an existing payment platform and ensure stable operations Ensure continuity of previously implemented payment solutions Monitor and manage risks related to payment processing and PCI DSS compliance Act as the primary contact between business users, restaurants, and technology vendors Support application management for POS systems and payment infrastructure Drive continuous improvements within payment and checkout solutions Coordinate incident management and improve operational transparency Ensure proactive application management and service delivery Document processes, procedures, operational routines, and decisions Collaborate closely with application owners and external partners Support compliance, governance, and quality assurance activities What You Bring Experience managing Payment Solutions or payment platforms Strong knowledge of PCI DSS and payment card security regulations Good understanding of POS (Point of Sale) systems and payment infrastructure Experience from Restaurant, Retail, Commerce, or similar industries is highly desirable Ability to quickly understand and manage existing system implementations Experience working with multiple vendors and external partners Strong stakeholder management and communication skills Experience with application management and service management Ability to identify risks and drive proactive improvements Strong analytical and problem-solving skills Experience with incident management and operational governance Experience with drive-through systems, retail technology, or franchise environments is an advantage Understanding of franchise operating models is considered a plus Structured, proactive, and self-driven working style Fluent communication skills in business and technical environments
Spektrum have a wide range of exciting opportunities in several global locations. We are always looking to add great new talent to our team and look forward to hearing from you. BACKGROUND: eu-LISA is the European Union Agency for the Operational Management of Large-Scale IT Systems in the Area of Freedom, Security and Justice (eu-LISA) manages large-scale IT systems to support the implementation of asylum, border management and migration policies in the European Union (EU). The Agency is also a front-runner for the digitalisation efforts of the EU's Justice and Home Affairs domain, building a new information architecture and contributing to the development of a new security ecosystem. Since the Agency's beginnings in 2012, eu-LISA has become the digital engine of the Schengen Area. With its activities and tasks, the Agency adds value to the EU Member States by supporting their efforts towards justice, security and freedom. TASK DESCRIPTION: * Supports the Agency's Information Security Officers in the management of information security and business continuity across organizational business processes and information systems * Develop security controls in the context of the agency's information security framework. * Expected also to perform the following tasks: * Perform risk assessments * Develop Information Security Management System (ISMS) procedures * Develop conceptual, logical and physical security models as appropriate. * Draft security policies, standards, procedures and guidelines in accordance with ISO27001 * Development of security plans and documentation (e.g. risk treatment plans, security test plans) * Development of business continuity and disaster recovery plans. * Perform security assessments and audits * Perform ISMS control audits * Perform ISMS gap assessments * Design security controls in accordance with agency information security policies and standards * Provide assistance in formal accreditation process for information systems handling EU sensitive and classified information. EDUCATION: * Minimum 4 years of relevant education (master or equivalent) after the secondary school MINIMUM EXPERIENCE: * Minimum 6 years of general IT professional experience, of which * Minimum 3 years of relevant professional experience in Information Security Management ADDITIONAL NEEDED QUALIFICATION, KNOWLEDGE AND SKILLS: * Good knowledge of/in: * ISO27001 implementation and management. * Relevant standards and good practice in information security management * Information risk management (in particular E-BIOS) * Governance, Risk & Compliance (GRC) practices and controls * ISO27001 security control audits and assessments * Developing security policies, standards and guidelines in accordance with ISO27001 and EU security policies and standards * Design, implementation and assessments of good practice security control frameworks such as SANS Top 20 Critical Controls, OWASP Application Security Verification Standard, * Secure development processes (Security and Privacy design) * Implementation of EU data protection principles in information system design and processes. * This profile is expected to possess one or more of the following qualifications: * Certified Information Systems Security Professional (CISSP) * Certified Information Security Manager (CISM) * Certified Information Systems Auditor (CISA) * ITIL/ITIL V3 * BSI ISO27001 Lead Auditor Qualification We never know what new opportunities might be just over the horizon. If this opportunity isn't for you, please feel free to send us your resume anyway and be the first to know if something suitable for your skills and experience comes up.
Spektrum have a wide range of exciting opportunities in several global locations. We are always looking to add great new talent to our team and look forward to hearing from you. BACKGROUND: eu-LISA is the European Union Agency for the Operational Management of Large-Scale IT Systems in the Area of Freedom, Security and Justice (eu-LISA) manages large-scale IT systems to support the implementation of asylum, border management and migration policies in the European Union (EU). The Agency is also a front-runner for the digitalisation efforts of the EU's Justice and Home Affairs domain, building a new information architecture and contributing to the development of a new security ecosystem. Since the Agency's beginnings in 2012, eu-LISA has become the digital engine of the Schengen Area. With its activities and tasks, the Agency adds value to the EU Member States by supporting their efforts towards justice, security and freedom. TASK DESCRIPTION: * Define security configuration and operations standards for security systems and applications, including policy assessment and compliance tools, network security appliances, and host- based security systems * Develop and validate baseline security configurations for operating systems, applications, and networking and telecommunications equipment * Perform internal and external technical control and vulnerability assessments to identify control weaknesses and assess the effectiveness of existing controls, and recommend remedial action * Perform source code reviews * Perform network and application penetration testing ( Black box, Grey box and White box) * Defining detailed security architecture * Performing technical security audits * Perform log analysis and security monitoring * Perform IT infrastructure/ Application Security configuration reviews * Design and implement technical security mechanisms and technologies * Design and develop technical security standards and procedures EDUCATION: * Minimum 4 years of relevant education (master or equivalent) after the secondary school MINIMUM EXPERIENCE: * Minimum 6 years of relevant professional experience in IT Security ADDITIONAL NEEDED QUALIFICATION, KNOWLEDGE AND SKILLS: * Expected to possess advanced knowledge of/in: * Security best practice guidelines (ISO 27001, NIST, SANS Top 20 OWASP, etc.) * Good practice in the secure configuration of servers, network devices and applications * Networking protocols and application communications * Network analysis tools * Securing Unix and Windows operating systems * Securing middleware and applications. * Network penetration testing * Web application penetration testing * Vulnerability assessments * Forensic image collection and analysis * Managing/deploying the following security technologies: Firewalls; IDS/IPS - Intrusion detection/Prevention Systems, SIEM – Security information and event management; IAM – Identity and access management; APT – Advanced Persistent threat detection; DLP – Data loss prevention; VA – Vulnerability Analysis and mitigation; PKI – Public key infrastructure; Virtual environments; Endpoint security; Mobile security; Communications and data encryption ; Remote access methods; Backup and disaster recovery methodologies; Patch management technologies and processes; Wireless protocols and services * Open Web Application Security Protocol (OWASP) and secure software development standards * Performing security code reviews. * Security monitoring, threat detection and incident response; * Proactively and iteratively searching through networks and applications to detect and isolate advanced threats that evade existing security solutions (Cyber threat hunting); * Security operations engineering (e.g. implementation of defensive measures, threat intelligence production); * Linux administration, TCP/IP, Network Security. * Security configuration reviews of IT Infrastructure and security devices, OS, Databases etc. * Expected to possess one or more of the following qualifications: * Certified Information Systems Security Professional with Information Systems Security Architecture Professional concentration (CISSP-ISSAP) * Certified Information Security Manager (CISM) * Certified Information Systems Auditor (CISA) * OSCP, OSCE, GPEN, CEH, CCNA, CCNP We never know what new opportunities might be just over the horizon. If this opportunity isn't for you, please feel free to send us your resume anyway and be the first to know if something suitable for your skills and experience comes up.