Sida 1 av 15
Security engineers at Spotify protect the security of Spotify’s platform and of our 750+ million users. We are looking for an experienced engineer to join us in securing the most important engineering initiatives at Spotify. You will be working in the infrastructure security engineering area to secure the foundations of Spotify’s platform. We’re a distributed team building the architecture and foundations for secure cloud computing and support platform teams in building best-in-class infrastructure on it. We aim to constantly improve the security posture for our fast-paced and rapidly-changing environment in a manner that will keep up with our scale. We’re experts in many domains of security, willing to teach and learn from anyone at the company. You are a seasoned security, systems or software engineer with a passion for cloud security. Above all you have an insatiable appetite for learning new things and honing your existing skill set. In this role you are expected to represent security in various engineering and business contexts so we expect you to be comfortable communicating with diverse audiences both verbally and in writing.
Nordnet redefined the financial world as the first digital bank in Europe. Now we are about to do it again and the aim is to create the next generation of bank, in the cloud. We know that this requires great people, great teams, and great technology. Do you want to join us and build the new Nordnet? At Nordnet we want to democratize savings and investments by giving our customers access to the best tools and information whether you are a professional investor or a small saver. With modern technologies and speed of delivery, we are building the next generation investment platform. This is part of the role Nordnet is a company with tech as the primary focus. In our agile and autonomous teams, you will be working with engaged colleagues that love to share their knowledge. As a cloud security engineer, you will drive automation and integrate DevSecOps into our cloud-based platform by embedding security in Continuous Integration/Continuous Delivery (CI/CD) pipelines, enhancing infrastructure security and ensuring secure software development practices. As a Cloud Security Engineer acting autonomously and with a clear mandate, you will: Develop and enforce cloud and Infrastructure As Code (IaC) security policies. Improve cloud security monitoring by building and managing detections. Collaborate with engineering teams to ensure security best practices and Secure Software Development Life Cycle SSDLC (Shift-Left). Facilitate threat modelling sessions, secure code review and vulnerability assessments. Coordinate penetration testing efforts and track remediations. Enable developers to ship fast by automating security Balance security rigor with business agility; we don't just secure, we enable. This is you To succeed in this role, we believe that you take great pride in your work, are curious and continuously want to learn and grow. Believing in collaboration and discussing ideas and concepts with your colleague, you will serve as the first point of contact for our Platform teams as a Cloud Security Subject Matter Expert to enable the delivery of great products. As a Cloud Security Engineer, you have: Offensive security mindset ideally with former red teamer or penetration tester experience Knowledge of Google Cloud Platform (or equivalent experience with other Cloud providers) Google Security Command Centre (SCC) Google Kubernetes Engine (GKE) Identity and Access Management (IAM) Infrastructure As Code (Terraform) Github Ability to work independently and as part of a team Strong stakeholder management skills, ability to work with both technical and non-technical stakeholders Ability define and implement security requirements in cloud environments Experience with security best practices and vulnerability management process. Familiarity with programming and major frameworks (Java, Spring, React) What we offer Your expertise and contribution will be appreciated from day one Access to the latest AI tools with cutting edge models to support your daily work. Plenty of opportunities to grow as a security professional Competitive salary and compensation Opportunity to shape the architecture, influencing the security design of Europe’s next-generation digital bank from the ground up. Access to training opportunities such as professional certifications (e.g., GCP Security, OSCP, OSAI+, CISSP), industry conferences, and dedicated time for skills development. You won't just follow a checklist; you’ll have the mandate to build and own your security automation roadmap. We offer you the opportunity to work in a Nordic environment with a strong focus on delivery, product development and technology. Our ambitions are high and you will embark on a fast and challenging journey together with a skillful team of sharp and committed colleagues. Our teams are autonomous and embrace the agile way of working. Culture is built and cared for, each day by everyone. We’re proud of ours. Having a flat organization where anyone can talk to anyone creates a warm and friendly atmosphere worth protecting. We believe in a culture where every effort counts and where everyone is being recognized. A culture embracing our core values – passion, simplicity and transparency on all levels, no matter who you are or what you do. We are over 900 employees located in Stockholm, Oslo, Helsinki, Copenhagen and Frankfurt. Visit us on: career.nordnetab.com/pages/engineering Learn more about Nordnet in our brand movie This is Nordnet, that describes our identity. Questions & Applications Please note that we will start reviewing applications after the summer holidays. To ensure a fair process and that your data is handled securely, we only accept applications through our recruitment system, applications sent via email will not be considered. If you have questions, please contact Hiring Manager Ralph Benton at ralph.benton@nordnet.se We want to inform you that Nordnet conducts mandatory credit and background checks, as well as drug testing as a part of our recruitment process. We look forward to receiving your application!
Som Cloud Security Engineer på Svenska Spel är du med och bygger grunden för ett effektivt säkerhetsarbete. Genom data, automation och smarta integrationer ser du till att rätt information finns på rätt plats när den behövs som mest. Gillar du att lösa komplexa problem med hjälp av data, automation och modern teknik? Då kan det här vara rollen för dig. Vad är det du ska göra? Som Cloud Security Engineer stärker du Svenska Spels cybersäkerhet genom att säkerställa att rätt säkerhetsdata finns tillgänglig när den behövs. Genom integrationer, automation och smart användning av loggar och telemetri omsätter du säkerhetsinsikter till tekniska lösningar som förbättrar detektion, analys och incidenthantering. Du arbetar nära säkerhetsanalytiker, utvecklings- och plattformsteam och blir en viktig brygga mellan säkerhetsanalys, teknik och plattform. Tillsammans vidareutvecklar vi vår förmåga att upptäcka, analysera och hantera säkerhetshändelser i komplexa och moderna miljöer. En viktig del av rollen handlar om att säkerställa att rätt säkerhetsdata finns tillgänglig, håller hög kvalitet och kan användas effektivt i det dagliga säkerhetsarbetet. Du bygger integrationer, utvecklar pipelines och skapar förutsättningar för bättre detektion och snabbare respons. Rollen omfattar även att utforska hur AI kan användas för att effektivisera säkerhetsarbetet – samtidigt som vi hanterar de risker som tekniken för med sig. Du kommer bland annat att: Bygga och vidareutveckla datainsamling, integrationer och pipelines för loggar, händelser och telemetri Säkerställa datakvalitet genom parsers, normalisering, datamodeller och korrelationslogik Omsätta säkerhetsbehov till use cases, larm, detektioner och automatiserade arbetsflöden Utveckla tekniska förmågor för detektion, analys och respons på säkerhetshändelser Automatisera manuella moment och arbeta med scripting när standardlösningar inte räcker till Samarbeta nära säkerhetsanalytiker, utvecklings- och plattformsteam Bidra till AI-stödda arbetssätt och ett säkert införande av AI-lösningar Är du den som ska göra det? För att trivas i rollen tror vi att du gillar att lösa problem, göra saker smartare och bygga lösningar som håller över tid. Du är nyfiken på hur saker fungerar, gillar att grotta ner dig i detaljer när det behövs och har samtidigt förmågan att lyfta blicken och se helheten. Du tycker om att samarbeta med andra och trivs i skärningspunkten mellan människor, data och teknik. Du förstår behoven bakom en detektion eller ett larm för att sedan skapa lösningen som gör den användbar i praktiken. Att dela kunskap, hitta bättre arbetssätt och hjälpa kollegor att lyckas är en naturlig del av hur du jobbar. Du behöver inte kunna allt från början, men vi tror att du har erfarenhet av några av följande områden: Säkerhetsplattformar som SIEM, SOAR, XDR eller EDR Molnmiljöer och logginsamling i Azure eller GCP Integrationer, automation, API eller Infrastructure as Code Ramverk och verktyg som MITRE ATT&CK, Sigma, YARA, KQL eller SPL Incidenthantering, threat hunting eller AI-relaterat säkerhetsarbete Vi värdesätter nyfikenhet, problemlösningsförmåga och viljan att fortsätta utvecklas minst lika mycket som erfarenhet av specifika tekniker. Vi behöver dig som motiveras av att bidra till säkerhetsförmågan i en verksamhet med höga krav på tillgänglighet, säkerhet och förtroende. Varför Svenska Spel och Cyber Security Operations? För oss är säkerhet och tillgänglighet inte en sidofråga utan en förutsättning för förtroendet för vår affär. Våra tjänster används av miljontals människor och vi hanterar stora mängder data, höga tillgänglighetskrav och avancerade digitala plattformar. Hos oss blir du en del av ett team som varje dag arbetar för att skapa trygga och säkra digitala upplevelser för miljontals människor. Här finns komplex teknik, höga ambitioner och stora möjligheter att utvecklas – men framför allt kollegor som gärna delar med sig av sin kunskap och hjälper varandra framåt. Vi lär oss varje dag, får saker att hända tillsammans och bygger säkerhetsförmågor som gör verklig skillnad för våra kunder, vår verksamhet och samhället i stort. Vi hanterar 10 miljoner transaktioner om dagen, året runt och utvecklar, driftar och supportar ett av världens mest avancerade spelsystem. Vi är med andra ord ett techbolag som sysslar med spel - inte tvärtom. Det här kommer med ett ansvar, både för folkets drömmar och spänning, men även för deras spelande. Vi vill att fler ska spela hållbart hos oss och vår verksamhet ska bedrivas på ett socialt, ekonomiskt och miljömässigt ansvarsfullt sätt. Vi är Sveriges största idrottssponsor och investerar nära 300 miljoner kronor årligen i svensk idrott. Är du nyfiken på våra förmåner? Då hittar du dem här! Ansökan och kontaktuppgifter Tjänsten är en tillsvidareanställning med placering i Stockholm eller i Visby. För frågor om tjänsten är du varmt välkommen att kontakta Tonny Hultberg, Chef Cyber Security Operations, på tonny.hultberg@svenskaspel.se För frågor om rekryteringsprocessen, kontakta Team TA; teamta@svenskaspel.se 🏖️ Vi arbetar med urval och intervjuer löpande fram till och med vecka 29. Därefter väntar några veckors semester för oss som jobbar med processen, vilket innebär att återkopplingen kan dröja under sommaren. Vecka 33 kliver vi ur hängmattan och är tillbaka igen, redo att fortsätta processen. Så skicka in din ansökan och njut av glass och värme, så hörs vi igen senast i mitten augusti.
Som Cloud Security Analyst på Svenska Spel är du med och skyddar några av Sveriges mest använda digitala tjänster. Vi arbetar i en miljö där säkerhet, tillgänglighet och förtroende är avgörande. Här blir du en viktig del av arbetet med att identifiera risker, upptäcka hot och säkra våra molnplattformar, affärssystem och speltjänster. Du kombinerar analys, teknik och samarbete för att göra verklig skillnad och bygger säkerhet som en naturlig del av våra tjänster – från design och utveckling till drift och incidenthantering. Vad är det du ska göra? Som Cloud Security Analyst arbetar du både proaktivt och operativt för att förebygga, upptäcka och hantera säkerhetsrisker i våra moln- och IT-miljöer. Samtidigt bidrar du till att utveckla vår säkerhetsförmåga och våra arbetssätt. Du samarbetar nära utvecklings-, plattforms- och verksamhetsteam för att omsätta säkerhetskrav till praktiska lösningar som stärker våra tjänster och hjälper organisationen att hantera risker på ett effektivt sätt. Du får en central roll i arbetet med att utveckla säkerheten i GCP och våra affärs- och spelplattformar. Rollen omfattar även att utforska hur AI kan användas för att effektivisera säkerhetsarbetet – samtidigt som vi hanterar de risker som tekniken för med sig. Analyserar och hanterar säkerhetshändelser, hot och sårbarheter Stöttar vid incidenter genom logganalys, utredningar och säkerhetsrekommendationer Granskar molnkonfigurationer, identitetshantering, nätverk och dataskydd Bidrar till att utveckla detektion, övervakning och säkerhetsförmågor i våra plattformar Stöttar team med säkerhetsgranskningar, riskbedömningar och secure-by-design Bidrar till utvecklingen av AI-stödda arbetssätt och ett säkert införande av AI-lösningar Är du den som ska göra det? För att trivas i rollen tror vi att du är nyfiken, analytisk och drivs av att förstå hur teknik fungerar, hur den tyvärr ibland kan missbrukas och hur den kan skyddas. Du har lätt för att växla mellan detaljer och helhet, och du tycker om att samarbeta med andra för att hitta lösningar som fungerar i praktiken. Du gillar att dela med dig av din kunskap, utmana invanda arbetssätt och bidra till att göra säkerhetsarbetet lite smartare varje dag. Du tycker om att omsätta tekniska säkerhetsfrågor till konkreta rekommendationer som hjälper verksamheten framåt. Det är extra intressant om du har erfarenhet av: Säkerhetsanalys, incidenthantering eller threat hunting Säkerhetsplattformar som SIEM, EDR eller liknande verktyg Säkerhetsarbete i GCP eller Azure Identitets- och behörighetsstyrning i molnmiljöer Scripting, automation eller AI-relaterat säkerhetsarbete Du behöver inte kunna allt. Vi värdesätter nyfikenhet, problemlösningsförmåga och viljan att fortsätta utvecklas minst lika mycket som erfarenhet av specifika tekniker. Varför Svenska Spel och Cyber Security Operations? Säkerhet är en strategisk fråga för oss. Våra tjänster används av miljontals människor och vi hanterar stora mängder data, höga tillgänglighetskrav och avancerade digitala plattformar. Hos oss blir du en del av ett team som varje dag arbetar för att skapa trygga och säkra digitala upplevelser för miljontals människor. Här finns komplex teknik, höga ambitioner och stora möjligheter att utvecklas – men framför allt kollegor som gärna delar med sig av sin kunskap och hjälper varandra framåt. Vi lär oss varje dag, får saker att hända tillsammans och bygger säkerhetsförmågor som gör verklig skillnad för våra kunder, vår verksamhet och samhället i stort. Vi hanterar 10 miljoner transaktioner om dagen, året runt och utvecklar, driftar och supportar ett av världens mest avancerade spelsystem. Vi är med andra ord ett techbolag som sysslar med spel - inte tvärtom. Det här kommer med ett ansvar, både för folkets drömmar och spänning, men även för deras spelande. Vi vill att fler ska spela hållbart hos oss och vår verksamhet ska bedrivas på ett socialt, ekonomiskt och miljömässigt ansvarsfullt sätt. Vi är Sveriges största idrottssponsor och investerar nära 300 miljoner kronor årligen i svensk idrott. Är du nyfiken på våra förmåner? Då hittar du dem här! Ansökan och kontaktuppgifter Tjänsten är en tillsvidareanställning med placering i Stockholm eller i Visby. För frågor om tjänsten är du varmt välkommen att kontakta Tonny Hultberg, Chef Cyber Security Operations, på tonny.hultberg@svenskaspel.se För frågor om rekryteringsprocessen, kontakta Team TA; teamta@svenskaspel.se 🏖️ Vi arbetar med urval och intervjuer löpande fram till och med vecka 29. Därefter väntar några veckors semester för oss som jobbar med processen, vilket innebär att återkopplingen kan dröja under sommaren. Vecka 33 kliver vi ur hängmattan och är tillbaka igen, redo att fortsätta processen. Så skicka in din ansökan och njut av glass och värme, så hörs vi igen senast i mitten augusti.
Som Cloud Security Analyst på Svenska Spel är du med och skyddar några av Sveriges mest använda digitala tjänster. Vi arbetar i en miljö där säkerhet, tillgänglighet och förtroende är avgörande. Här blir du en viktig del av arbetet med att identifiera risker, upptäcka hot och säkra våra molnplattformar, affärssystem och speltjänster. Du kombinerar analys, teknik och samarbete för att göra verklig skillnad och bygger säkerhet som en naturlig del av våra tjänster – från design och utveckling till drift och incidenthantering. Vad är det du ska göra? Som Cloud Security Analyst arbetar du både proaktivt och operativt för att förebygga, upptäcka och hantera säkerhetsrisker i våra moln- och IT-miljöer. Samtidigt bidrar du till att utveckla vår säkerhetsförmåga och våra arbetssätt. Du samarbetar nära utvecklings-, plattforms- och verksamhetsteam för att omsätta säkerhetskrav till praktiska lösningar som stärker våra tjänster och hjälper organisationen att hantera risker på ett effektivt sätt. Du får en central roll i arbetet med att utveckla säkerheten i GCP och våra affärs- och spelplattformar. Rollen omfattar även att utforska hur AI kan användas för att effektivisera säkerhetsarbetet – samtidigt som vi hanterar de risker som tekniken för med sig. * Analyserar och hanterar säkerhetshändelser, hot och sårbarheter * Stöttar vid incidenter genom logganalys, utredningar och säkerhetsrekommendationer * Granskar molnkonfigurationer, identitetshantering, nätverk och dataskydd * Bidrar till att utveckla detektion, övervakning och säkerhetsförmågor i våra plattformar * Stöttar team med säkerhetsgranskningar, riskbedömningar och secure-by-design * Bidrar till utvecklingen av AI-stödda arbetssätt och ett säkert införande av AI-lösningar Är du den som ska göra det? För att trivas i rollen tror vi att du är nyfiken, analytisk och drivs av att förstå hur teknik fungerar, hur den tyvärr ibland kan missbrukas och hur den kan skyddas. Du har lätt för att växla mellan detaljer och helhet, och du tycker om att samarbeta med andra för att hitta lösningar som fungerar i praktiken. Du gillar att dela med dig av din kunskap, utmana invanda arbetssätt och bidra till att göra säkerhetsarbetet lite smartare varje dag. Du tycker om att omsätta tekniska säkerhetsfrågor till konkreta rekommendationer som hjälper verksamheten framåt. Det är extra intressant om du har erfarenhet av: * Säkerhetsanalys, incidenthantering eller threat hunting * Säkerhetsplattformar som SIEM, EDR eller liknande verktyg * Säkerhetsarbete i GCP eller Azure * Identitets- och behörighetsstyrning i molnmiljöer * Scripting, automation eller AI-relaterat säkerhetsarbete Du behöver inte kunna allt. Vi värdesätter nyfikenhet, problemlösningsförmåga och viljan att fortsätta utvecklas minst lika mycket som erfarenhet av specifika tekniker. Varför Svenska Spel och Cyber Security Operations? Säkerhet är en strategisk fråga för oss. Våra tjänster används av miljontals människor och vi hanterar stora mängder data, höga tillgänglighetskrav och avancerade digitala plattformar. Hos oss blir du en del av ett team som varje dag arbetar för att skapa trygga och säkra digitala upplevelser för miljontals människor. Här finns komplex teknik, höga ambitioner och stora möjligheter att utvecklas – men framför allt kollegor som gärna delar med sig av sin kunskap och hjälper varandra framåt. Vi lär oss varje dag, får saker att hända tillsammans och bygger säkerhetsförmågor som gör verklig skillnad för våra kunder, vår verksamhet och samhället i stort. Vi hanterar 10 miljoner transaktioner om dagen, året runt och utvecklar, driftar och supportar ett av världens mest avancerade spelsystem. Vi är med andra ord ett techbolag som sysslar med spel - inte tvärtom. Det här kommer med ett ansvar, både för folkets drömmar och spänning, men även för deras spelande. Vi vill att fler ska spela hållbart hos oss och vår verksamhet ska bedrivas på ett socialt, ekonomiskt och miljömässigt ansvarsfullt sätt. Vi är Sveriges största idrottssponsor och investerar nära 300 miljoner kronor årligen i svensk idrott. Är du nyfiken på våra förmåner? Då hittar du dem här! Ansökan och kontaktuppgifter Tjänsten är en tillsvidareanställning med placering i Stockholm eller i Visby. För frågor om tjänsten är du varmt välkommen att kontakta Tonny Hultberg, Chef Cyber Security Operations, på tonny.hultberg@svenskaspel.se För frågor om rekryteringsprocessen, kontakta Team TA; teamta@svenskaspel.se 🏖️ Vi arbetar med urval löpande fram till och med vecka 28. Därefter väntar några veckors semester för oss som jobbar med processen, vilket innebär att återkopplingen kan dröja under sommaren. Vecka 33 kliver vi ur hängmattan och är tillbaka igen, redo att fortsätta processen. Så skicka in din ansökan och njut av glass och värme, så hörs vi igen senast i mitten augusti.
Som Cloud Security Engineer på Svenska Spel är du med och bygger grunden för ett effektivt säkerhetsarbete. Genom data, automation och smarta integrationer ser du till att rätt information finns på rätt plats när den behövs som mest. Gillar du att lösa komplexa problem med hjälp av data, automation och modern teknik? Då kan det här vara rollen för dig. Vad är det du ska göra? Som Cloud Security Engineer stärker du Svenska Spels cybersäkerhet genom att säkerställa att rätt säkerhetsdata finns tillgänglig när den behövs. Genom integrationer, automation och smart användning av loggar och telemetri omsätter du säkerhetsinsikter till tekniska lösningar som förbättrar detektion, analys och incidenthantering. Du arbetar nära säkerhetsanalytiker, utvecklings- och plattformsteam och blir en viktig brygga mellan säkerhetsanalys, teknik och plattform. Tillsammans vidareutvecklar vi vår förmåga att upptäcka, analysera och hantera säkerhetshändelser i komplexa och moderna miljöer. En viktig del av rollen handlar om att säkerställa att rätt säkerhetsdata finns tillgänglig, håller hög kvalitet och kan användas effektivt i det dagliga säkerhetsarbetet. Du bygger integrationer, utvecklar pipelines och skapar förutsättningar för bättre detektion och snabbare respons. Rollen omfattar även att utforska hur AI kan användas för att effektivisera säkerhetsarbetet – samtidigt som vi hanterar de risker som tekniken för med sig. Du kommer bland annat att: * Bygga och vidareutveckla datainsamling, integrationer och pipelines för loggar, händelser och telemetri * Säkerställa datakvalitet genom parsers, normalisering, datamodeller och korrelationslogik * Omsätta säkerhetsbehov till use cases, larm, detektioner och automatiserade arbetsflöden * Utveckla tekniska förmågor för detektion, analys och respons på säkerhetshändelser * Automatisera manuella moment och arbeta med scripting när standardlösningar inte räcker till * Samarbeta nära säkerhetsanalytiker, utvecklings- och plattformsteam * Bidra till AI-stödda arbetssätt och ett säkert införande av AI-lösningar Är du den som ska göra det? För att trivas i rollen tror vi att du gillar att lösa problem, göra saker smartare och bygga lösningar som håller över tid. Du är nyfiken på hur saker fungerar, gillar att grotta ner dig i detaljer när det behövs och har samtidigt förmågan att lyfta blicken och se helheten. Du tycker om att samarbeta med andra och trivs i skärningspunkten mellan människor, data och teknik. Du förstår behoven bakom en detektion eller ett larm för att sedan skapa lösningen som gör den användbar i praktiken. Att dela kunskap, hitta bättre arbetssätt och hjälpa kollegor att lyckas är en naturlig del av hur du jobbar. Du behöver inte kunna allt från början, men vi tror att du har erfarenhet av några av följande områden: * Säkerhetsplattformar som SIEM, SOAR, XDR eller EDR * Molnmiljöer och logginsamling i Azure eller GCP * Integrationer, automation, API eller Infrastructure as Code * Ramverk och verktyg som MITRE ATT&CK, Sigma, YARA, KQL eller SPL * Incidenthantering, threat hunting eller AI-relaterat säkerhetsarbete Vi värdesätter nyfikenhet, problemlösningsförmåga och viljan att fortsätta utvecklas minst lika mycket som erfarenhet av specifika tekniker. Vi behöver dig som motiveras av att bidra till säkerhetsförmågan i en verksamhet med höga krav på tillgänglighet, säkerhet och förtroende. Varför Svenska Spel och Cyber Security Operations? För oss är säkerhet och tillgänglighet inte en sidofråga utan en förutsättning för förtroendet för vår affär. Våra tjänster används av miljontals människor och vi hanterar stora mängder data, höga tillgänglighetskrav och avancerade digitala plattformar. Hos oss blir du en del av ett team som varje dag arbetar för att skapa trygga och säkra digitala upplevelser för miljontals människor. Här finns komplex teknik, höga ambitioner och stora möjligheter att utvecklas – men framför allt kollegor som gärna delar med sig av sin kunskap och hjälper varandra framåt. Vi lär oss varje dag, får saker att hända tillsammans och bygger säkerhetsförmågor som gör verklig skillnad för våra kunder, vår verksamhet och samhället i stort. Vi hanterar 10 miljoner transaktioner om dagen, året runt och utvecklar, driftar och supportar ett av världens mest avancerade spelsystem. Vi är med andra ord ett techbolag som sysslar med spel - inte tvärtom. Det här kommer med ett ansvar, både för folkets drömmar och spänning, men även för deras spelande. Vi vill att fler ska spela hållbart hos oss och vår verksamhet ska bedrivas på ett socialt, ekonomiskt och miljömässigt ansvarsfullt sätt. Vi är Sveriges största idrottssponsor och investerar nära 300 miljoner kronor årligen i svensk idrott. Är du nyfiken på våra förmåner? Då hittar du dem här! Ansökan och kontaktuppgifter Tjänsten är en tillsvidareanställning med placering i Stockholm eller i Visby. För frågor om tjänsten är du varmt välkommen att kontakta Tonny Hultberg, Chef Cyber Security Operations, på tonny.hultberg@svenskaspel.se För frågor om rekryteringsprocessen, kontakta Team TA; teamta@svenskaspel.se 🏖️ Vi arbetar med urval löpande fram till och med vecka 28. Därefter väntar några veckors semester för oss som jobbar med processen, vilket innebär att återkopplingen kan dröja under sommaren. Vecka 33 kliver vi ur hängmattan och är tillbaka igen, redo att fortsätta processen. Så skicka in din ansökan och njut av glass och värme, så hörs vi igen senast i mitten augusti.
Join Truecaller – The place where innovation meets impact! Truecaller's mission is to build trust in communication by making it safer, smarter, and more efficient. Born in Sweden, trusted by the world, and here’s why we stand out: * We are trusted by over 450 million active users every month across 190+ countries * We identify over 15 billion calls daily, helping users avoid spam and scams * We are powered by a team of 450+ employees from 45+ nationalities We always look for people who take initiative, own their work, and keep raising the bar. An entrepreneurial mindset matters here, especially when it turns bold ideas into real actions. We stay collaborative and focused, always searching for smarter paths forward. If you want to make an impact and grow with a team that inspires millions, you’ll fit right in. The role: As a Senior Cloud Security Engineer, you will act as a technical leader in safeguarding our core cloud infrastructure. You will take ownership of maintaining the highest standards of security controls for our critical systems within Google Cloud Platform (GCP). We're looking for someone who thrives in complex environments, can solve infrastructure security problems where no established patterns exist, and isn't afraid to get their hands dirty. You won't just advise; you will actively build, configure, and fix security controls. You'll leverage your expert understanding of cloud services, infrastructure-as-code, and container security to architect robust security measures and drive systemic improvements across the organization. What you’ll do: * Architect and Lead GCP Security: Take end-to-end ownership of designing and implementing security architectures for our GCP infrastructure. You will look beyond immediate fixes to architect long-term, scalable solutions for networking, compute, storage, and GKE. * Hands-on Remediation & Engineering: You don't just identify risks; you fix them. You will actively write code, create Pull Requests, and apply configurations to resolve security issues, harden infrastructure, and deploy tooling (e.g., EDR, Identity proxies) in production environments. * Drive Systemic Risk Reduction: Identify repeating classes of vulnerabilities or systemic risks (e.g., data exfiltration paths) and drive organizational change to eliminate them, rather than just patching individual issues. * Manage GCP Security Posture: Utilize GCP-native tools (e.g., Security Command Center, Cloud Armor, VPC Service Controls, IAM) to continuously monitor, assess, and improve the security posture of our cloud environment. * Advanced Network & Container Security: Design complex network security controls and Kubernetes (GKE) hardening strategies, balancing strict security requirements with operational velocity. * Mentorship and Technical Sparring: Act as a technical mentor and sparring partner to other engineers. You will elevate engineering standards by guiding colleagues on advanced security concepts and architecture. * Automate Security Operations: Develop advanced automation (using Python, Go, No/Low Code) to eliminate toil, turning manual security reviews into automated policy-as-code checks and high-fidelity alerts. What you bring in: * Technical Experience: Several years of hands-on experience in a senior security engineering role. You have a track record of leading technical designs and influencing decisions across multiple squads. * Security Passion & Threat Awareness: You are passionate about security and stay constantly updated on the evolving threat landscape, emerging vulnerabilities, and attack vectors, translating this knowledge into proactive defense strategies. * Navigating Ambiguity: You excel at breaking down complex, multi-faceted technical problems into actionable components. You are comfortable defining security standards for experimental technologies where internal patterns may not yet exist. * Project Ownership & Grit: Demonstrated ability to drive mid-to-large scale projects from idea to implementation independently, including successful stakeholder alignment and management of external dependencies. * Operational "Doer" Mindset: You are a practitioner who enjoys the craft of engineering. You have recent, deep experience directly configuring infrastructure, writing production-grade code, and debugging complex systems. Once an issue has been identified you have the experience applying the fix either yourself or through collaboration with stakeholders. * Business-Aligned Risk Assessment: Experience weighing risk vs. speed, and making technical decisions that balance short-term delivery with long-term maintainability and business value. * Deep GCP Expertise: Expert-level knowledge of securing cloud infrastructure, with the ability to architect tool-agnostic solutions and evaluate trade-offs in GCP services (GCE, GKE, VPC, IAM, SCC). * Communication: Strong ability to communicate technical security concepts to non-technical stakeholders, clearly articulating business impact (e.g., financial loss, brand reputation) to secure buy-in. What we offer: We support growth through learning resources, leadership programs, mentoring, and real hands-on work. People can move between teams and projects to build new skills and keep things interesting. We offer clear internal mobility and a transparent path for progression, with leaders who stay involved and provide guidance throughout the year. In addition, you will benefit from: * A comprehensive compensation package: We offer a competitive salary, 30 days of paid vacation, private health insurance, parental leave top-up, pension, and wellness contributions. * Modern tools to do your best work: Choose your preferred computer and phone within our budget, so you can work comfortably and efficiently. * A people-focused office culture: We value in-person collaboration and follow an office-first model, with some flexibility. Our offices offer a vibrant environment with opportunities to learn, connect, and recharge, from breakfast, lunch, and well-stocked snack stations and quiet spaces to team activities such as movie nights, tech meetups, and cultural events. There's something for everyone. * Truecaller’s “Lab Days” offer a space for imagination: 5 times per year for 3 days, where everyone steps away from their normal tasks to explore new, bold ideas and build things they’ve always wanted to. It’s a space where curiosity leads the way, and prototypes take shape. Some concepts even make it into production, and a few have grown into real features used by millions today. Lab Days allow you to be creative, learn fast, and help shape Truecaller's future. Come as you are: Truecaller is committed to building a diverse and inclusive team. We believe that a wide range of backgrounds, perspectives, and experiences strengthens our products and our culture. No matter where you're from, what language you speak, or how you identify, we value what makes you unique and would love to get to know you. Check out Life at Truecaller - Behind the code: https://www.instagram.com/lifeattruecaller/ Sounds like a great opportunity? We will fill the position as soon as we find the right candidate, so please send your application as soon as possible. As part of the recruitment process, we will conduct a background check. We only accept applications in English.
Summary of the Role: As Security Engineer (Internal) at Maze, you'll own how we secure ourselves — our cloud, our applications, and the way our engineers build. This is a unique opportunity to join a well-funded Series A startup building at the intersection of generative AI and cybersecurity, establishing the internal security foundation that lets a three-product company keep moving fast as it scales. You'll take hands-on ownership of cloud infrastructure security, application security, security tooling, and the compliance work that unlocks enterprise deals. We're deliberately looking for a strong generalist rather than a narrow specialist: someone who can harden our AWS environment and identity model, get into the weeds on application security, and run a pragmatic compliance program — and who knows when a control is worth the friction and when it isn't. Your success will be measured by the robustness of our security posture, our readiness for enterprise customer requirements, and your ability to make secure the default path for engineering rather than a blocker. This role is perfect for a pragmatic, broad security engineer who has built and run security at a startup, thrives with autonomy, and wants to own a domain end-to-end. You'll be our founding internal security hire — but not a lone wolf for long: this is the first role in a function we expect to grow, and as we scale we'll add to the team and bring in dedicated security leadership. You'll set the foundations the rest of that team is built on, and have a clear runway to grow alongside it. YOUR CONTRIBUTIONS TO OUR JOURNEY: * Harden Our Cloud Infrastructure: Secure our AWS environment by design — identity and access management, hardening, network and infrastructure-as-code controls (Terraform) — closing real risk rather than chasing checkboxes * Own Application Security: Embed application security into how we build, from secure-by-default patterns and code review guidance to triaging and driving down vulnerabilities across our own products and services * Build Security Tooling and Monitoring: Stand up the monitoring, logging, and alerting that gives us visibility across infrastructure and applications, and serve as our first line of defence * Run Compliance Pragmatically: Lead readiness for SOC2, ISO27001, and similar frameworks — building the controls, documentation, and evidence that support enterprise sales without drowning the team in process * Establish Security Policies That Enable: Create practical security policies and procedures that keep standards high while letting the team move quickly — no security theatre * Automate Security Operations: Build security automation and tooling in code, using AI-assisted workflows to ship faster while keeping quality high * Manage Vendor and Supply-Chain Security: Assess third-party vendors and tools so our supply chain meets enterprise expectations * Enable Incident Response: Develop incident response plans and runbooks, and establish clear processes for detecting, responding to, and recovering from security incidents WHAT YOU NEED TO BE SUCCESSFUL: * Broad, Hands-On Security Engineering: 5+ years building and running security, with genuine breadth across cloud security and application security rather than depth in only one — comfortable being the person who covers the whole surface area * AWS Security Expertise: Deep, hands-on knowledge of AWS security — IAM, hardening, and AWS-native security tooling — with the judgement to prioritise what matters * Application Security Capability: Real experience finding and fixing application-layer vulnerabilities, and embedding secure development practices into engineering workflows * Infrastructure as Code Proficiency: Strong experience managing security controls programmatically with Terraform, building secure, scalable infrastructure through code * Coding and Scripting Skills: Proficiency in Python, Bash, or similar for security automation, custom tooling, and integrating security into development workflows * Compliance and GRC Know-How: Practical experience translating SOC2, ISO27001, or similar requirements into technical controls — without letting process become the product * Pragmatic Security Mindset: A track record of balancing security rigour with business velocity, implementing controls that enable engineering rather than block it * Startup Self-Direction: Proven ability to operate autonomously as an early security hire, prioritise ruthlessly, and build without extensive oversight — and to thrive in the ambiguity of an early-stage company * Foundation-Setter: Mindset to build security in a way others can build on as the team grows — clear documentation, repeatable processes, and standards a future team and security leadership inherit cleanly * Nice to haves: * Experience building security programs at early-stage startups (seed through Series B) * Background in DevOps or SRE that grew into security engineering * Familiarity with container security (Docker, Kubernetes) * Experience at a cybersecurity product company * A bias toward building vs buying security tooling under startup constraints * AI-assisted security workflow experience WHY JOIN US: * Ambitious Challenge: We're building at the intersection of generative AI (LLMs and agents) and cybersecurity — and you'll secure the company doing it, across cloud and application security. * Build Security from Zero: Own the internal security function from day one, establishing the architecture, tooling, and practices that scale Maze through hypergrowth — then help grow the team and function around you as we scale. * Expert Team: Work alongside a CTO and engineering team with deep experience in AI and cybersecurity — hands-on leaders who have been part of multiple acquisitions and an IPO — giving you strong technical partnership while you own security. * Impactful Work: Cybersecurity is a force for good. Your work directly enables AI-powered security solutions that protect organisations worldwide — making security an enabler of innovation, not a blocker. * Build an AI-native Company: Join early enough to design everything from the ground up, with significant equity upside and a clear path to grow as our security organisation matures.
Om din roll Som Cyber Security Specialist på Åhléns har du en central roll i att säkerställa att våra system, applikationer och molnmiljöer är säkra, robusta och tillgängliga för verksamheten. Du arbetar både operativt och strategiskt med säkerhet från att identifiera risker och hantera incidenter till att utveckla och implementera säkerhetslösningar och ramverk. Rollen innebär nära samarbete med arkitekter, utvecklare och andra delar av IT-organisationen, där du bidrar med din expertis för att stärka vår säkerhetsförmåga. I en verksamhet där digital utveckling är avgörande blir du en nyckelperson i att skydda affären och möjliggöra fortsatt innovation. Exempel på arbetsuppgifter: Utveckla och utvärdera säkerhetslösningar för molnbaserade system, databaser och nätverk Samarbeta med arkitekter och utvecklare kring säkerhetskrav och implementation Övervaka och analysera loggar för att identifiera hot och säkerhetsincidenter Genomföra sårbarhetsbedömningar och föreslå åtgärder Hantera och följa upp säkerhetsincidenter Ta fram säkerhetsrapporter på både teknisk och strategisk nivå Säkerställa att IT-miljön uppfyller krav enligt GDPR, NIS2 och ISO27001 Bidra till utveckling av arbetssätt, rutiner och säkerhetsramverk Varför Åhléns IT? I den här rollen blir du en del av en IT-organisation som befinner sig i en utvecklingsfas, där vi inte bara förvaltar utan bygger nytt. Vi arbetar i många delar med ett mer entreprenöriellt och utforskande arbetssätt – likt en startup – där idéer snabbt kan omsättas till verklighet och där du har stor möjlighet att påverka både riktning och lösningar. Här får du en viktig roll i att forma och utveckla vårt säkerhetsarbete framåt, i nära samarbete med verksamheten och andra delar av IT. Du blir en del av ett engagerat team där vi tillsammans driver utveckling, testar nytt och skapar framtidens lösningar för Åhléns. Till oss tar du med dig: Erfarenhet av arbete inom cybersäkerhet Erfarenhet av säkerhetslösningar inom infrastruktur, applikationer eller IAM Erfarenhet av säkerhetsövervakning och incidenthantering Förståelse för molnbaserade miljöer Kunskap om regelverk och standarder som GDPR Certifieringar som CISSP eller liknande är meriterande Vi på Åhléns vet att alla inte kan göra allt, men att alla kan göra något. För att lyckas i rollen ser vi att du är en ansvarstagande och lösningsorienterad person som drivs av att skapa säkra och stabila IT-miljöer. Du har ett analytiskt förhållningssätt och trivs med att arbeta både proaktivt och reaktivt i säkerhetsfrågor. Du är kommunikativ och kan förklara tekniska säkerhetsfrågor på ett tydligt sätt, både till tekniska kollegor och till verksamheten. Samtidigt är du strukturerad och stresstålig, och kan prioritera rätt när det uppstår incidenter eller förändringar. Om rekryteringen Tjänsten är en tillsvidareanställning på heltid och är placerad på Åhléns huvudkontor i Stockholm. Urval och intervjuer sker löpande och tjänsten kan tillsättas innan sista ansökningsdag, så skicka in din ansökan redan idag! Som en del av vår rekryteringsprocess använder vi Alva Labs arbetspsykologiska tester för att skapa en rättvis, träffsäker och datadriven bedömning. Som Cyber Security Specialist på Åhléns blir du en del av ett passionerat team som drivs av affärsmannaskap och entreprenörskap. Vi ger dig förtroende och möjligheten att växa i en utvecklande miljö. Med det hälsar vi dig varmt välkommen till Åhléns!
SpaceXAI’s mission is to create AI systems that can accurately understand the universe and aid humanity in its pursuit of knowledge. Our team is small, highly motivated, and focused on engineering excellence. This organization is for individuals who appreciate challenging themselves and thrive on curiosity. We operate with a flat organizational structure. All employees are expected to be hands-on and to contribute directly to the company’s mission. Leadership is given to those who show initiative and consistently deliver excellence. Work ethic and strong prioritization skills are important. All employees are expected to have strong communication skills. They should be able to concisely and accurately share knowledge with their teammates. ABOUT THE ROLE: We are seeking a skilled Azure Security Engineer to design, implement, and maintain robust security controls across our Azure Gov Cloud environment (including hybrid and multi-cloud scenarios). In this hands-on role, you will build, strengthen, and maintain our cloud security posture, protect critical workloads, and collaborate with engineering, DevOps, and compliance teams to embed security throughout the development lifecycle. You will develop, implement, and leverage Microsoft’s native security tools to detect threats, respond to incidents, and ensure alignment with industry standards and regulations. Lastly, you will be required to both achieve and maintain compliance with government regulations such as FedRAMP and CMMC. RESPONSIBILITIES: * Implement, design, and manage security architecture for Azure Government and Commercial deployments (with considerations for DoD IL5\IL6 and FedRAMP High controls) * Configure and optimize Microsoft Defender for Cloud, Microsoft Sentinel, Microsoft Defender for Endpoint, and related services for threat detection, vulnerability management, and automated response * Design and enforce identity & access management using Microsoft Entra ID, Privileged Identity Management (PIM), Conditional Access policies, RBAC, and just-in-time access * Secure network architectures with Azure Firewall, Network Security Groups (NSGs), DDoS Protection, Web Application Firewall (WAF), Network Watcher, and private endpoints * Protect data at rest and in transit via Azure Key Vault, encryption strategies, data classification, and information protection controls * Develop and maintain security policies, initiatives, and blueprints using Azure Policy and Microsoft Purview for compliance (NIST, FedRAMP, CMMC, STIGs, etc.) * Perform threat hunting, incident response, and forensics using Sentinel playbooks, Log Analytics, and KQL queries * Conduct security reviews of Infrastructure as Code (IaC), containers, Kubernetes (AKS), and serverless workloads * Collaborate with developers and architects to implement DevSecOps practices, including secure CI/CD pipelines, code scanning, and secure defaults * Monitor and remediate security findings, reduce attack surface, and improve overall security posture per the Microsoft Cloud Security Benchmark (MCSB) * Deploy configurations and compliance policies to Azure AVD endpoints using Intune and other Azure native services. BASIC QUALIFICATIONS: * Active U.S. security clearance (e.g., Secret, Top Secret) or eligibility to obtain one. * 3+ years of experience in cloud security, cybersecurity engineering, or related roles (with strong Azure focus) * Deep hands-on expertise with core Azure security services: Microsoft Defender suite, Sentinel, Intune, Entra ID, Key Vault, Azure Policy, Firewall, Network Watcher, and Purview * Strong understanding of DLP implementation both in cloud and on endpoints utilizing Purview and other Microsoft native controls * Experience implementing security in hybrid/multi-cloud environments * Proficiency in scripting/automation (PowerShell, Azure CLI, Bicep/ARM templates, Terraform) * Strong understanding of identity federation, zero-trust principles, encryption, network security, and vulnerability management * Familiarity with compliance frameworks (NIST, FedRAMP, CMMC, STIGs, etc.) and regulatory requirements * Excellent problem-solving, analytical, and communication skills * Strong verbal and written communication skills and the ability to stay composed under pressure. PREFERRED SKILLS AND EXPERIENCE: * Microsoft Certified: Azure Security Engineer Associate (AZ-500), Microsoft Cybersecurity Architect (SC-100) * Additional relevant certifications (e.g., CISSP, CCSP, Microsoft Certified: Azure Administrator, AWS Security Specialty, SANS GCPS, SANS GCAD) * Deep experience with detection and response engineering and SOC operations * Knowledge of container security (Docker, AKS), secure DevOps, or AI/ML workload protection * Prior experience in government regulations frameworks such as FedRAMP and CMMC. COMPENSATION AND BENEFITS: $100,000 - $258,000 USD Base salary is just one part of our total rewards package at SpaceXAI, which also includes equity, comprehensive medical, vision, and dental coverage, access to a 401(k) retirement plan, short & long-term disability insurance, life insurance, and various other discounts and perks. ITAR REQUIREMENTS: * To conform to U.S. Government export regulations, applicant must be a (i) U.S. citizen or national, (ii) U.S. lawful, permanent resident (aka green card holder), (iii) Refugee under 8 U.S.C. § 1157, or (iv) Asylee under 8 U.S.C. § 1158, or be eligible to obtain the required authorizations from the U.S. Department of State. Learn more about the ITAR here. SpaceXAI is an equal opportunity employer. For details on data processing, view our Recruitment Privacy Notice.
Build the Future of Technology with Professional Galaxy AB Join a network of talented engineers, developers, cloud specialists, and AI innovators working on impactful projects across Sweden and Europe. At Professional Galaxy AB, we connect top tech talent with organizations driving digital transformation in areas like cloud computing, software engineering, data, cybersecurity, and artificial intelligence. Explore exciting opportunities and grow your career while working with cutting-edge technologies and forward-thinking teams. We are looking for a Cyber Security Advisor Responsibilities: Act as a trusted advisor to management and key stakeholders, ensuring cybersecurity considerations are integrated into decision-making Ensure cybersecurity best practices align with business objectives and delivery goals without hindering operational efficiency Provide cybersecurity expertise during projects and engagements to mitigate risks and enhance security controls Work with cross-functional teams to enhance the organization’s overall cybersecurity resilience Identify, assess, and provide guidance on mitigating cybersecurity risks across business functions Support compliance with relevant cybersecurity laws, regulations, and industry standards Contribute to the development and implementation of security strategies, policies, and frameworks Promote cybersecurity awareness and best practices among employees and stakeholders Qualifications: Typically 10+ years of experience in cybersecurity, information security, IT governance, risk management, or compliance Bachelor’s degree in Computer Science or related field (or equivalent experience) Proven leadership in security governance frameworks, policies, and strategies Experience aligning security and data privacy with business objectives at a strategic level Hands-on experience with enterprise risk management and compliance frameworks (e.g., GDPR, ISO 27001, NIST, PCI DSS) Strong expertise in third-party/vendor risk management Experience in security incident response and crisis management Ability to influence senior leadership and board-level stakeholders Additional qualifications (optional): Strong communication skills and stakeholder management Business understanding with security impact awareness Ability to analyze and mitigate security risks Certifications such as CISSP, CIPM, CISA, ISO/IEC 27001 Lead Auditor Specializations such as AI Governance, Cloud Security, or CIPP/E Uppdragsinformation: Uppdragslängd: 2026-05-04 – 2026-09-30 Placeringsort: Stockholm Svar önskas snarast, dock senast 2026-05-03. How to Apply: Please apply via the Professional Galaxy AB portal with: Your updated CV Your availability to start A motivation statement describing your suitability Please note: Applications via email will not be accepted. All applications must be submitted through the portal. Öppen för alla Vi fokuserar på din kompetens, inte dina övriga förutsättningar. Vi är öppna för att anpassa rollen eller arbetsplatsen efter dina behov.
About the Role We are looking for a Cloud Solution Architect who can design scalable, secure, and high‑performance cloud solutions that support our product and business goals. You will work closely with engineering, product, data, and security teams to define architecture standards, modernize infrastructure, and guide the organisation toward a cloud‑native, automation‑driven future. This role is ideal for someone who enjoys solving complex technical problems, influencing engineering direction, and building systems that scale reliably. Key Responsibilities Design end‑to‑end cloud architectures across compute, storage, networking, security, and data platforms. Lead cloud solution design sessions, architecture reviews, and technical decision‑making. Build reference architectures, reusable frameworks, and best practices for engineering teams. Drive cloud modernization initiatives including microservices, containerization, DevOps, and automation. Collaborate with product and engineering teams to translate business requirements into technical solutions. Ensure cloud environments follow strong security, governance, and compliance standards. Optimize cloud cost, performance, and reliability through continuous monitoring and improvements. Provide technical leadership on cloud migrations, integrations, and platform scalability. Evaluate new cloud services, tools, and technologies to strengthen our architecture roadmap. Mentor engineers and promote architectural excellence across teams. Core Competencies & Skills Technical Skills Strong expertise in at least one major cloud platform: Azure, AWS, or Google Cloud. Hands‑on experience with: Cloud networking, IAM, VPC/VNet design Serverless, containers (Docker, Kubernetes), microservices CI/CD pipelines and DevOps tooling Infrastructure as Code (Terraform, ARM, CloudFormation, Pulumi) Cloud security, encryption, identity, and governance Solid understanding of distributed systems, API design, and event‑driven architectures. Experience with data platforms: data lakes, ETL pipelines, streaming, or analytics tools. Soft Skills Strong communication and stakeholder management. Ability to simplify complex technical concepts for non‑technical teams. Strategic thinking with a hands‑on execution mindset. Comfortable working in fast‑moving, ambiguous, and high‑growth environments. Preferred Qualifications 7–12 years of experience in cloud engineering, architecture, or platform roles. Cloud certifications (Azure Architect Expert, AWS Solutions Architect Professional, GCP Professional Cloud Architect) are a plus. Experience in startup or scale‑up environments. Proven track record of leading architecture transformations or cloud migrations. Location & Work Model Hybrid work model with periodic onsite collaboration. Open to candidates willing to relocate based on business needs. Why Join Us Opportunity to shape the cloud architecture of a growing organisation. High ownership, autonomy, and influence on technical direction. Work with a collaborative, product‑driven, and engineering‑focused team. Build systems that directly impact scalability, performance, and customer experience.
About the job Are you a skilled Cyber Security Engineer with a talent for finding gaps in the most secure systems? We’re looking for someone to perform in-depth penetration testing across various technologies, including Windows and Linux environments, Citrix Workspaces, Cloud infrastructures, and APIs. You will use the latest tools and techniques to uncover vulnerabilities and work alongside our development and security teams to address and fix them. If you're ready to tackle complex security challenges, we want to hear from you! The ideal profile The perfect candidate is a highly skilled and detail-oriented Cyber Security Engineer with genuine hands-on experience in penetration testing and vulnerability analysis. You have excellent written and verbal communication skills and are a strong problem-solver. You thrive both working independently and collaborating within a team, always ready to tackle challenges with analytical precision. Qualifications: You have a strong understanding of network protocols, both Windows and Linux operating systems, application architectures and Red Hat In-depth knowledge of common vulnerabilities and exploits (CVEs) Proficiency in using various penetration testing tools such as Metasploit, Nmap, Burp Suite and/or Nessus Additional skills: Experience with cloud security, particularly AWS. Knowledge of scripting languages (e.g., Python, PowerShell). Familiarity with source code review techniques. Understanding of frameworks like ISO 27001, NIST, CIS Security certifications such as OSCP, CEH, PEN TEST+
At HiQ, every challenge is an invitation to explore new possibilities. We’re looking for someone who thrives on the thrill of discovery, who sees every system as a puzzle waiting to be solved, and who finds energy in the pursuit of safer, smarter digital solutions. As part of our Pentest team, you’ll be at the heart of our mission to build secure applications and environments for some of the most exciting organizations in the Nordics. Your days will be filled with hands-on penetration testing, creative problem-solving, and the freedom to dive deep into the latest tools and techniques. Whether you’re orchestrating a Red Team engagement or probing the intricacies of cloud security, you’ll have the autonomy to shape your own approach, while always knowing that a team of passionate experts has your back. You’ll work with Burp Suite, Nmap, Wireshark, and a host of other tools, sometimes in the cloud, sometimes on-prem, always at the cutting edge. Your experience with Active Directory and scripting will come to life as you navigate complex environments, uncover vulnerabilities, and help our clients see their systems through a new lens. If you’ve cracked hashes, explored mobile app security, or sharpened your skills in CTFs, you’ll find plenty of opportunities to push your expertise even further. WHAT YOU BRING * At least 5 years of practical experience in penetration testing or Red Team operations * Deep familiarity with industry-standard tools such as Burp Suite, Nmap, and Wireshark * Strong background in assessing and securing web applications * Proven experience performing Active Directory and broader network security assessments * Understanding of modern cloud platforms and architectures * Scripting skills that enable you to automate workflows and develop new solutions * Relevant education and/or certifications (e.g., OSCP, OSCE, AWS/Azure Security) * Excellent communication skills, with the ability to clearly document and articulate vulnerabilities and recommendations * Swedish citizenship, as HiQ carries out security-classified assignments that may require it BONUS SKILLS * Experience with hash cracking * Knowledge of mobile application security * Knowledge in cloud security * Networking know-how * Capture the Flag participation * Insights into computer forensics Here, learning is woven into the fabric of every project. Whether you’re pursuing new certifications, experimenting with the latest exploits, or sharing insights with colleagues, you’ll find endless room to grow. We celebrate curiosity and initiative, if you spot an opportunity to make something better, you’ll have the freedom and support to make it happen. You’ll be trusted to run penetration tests independently, but you’ll never be alone. Collaboration is second nature here: ideas bounce, knowledge flows, and everyone’s voice matters. You’ll document your findings with clarity, communicate risks with empathy, and help guide clients toward stronger, more resilient solutions. If you’re ready to join a team where your passion for security is matched only by your drive to learn and create, we’d love to meet you. Ready to take the next step? Apply now and let’s build something extraordinary together.
SUMMARY OF THE ROLE: As a Security Research Engineer at Maze, you'll be at the forefront of defining what constitutes real security risk in the age of AI-powered vulnerability detection. This is a unique opportunity to join our growing security research team at a well-funded startup building at the intersection of generative AI and cybersecurity, where your security expertise directly shapes how our AI models understand and prioritize cloud security threats. You'll spend the majority of your time as the expert human-in-the-loop, analyzing cloud vulnerability findings from our AI systems, conducting deep research to validate and contextualize threats, and creating the authoritative labels that train our models to distinguish critical risks from noise. Working alongside other security researchers, you'll help scale our labeling operations while providing critical input into product development decisions based on real-world threat patterns you discover. This role is perfect for a security researcher who wants to pioneer the future of AI-assisted threat detection, loves diving deep into cloud security vulnerabilities, and wants to see their security insights amplified through cutting-edge technology while contributing to a growing team. YOUR CONTRIBUTIONS TO OUR JOURNEY: * Scale Expert Data Labeling Operations: Lead high-volume vulnerability labeling and validation work as the authoritative voice on threat severity, reviewing and categorizing cloud security findings from our AI models to create the high-quality training data that powers our platform * Drive Product Development Through Research Insights: Translate patterns and insights from your labeling and research work into actionable product improvements, working directly with engineering and product teams to enhance detection capabilities and user experience * Collaborate with Security Research Team: Work closely with fellow Security Research Engineers to maintain consistency in labeling standards, share research findings, and collectively improve our vulnerability assessment methodologies * Deep Vulnerability Research: Conduct comprehensive research into cloud vulnerabilities affecting EC2 images, Docker containers, and cloud infrastructure, investigating true/false positives, analyzing business impact, and building proof-of-concepts to validate threat scenarios * Enhance AI Model Accuracy: Provide expert feedback through our labeling tools that improves our AI models' understanding of vulnerability context, helping them learn to prioritize threats like a seasoned security researcher * Technical Investigation and Analysis: Create detailed technical writeups about exploitation techniques, attack vectors, and remediation strategies for cloud vulnerabilities, turning complex security research into actionable intelligence * Leverage External Security Intelligence: Integrate insights from CVE databases, security advisory feeds, and threat intelligence sources to enrich vulnerability findings with broader context and emerging threat patterns * Contribute to Thought Leadership: Support our external presence through technical blog posts, security videos/podcasts, and occasional conference presentations, sharing insights from your research WHAT YOU NEED TO BE SUCCESSFUL: * Security Research Expertise: 5+ years of hands-on security experience with proven vulnerability research background, comfortable investigating complex security issues and building proof-of-concepts to validate findings * Cloud Security Mastery: Deep knowledge of AWS security, cloud infrastructure vulnerabilities, container security, and cloud-native attack vectors, with hands-on experience securing cloud environments at scale * Technical Investigation Skills: Strong coding and scripting abilities (Python, Go, or similar) for automating research tasks, building validation tools, and creating proof-of-concept exploits * Analytical Excellence: Proven ability to analyze complex security data, distinguish between critical threats and false positives, and communicate technical findings to both technical and business audiences * Product Mindset: Experience translating security insights into product requirements, with ability to identify patterns across vulnerabilities that inform strategic product decisions * External Intelligence Integration: Experience working with vulnerability databases, security advisory feeds, and threat intelligence sources to contextualize and prioritize security findings * Collaborative Mindset: Strong communication skills and ability to work effectively with security research peers, AI/ML teams, and product stakeholders, translating security domain knowledge into actionable improvements * High-Volume Execution: Comfort with systematic labeling work while maintaining accuracy and attention to detail, balancing speed with quality in fast-paced environments * Nice to haves: * Experience with AI/ML security or working with AI-generated security findings * Background at security tooling companies or building security products * Expertise in specific vulnerability research methodologies and frameworks * Open source contributions to security tools or research projects * Previous content creation experience in security (blogs, talks, research papers) * Industry certifications (CISSP, OSCP, AWS Security, etc.) WHY JOIN US: * Ambitious Challenge: We're using generative AI (LLMs and agents) to solve some of the most pressing challenges in cloud security today. You'll be defining how AI understands and prioritizes vulnerabilities, working at the cutting edge of AI-powered threat detection. * Expert Team: We are a team of hands-on leaders with experience in Big Tech and Scale-ups. Our team has been part of the leadership teams behind multiple acquisitions and an IPO. * Growing Security Research Function: Join a collaborative security research team where you'll work alongside other experts, share insights, and collectively shape how our AI platform understands security threats at scale. * Impactful Work: Your security research and labeling work will directly improve how thousands of organizations understand and respond to cloud security threats, scaling expert security knowledge through AI to protect the entire ecosystem. * Product Influence: Your day-to-day research insights will directly influence product strategy and development, giving you a voice in building the next generation of AI-powered security tools. * Pioneer AI-Native Security: Help establish the gold standard for AI-assisted vulnerability research, defining how human security expertise enhances machine learning models in the cybersecurity domain.
About Consilium Safety Group At Consilium Safety Group, we don’t just build technology, we create solutions that protect people, assets, and the planet. As a global leader in fire and gas safety, we serve critical industries such as marine, energy, rolling stock, and infrastructure. With more than 100 years of expertise, we combine deep industry knowledge with cutting-edge innovation to shape the future of Safety Tech. Headquartered in Gothenburg, Sweden, and operating in over 55 locations worldwide, we are a fast-growing global organization backed by Antin Infrastructure Partners. With strong financial support and a clear strategic vision, we are on an ambitious journey of growth and transformation, investing in innovation, operational excellence, and talent. This is an exciting time to join us. We are now looking for an Information Security Engineer to join the information security team at Consilium! About the Role As an Information Security Engineer at Consilium, you will combine hands-on security operations with strategic governance and compliance work. In practice, the role is split into two central pillars: Operational Excellence: Working hands-on to implement security controls, managing daily security activities, and acting as an internal subject matter expert. Strategic and Compliance-Oriented Leadership: Developing and driving our security strategy, ensuring we meet regulatory requirements, and continuously strengthening our security posture. You will help protect Consilium’s information assets, lead compliance efforts related to NIS2, and support alignment with frameworks such as NIST CSF, ISO 27001, the EU CRA, and the AI Act. The role works closely with teams across IT, HR, R&D, Sales, and Marketing. Your Main Responsibilities In this role, you will manage day-to-day security operations activities as well as strengthening the ISMS, implement controls aligned with ISO 27001, NIS2, and NIST CSF, coordinate audits, develop policies, and provide risk reporting and advisory support across the business. Qualifications and Experience To succeed in this role, you bring strong technical security knowledge, incident-handling capability, and an interest in governance and compliance. Requirements Technical Environment: Solid understanding of Microsoft Defender suite, Azure/O365, Windows, and Linux. Networking & Security Tools: Strong knowledge of TCP/IP, segmentation, firewalls, SIEM, EDR/EPP, and patch management. Automation: Basic to intermediate scripting skills (PowerShell, Python, Bash, KQL, or Graph API). Incident & Frameworks: Experience with log analysis, incident lifecycles, and frameworks like ISO 27001 or NIST CSF. Communication: Ability to explain technical security concepts clearly to non-technical stakeholders. Meriting Hands-on experience with Microsoft's advanced security stack (Sentinel, XDR, Entra, Intune, Purview/Priva). Cloud security controls (Azure), DevSecOps (GitHub Advanced Security), or direct audit-evidence collection experience. Previous experience working with audits and evidence collection linked to ISO 27001/NIS2/NIST CSF. Who Are We Looking For? We are looking for someone with hands-on experience in IT security and information security compliance, along with a solid understanding of relevant regulations and security frameworks. You are structured, analytical, and able to communicate clearly with a wide range of stakeholders. Personal Attributes You are analytical, proactive, and solution-oriented, with high integrity and a structured way of working. You communicate clearly, work well independently, and build strong relationships across technical and non-technical teams. What We Offer At Consilium Safety Group, you will join an innovative international environment where quality and safety come first. This is a high-impact role with opportunities to shape global security initiatives, along with a competitive salary, benefits, and career development. Apply Now Does this sound like your next challenge? Submit your application as soon as possible, as we review applications on a rolling basis. Consilium Safety Group is an equal opportunity employer committed to diversity and inclusion. Ready to learn more about our journey? Hear from our CEO: Philip Isell Lind af Hageby, Consilium, en mästare på turnarounds - Värdeskaparna | En podd om riskkapital av OPX Partners | Podcast on Spotify
TL;DR: We're looking for an exceptional security leader and executive to build and run the function that will make Lovable the most trusted AI-powered software creation platform Why Lovable? Lovable lets anyone and everyone build software with any language. From solopreneurs to Fortune 100 teams, millions of people use Lovable to transform raw ideas into real products - fast. We are at the forefront of a foundational shift in software creation, which means you have an unprecedented opportunity to change the way the digital world works. Lovable-built applications and websites are visited hundreds of millions of times a month, and our enterprise footprint is compounding fast. And we're just getting started. We're a small, talent-dense team building a generation-defining company from Stockholm. We value extreme ownership, high velocity, and low-ego collaboration. We seek out people who care deeply, ship fast, and are eager to make a dent in the world. What we're looking for 10+ years in information security, including 3+ years leading security at a high-growth SaaS or platform company A track record of building security programs from the ground up, including scaling through SOC 2, ISO 27001, or equivalent enterprise frameworks Deep technical fluency across cloud, application, and infrastructure security — comfortable going hands-on, not just directing others Experience partnering with engineering, legal, and sales to close enterprise deals and pass customer due diligence The judgment and communication skill to translate technical risk into business decisions for an executive team and board Experience securing platforms that generate or execute user-created code, or prior experience as a founding security hire at a startup What you'll do Own Lovable's security strategy and risk management framework end to end, reporting directly to the executive team Build and lead the security organization, starting with our first security engineers and analysts Get Lovable certified against the frameworks our enterprise customers require, including SOC 2 Type II and ISO 27001 Own application, infrastructure, and cloud security — secure SDLC, vulnerability management, incident response Partner with Sales and Customer Success to move security reviews and questionnaires from blocker to closer Build the security-first culture and training that lets a fast-moving engineering org stay fast without cutting corners Be the person our team, our customers, and regulators call when something needs an answer About your application Please submit your application in English. It's our company language, so you'll be speaking lots of it if you join. We treat all candidates equally - if you're interested, please apply through our careers portal.
Why Join Us? We’re on a mission to empower people with disabilities to do what they once did or never thought possible. As the world-leader in assistive communication solutions, we empower our customers to express themselves, connect with the world, and live richer lives. At Tobii Dynavox, you can grow your career within a dynamic, global company that has a clear, impactful purpose - with the flexibility to also do what truly matters to you outside of work. What’s more, you’ll be part of a work culture where collaboration is the norm and individuality is welcomed. As a member of our team, you’ll have the power to grow ideas in an unconventional environment. At the same time, you’ll work in a culture of ongoing learning and development, allowing you to constantly expand your area of expertise. Summer Holiday Notice Our team will be taking a summer break, and as a result, the recruitment process will move at a slower pace during this period. We will begin reviewing applications in the second half of August and will get back to candidates thereafter. Thank you for your patience, and we look forward to receiving your application! About the role We are looking for a Security Operations Engineer to join our global IT Operations team. As part of IT Operations, you will take ownership of operational security processes and controls. Ensuring our environment is secure, stable, and aligned with ISO27001 requirements. You will work hands on with implementing, monitoring and continuously improving security controls across endpoints, identity, network and Microsoft 365. Key responsibilities Security Operations Implement and continuously improve security controls across the IT environment Make sure logging, monitoring, and detection actually work in practice Investigate and respond to security incidents in collaboration with the Information Security team Security Processes Own and operate core IT-operations security processes, including: Access management (joiner / mover / leaver) Vulnerability and patch management Security validation in change processes Secure configuration baselines Keep these processes practical, measurable, and continuously improving over time Platform Security (Endpoint, Identity & Cloud) Manage and improve security across endpoints, identity, and cloud platforms Enforce secure configurations using tools such as Intune, Defender, and Entra ID Implement and maintain controls such as MFA, Conditional Access, and least privilege access Support secure lifecycle management of devices and identities Compliance & Audit support Ensure security controls align with ISO27001 requirements and work in practice Own technical audit readiness and evidence for IT Operations Collaborate on risk assessments, gap analyses, and remediation activities Support internal and external audits from a technical perspective Required skills & experience Experience in security operations or security engineering in an enterprise environment Hands-on experience with Microsoft security tools (e.g., Defender, Intune, Entra ID, Microsoft 365, Azure) Good understanding of endpoint, identity, and cloud security Experience with incident handling, vulnerability management, and security monitoring Familiarity with ISO27001 or similar frameworks Ability to work independently and take ownership of security initiatives within IT Operations Who you are Structured and pragmatic, with a focus on solving problems in a practical way Proactive and willing to take ownership of tasks and improvements Comfortable working independently, while collaborating with others when needed Communicates clearly with both technical and non-technical stakeholders Calm and methodical when handling incidents and operational challenges Apply today! We believe in empowering individuals - including our own employees - to reach their full potential. So, if you want to change lives while growing your own career, we’d love to hear from you. Where we stand: We believe diversity not only enriches our workplace culture, but also gives us a strategic advantage. Working with people from a variety of backgrounds and perspectives helps us all become better communicators, better problem solvers, and better human beings. Our differences make us stronger. Tobii Dynavox values equality of opportunity, human dignity, and racial/ethnic and cultural diversity. Tobii Dynavox does not discriminate against individuals on the basis of race, color, sex, sexual orientation, gender identity, religion, disability, age, veteran status, ancestry, or national or ethnic origin. Equal Opportunity Employer/AA Women/Minorities/Veterans/Disabled
EQT is looking for an Application & AI Cyber Security Engineer to join our Cyber Security Engineering team, owning the security posture of our hosted applications, container platforms, and AI environments. This is a hands-on engineering role where you will build automated guardrails and real-time visibility — making the secure path the easy path across a modern, globally distributed technology landscape. ABOUT THE TEAM The Cyber Security Engineering team defines and validates security standards across EQT's technology landscape. Operating as a trusted security function, the team works closely with platform engineering, cloud infrastructure, identity, and technology assurance teams to strengthen controls while enabling innovation. This role sits within a small, high-trust team where collaboration, curiosity, and technical depth are core to how we work. The team supports both traditional application environments and emerging AI and agentic platforms, helping EQT navigate a rapidly evolving threat landscape with practical, engineering-led security standards. You will report to the Head of Digital Employee Experience and partner closely with the CISO function, contributing engineering depth directly to governance and policy decisions. ABOUT THE ROLE This role brings together application security, container security, and AI security into one evolving discipline — giving you the scope to influence standards, technical controls, and governance frameworks across a global technology environment. The mandate is to build automated guardrails and observability at scale, not to review individual applications by hand. * Design and deploy automated controls for container platforms and application deployments — admission controllers, policy-as-code, and pre-configured scanning — that enforce standards at the point of deployment rather than after the fact. * A growing part of the job is enabling citizen development — making sure non-technical teams can use AI coding tools like Claude Code and CoWork without needing to come through security first, because the guardrails are already there. * Curate internal security tooling, automation, and AI skills for cost, reliability, and security posture — favouring deterministic, scripted components that run fast and cheap over token-intensive approaches, and tracking cost-per-outcome across security controls as a core operating discipline. * Own container security standards as enforceable controls: image scanning policy, runtime baselines, and registry governance across all deployment paths, including workloads outside formal pipelines. * Manage software supply chain risk end-to-end, including dependency scanning, build-time and runtime composition analysis, and identifying high-propagation risk junctions. * Build application security observability that goes beyond static inventories — a live picture of what is deployed, what it is composed of, and where risk is concentrated — and provide actionable dashboards for engineering leadership and the CISO function. * Own the security configuration of EQT's AI platforms, including hardening, access controls, data flow governance, and defences against prompt injection and data exfiltration. * Assess MCP connector risk — API call patterns, data processing terms, allowlist maintenance, and dependency chains — and evaluate new AI tools with enough technical depth to inform CISO-level approval decisions. * Define behavioural baselines for agentic execution environments and close AI-specific insider threat gaps, ensuring monitoring tools can see into AI data flows. * Collaborate with Detection & Insider Threat Engineers on container runtime telemetry, and with Identity & Cloud Security Engineers on service identity, workload access, and secrets management. TOOLS YOU'LL WORK WITH Kubernetes, CI/CD platforms, SBOM tooling, Aikido, Claude Enterprise, Claude Code, MCP, CoWork, DTEX, Datadog, policy-as-code frameworks. ABOUT YOU You are a technically grounded security engineer who cares deeply about developer experience and approaches security friction as a design problem to solve, not a trade-off to accept. You work with clarity and ownership, communicate technical findings to senior stakeholders with confidence, and are actively building your knowledge of AI and agentic security. What you'll bring (must-have): * Proven hands-on experience with container security — Kubernetes, image scanning, admission control, runtime protection, and policy-as-code. * A track record of building automated security controls that scale, with an instinct for making the right path easy and the wrong path hard rather than relying on manual review. * Solid application security fundamentals, including familiarity with OWASP Top 10, secure development lifecycle, and software supply chain risk, with an orientation toward enforcement over assessment. * Experience building security visibility into running systems through instrumentation, runtime analysis, or operational dashboards — understanding the difference between knowing what was shipped and knowing what is actually executing in production. * Active use of AI-assisted development tools in your own engineering work (such as Claude Code, GitHub Copilot, or equivalent); this role is designed around that way of working. * Early or growing experience in AI and LLM security — including prompt injection, data exfiltration, model API security, or agentic system controls — and a clear appetite to develop expertise in this space. * The ability to communicate complex technical findings clearly and concisely to senior stakeholders who will translate them into policy and governance decisions. Nice to have: * Familiarity with tools such as CrowdStrike, Aikido, Bold Security, Nightfall, Zscaler, or Lakera Guard. * Experience with MCP (Model Context Protocol), agentic frameworks, or AI platform administration. * Background working in private equity, financial services, or other environments where non-public information is a primary asset requiring protection. * Experience measuring and optimising the operational cost of security controls. * Comfort deploying and working with local open-source LLMs for automation use cases. HOW WE THINK ABOUT THIS ROLE Application security and AI security share a common threat model — data exfiltration, supply chain compromise, and the boundary between trusted and untrusted code. AI connectors that interact with hosted services sit squarely in both domains. Splitting them into separate roles at a five-person team would create seams in exactly the places attackers exploit. The role is also shaped by a bet on AI-augmented engineering. An engineer with good tooling, a real token budget, and the discipline to automate before they assess can cover ground that would have required a larger team not long ago. We've designed the headcount around that — not to cut corners, but because the best security engineering now looks like one person building excellent guardrails with AI, not several people reviewing things by hand. WHAT WE OFFER At EQT, you will work in an environment that combines high impact with high trust, contributing to security challenges that matter at a global scale. You will help shape practices in areas that are rapidly evolving across the industry — AI security, software supply chain security, and modern application platforms — with direct influence on governance decisions and engineering standards. We offer meaningful and complex work with global reach, close collaboration with experienced colleagues across security, engineering, and technology, and genuine exposure to emerging AI technologies and cloud-native platforms. EQT has a culture that values curiosity, ownership, and continuous learning, with real opportunities for professional development in a fast-moving environment. COMPENSATION & BENEFITS NOTICE We offer a competitive total rewards package including base salary, determined based on the role, experience, skill set, and location. Eligible employees may also receive discretionary incentive compensation, awarded in recognition of individual performance and company results. EQT provides a comprehensive benefits offering designed to support employee wellbeing, development, and work-life balance. Benefits include paid time off, parental leave, wellbeing and wellness support, flexible working arrangements, and learning and development opportunities. Benefits are effective from the first day of employment and may vary by location and role. Inclusion at EQT Our vision for EQT employees is to build high performing & engaged teams. Our competitive edge comes from fostering an environment where every individual feels valued, empowered, and motivated to drive business impact. Our commitment to inclusion is not just about fairness; We understand and believe that being a great place to work drives the best performance.At EQT, inclusion is a business imperative and it's embedded into our talent strategy, decision-making, and culture to ensure that every individual and team operates at their full potential. By doing so, we unlock better collaboration, stronger innovation, and superior investment outcomes. About EQT EQT is a purpose-driven global investment organization focused on active ownership strategies. With a Nordic heritage and a global mindset, EQT has a track record of over three decades of developing companies across multiple geographies, sectors and strategies. EQT has investment strategies covering all phases of a business’ development, from start-up to maturity. EQT has EUR 270 billion in total assets under management (EUR 141 billion in fee-generating assets under management), within two business segments – Private Capital and Real Assets. With its roots in the Wallenberg family’s entrepreneurial mindset and philosophy of long-term ownership, EQT is guided by a set of strong values and a distinct corporate culture. EQT manages and advises funds and vehicles that invest across the world with the mission to future-proof companies, generate attractive returns and make a positive impact with everything EQT does. EQT has offices in more than 25 countries across Europe, Asia and the Americas and has more than 1,900 employees. More info: www.eqtgroup.com Follow EQT on LinkedIn, X, YouTube and Instagram
We are now looking for a Senior IT Security Architect who wants to play a key role in helping our customers build resilient, modern, and business-aligned security architectures. With us, you will work at the forefront of cybersecurity alongside some of the industry’s leading specialists — in a company with a strong expert profile, a solid culture, and international reach. This role is for someone highly senior who understands that good security architecture is not only about controls and technology, but about creating customer value: reducing risk, enabling transformation, supporting compliance, improving decision-making, and building solutions that remain effective over time. You are expected to take ownership of the bigger picture, challenge stakeholders at the right level, build trust in executive-level discussions, and at the same time possess sufficient technical depth to make sound architectural decisions. Example of responsibilities: Lead and drive security architecture initiatives in complex customer environments Develop target architectures, current-state assessments, gap analyses, and transformation roadmaps Advise customers on Zero Trust strategy and architecture, including identity-centric security, segmentation, least privilege, continuous verification, and secure access Design security architectures for hybrid environments, datacenters, networks, identity, endpoints, applications, and cloud services Support customers in architectural matters related to AWS, Azure, and GCP Ensure that security solutions support business objectives, risk management, and regulatory requirements Facilitate workshops, lead design decisions, and prepare decision-making material for both technical and business-oriented stakeholders Act as a strategic advisor to CISOs, IT leadership, architecture boards, and projects/programs Contribute to the continued development of our offerings, methodologies, and best practices within security architecture Your Profile We are looking for someone clearly senior, with many years of experience in security architecture, complex IT environments, and advisory work toward customers or larger internal organizations. You are confident in your expertise, comfortable taking ownership, and capable of connecting technology, risk, and business value. We believe you have: Extensive experience working as a Security Architect, Enterprise Architect with a security focus, or a similar senior advisory role Strong understanding of security architecture across several of the following areas: Zero Trust, IAM/PAM, network security, cloud security, hybrid architecture, endpoint security, application security, data protection, and logging/monitoring Proven experience translating security requirements and risks into concrete architectural decisions and actionable plans The ability to lead workshops, facilitate decisions, and build alignment between technical and business stakeholders Strong consultative skills and a deep understanding of how security creates customer value Experience working with strategies, target architectures, governing principles, reference architectures, and roadmap initiatives Good understanding of cloud platforms such as Azure, AWS, and/or GCP Meritorious Qualifications Certifications such as CISSP, SABSA, CISM, CCSP, TOGAF, Azure/AWS Security certifications, or similar Experience from regulated industries or critical infrastructure environments Knowledge of security frameworks and standards such as NIST CSF, ISO 27001, CIS Controls, or similar Experience with SASE/SSE, microsegmentation, identity federation, or modern access control Experience supporting customers in large-scale transformation initiatives or security programs Why Orange Cyberdefense? There are many employers within IT and security. But few are as clearly focused on cybersecurity as we are. At Orange Cyberdefense, you do not just get a new assignment — you become part of an environment where your expertise is taken seriously, continuously developed, and applied where it makes the greatest impact. With us, you will: Work in a dedicated cybersecurity company with deep specialist expertise and a strong market position Be close to some of the industry’s most complex and interesting assignments, where security is business-critical Collaborate with highly experienced colleagues in architecture, advisory, SOC, incident response, offensive security, and managed services Continuously develop through training, certifications, knowledge sharing, and professional exchange Make a real impact — both in customer engagements and in how we develop our services and ways of working Work in a Challenger culture where initiative, accountability, and ideas are encouraged Have colleagues who are passionate about cybersecurity, support each other, and generously share knowledge Contribute to something bigger: building a safer digital society
Sida 1 av 15