Sida 1 av 1
Are you passionate about ethical hacking and eager to develop the skills that keep modern applications safe? Do you dream of finding the weaknesses others miss — and helping organisations fix them before attackers do? If so, we have the perfect opportunity for you! ABOUT THE INTERNSHIP Our Application Security & Penetration Testing Internship is designed for ambitious individuals who want to explore the exciting world of offensive security and gain hands-on experience. This program offers the chance to work on real client engagements, learn industry-standard testing methodologies, and collaborate with experienced security consultants. WHAT YOU'LL LEARN As an intern, you will: Test modern web applications, APIs and mobile apps for real security weaknesses. Learn how professional penetration tests are planned, executed and reported. Turn technical findings into clear, practical advice that clients can act on. Gain hands-on experience with the tools and methodologies used on live engagements. This internship is designed for individuals eager to dive deep into application security and apply their curiosity to problems that matter. Every vulnerability you help find and every report you help write makes a real system secure and safer for the people who depend on it. WHY JOIN US? Hands-on experience with state-of-the-art security tools and technologies. Guidance and mentorship from seasoned penetration testers. Opportunity to work on real-world client engagements that make an impact. A collaborative and supportive environment where questions are always welcome. WHO WE'RE LOOKING FOR We welcome interns who: Have a strong interest in cybersecurity and ethical hacking. Have a solid grasp of web technologies, networking, and Linux or Windows OS. You don't need to be an expert, but we expect you to be very comfortable working in these environments. Good knowledge of mobile app development (iOS/Android) and APIs. Good knowledge of any major cloud technologies/platforms (AWS/Azure/GCP). Have some awareness of common application vulnerabilities, such as the OWASP Top 10. Exposure to web application penetration testing, API security testing, or mobile application security through academic projects or self-learning. Have tried their hand at CTFs or practice labs such as Hack The Box, TryHackMe or PortSwigger Web Security Academy, or personal projects or home labs. Good programming/scripting experience, for example, Python or Bash, is a bonus. Strong analytical and problem-solving skills with the ability to think creatively, eager to learn and solve complex problems. Are ready to contribute ideas and collaborate with a dynamic team. Approach security work with care, discretion and a strong ethical mindset. HOW TO APPLY Send your resume and a cover letter explaining why you're excited about penetration testing and why you are an ideal candidate for the role. It is recommended to include any personal security projects, CTF write-ups or lab platform profiles you have worked on. Applications are open until 31st August 2026. Don't miss this chance to kickstart your career in offensive security! Join us, and let's build a safer digital world together! Please note: This is an unpaid, full-time, 6-month onsite internship starting September 2026 at our offices in Lindholmen, Gothenburg.
TL;DR: We're looking for a world-class Penetration Tester with a name in the field. You'll push Lovable's platform to its limits, hunt vulnerabilities across our AI pipelines and user-generated code, and make sure attackers never get there before you do. Why Lovable? Lovable lets anyone and everyone build software with any language. From solopreneurs to Fortune 100 teams, millions of people use Lovable to transform raw ideas into real products - fast. We are at the forefront of a foundational shift in software creation, which means you have an unprecedented opportunity to change the way the digital world works. Over 2 million people in 200+ countries already use Lovable to launch businesses, automate work, and bring their ideas to life. And we’re just getting started. We’re a small, talent-dense team building a generation-defining company from Stockholm. We value extreme ownership, high velocity, and low-ego collaboration. We seek out people who care deeply, ship fast, and are eager to make a dent in the world. What we’re looking for * 12+ years of hands-on penetration testing experience across web, mobile, APIs, and cloud infrastructure. * A track record the field knows about: CVEs to your name, hall-of-fame credits in major bug bounty programs, or a reputation that precedes you. * Deep expertise in offensive security techniques: OWASP, MITRE ATT&CK, exploit development, privilege escalation, and lateral movement. * Hands-on experience using AI as part of your hacking workflow — not just testing AI systems, but actively leveraging it as an offensive tool. * Experience attacking AI-native products or LLM-integrated systems, including prompt injection, model abuse, and data exfiltration vectors. * Strong understanding of cloud environments (GCP, AWS, Cloudflare) and the attack surfaces they introduce. * Ability to translate complex findings into clear, prioritised reports that engineering teams can act on immediately. * Low ego, high output. You collaborate as naturally as you compete against systems. * Bonus: experience with red team operations, supply chain attacks, or mobile security (iOS/Android). Familiarity with SAST/DAST tooling. What you’ll do * Own offensive security end-to-end: plan and execute penetration tests across Lovable's web platform, mobile surface, APIs, cloud infrastructure, and AI pipelines. * Break our AI before others do: probe LLM integrations for prompt injection, jailbreaks, data leakage, and novel attack vectors unique to AI-generated code running in live products. * Stress-test user-generated code at scale: identify systemic vulnerabilities introduced when millions of users create and deploy real applications on Lovable. * Turn findings into action: work directly with engineering to prioritise, remediate, and verify fixes, closing the loop between discovery and resolution. * Raise the security bar org-wide: run internal red team exercises, contribute to threat modelling, and embed an attacker's mindset across the engineering culture. * Help make Lovable the most secure AI product in the market. Our Tech Stack * Frontend: React and TypeScript * Backend: Golang and Rust * Cloud: Cloudflare, GCP, AWS, multiple LLM providers * DevOps & Tooling: GitHub Actions, Grafana, OTEL, infra-as-code (Terraform) * Data: Clickhouse, Firestore, Spanner, BigQuery And we're always exploring what's next! About your application Please submit your application in English. It’s our company language, so you’ll be speaking lots of it if you join. We treat all candidates equally - if you’re interested, please apply through our careers portal.
TL;DR: We're looking for a Penetration Tester who lives to break things, ethically. You'll push Lovable's platform to its limits, hunt vulnerabilities across our AI pipelines and user-generated code, and make sure attackers never get there before you do. Why Lovable? Lovable lets anyone and everyone build software with any language. From solopreneurs to Fortune 100 teams, millions of people use Lovable to transform raw ideas into real products - fast. We are at the forefront of a foundational shift in software creation, which means you have an unprecedented opportunity to change the way the digital world works. Over 2 million people in 200+ countries already use Lovable to launch businesses, automate work, and bring their ideas to life. And we’re just getting started. We’re a small, talent-dense team building a generation-defining company from Stockholm. We value extreme ownership, high velocity, and low-ego collaboration. We seek out people who care deeply, ship fast, and are eager to make a dent in the world. What we’re looking for 5+ years of hands-on penetration testing experience across web, mobile, APIs, and cloud infrastructure. Deep expertise in offensive security techniques: OWASP, MITRE ATT&CK, exploit development, privilege escalation, and lateral movement. Experience attacking AI-native products or LLM-integrated systems, including prompt injection, model abuse, and data exfiltration vectors. Strong understanding of cloud environments (GCP, AWS, Cloudflare) and the attack surfaces they introduce. Ability to translate complex findings into clear, prioritised reports that engineering teams can act on immediately. Low ego, high output. You collaborate as naturally as you compete against systems. Bonus: experience with red team operations, supply chain attacks, or mobile security (iOS/Android). Familiarity with SAST/DAST tooling. Background in security research or CVE disclosure. What you’ll do Own offensive security end-to-end: plan and execute penetration tests across Lovable's web platform, mobile surface, APIs, cloud infrastructure, and AI pipelines. Break our AI before others do: probe LLM integrations for prompt injection, jailbreaks, data leakage, and novel attack vectors unique to AI-generated code running in live products. Stress-test user-generated code at scale: identify systemic vulnerabilities introduced when millions of users create and deploy real applications on Lovable. Turn findings into action: work directly with engineering to prioritise, remediate, and verify fixes, closing the loop between discovery and resolution. Raise the security bar org-wide: run internal red team exercises, contribute to threat modelling, and embed an attacker's mindset across the engineering culture. Help make Lovable the most secure AI product in the market. Our Tech Stack Frontend: React and TypeScript Backend: Golang and Rust Cloud: Cloudflare, GCP, AWS, Modal, multiple LLM providers DevOps & Tooling: GitHub Actions, Grafana, OTEL, infra-as-code (Terraform) Data: Clickhouse, Firestore, Spanner, BigQuery And we're always exploring what's next! About your application Please submit your application in English. It’s our company language, so you’ll be speaking lots of it if you join. We treat all candidates equally - if you’re interested, please apply through our careers portal.
At HiQ, every challenge is an invitation to explore new possibilities. We’re looking for someone who thrives on the thrill of discovery, who sees every system as a puzzle waiting to be solved, and who finds energy in the pursuit of safer, smarter digital solutions. As part of our Pentest team, you’ll be at the heart of our mission to build secure applications and environments for some of the most exciting organizations in the Nordics. Your days will be filled with hands-on penetration testing, creative problem-solving, and the freedom to dive deep into the latest tools and techniques. Whether you’re orchestrating a Red Team engagement or probing the intricacies of cloud security, you’ll have the autonomy to shape your own approach, while always knowing that a team of passionate experts has your back. You’ll work with Burp Suite, Nmap, Wireshark, and a host of other tools, sometimes in the cloud, sometimes on-prem, always at the cutting edge. Your experience with Active Directory and scripting will come to life as you navigate complex environments, uncover vulnerabilities, and help our clients see their systems through a new lens. If you’ve cracked hashes, explored mobile app security, or sharpened your skills in CTFs, you’ll find plenty of opportunities to push your expertise even further. WHAT YOU BRING * At least 5 years of practical experience in penetration testing or Red Team operations * Deep familiarity with industry-standard tools such as Burp Suite, Nmap, and Wireshark * Strong background in assessing and securing web applications * Proven experience performing Active Directory and broader network security assessments * Understanding of modern cloud platforms and architectures * Scripting skills that enable you to automate workflows and develop new solutions * Relevant education and/or certifications (e.g., OSCP, OSCE, AWS/Azure Security) * Excellent communication skills, with the ability to clearly document and articulate vulnerabilities and recommendations * Swedish citizenship, as HiQ carries out security-classified assignments that may require it BONUS SKILLS * Experience with hash cracking * Knowledge of mobile application security * Knowledge in cloud security * Networking know-how * Capture the Flag participation * Insights into computer forensics Here, learning is woven into the fabric of every project. Whether you’re pursuing new certifications, experimenting with the latest exploits, or sharing insights with colleagues, you’ll find endless room to grow. We celebrate curiosity and initiative, if you spot an opportunity to make something better, you’ll have the freedom and support to make it happen. You’ll be trusted to run penetration tests independently, but you’ll never be alone. Collaboration is second nature here: ideas bounce, knowledge flows, and everyone’s voice matters. You’ll document your findings with clarity, communicate risks with empathy, and help guide clients toward stronger, more resilient solutions. If you’re ready to join a team where your passion for security is matched only by your drive to learn and create, we’d love to meet you. Ready to take the next step? Apply now and let’s build something extraordinary together.
About the job Are you a skilled Cyber Security Engineer with a talent for finding gaps in the most secure systems? We’re looking for someone to perform in-depth penetration testing across various technologies, including Windows and Linux environments, Citrix Workspaces, Cloud infrastructures, and APIs. You will use the latest tools and techniques to uncover vulnerabilities and work alongside our development and security teams to address and fix them. If you're ready to tackle complex security challenges, we want to hear from you! The ideal profile The perfect candidate is a highly skilled and detail-oriented Cyber Security Engineer with genuine hands-on experience in penetration testing and vulnerability analysis. You have excellent written and verbal communication skills and are a strong problem-solver. You thrive both working independently and collaborating within a team, always ready to tackle challenges with analytical precision. Qualifications: You have a strong understanding of network protocols, both Windows and Linux operating systems, application architectures and Red Hat In-depth knowledge of common vulnerabilities and exploits (CVEs) Proficiency in using various penetration testing tools such as Metasploit, Nmap, Burp Suite and/or Nessus Additional skills: Experience with cloud security, particularly AWS. Knowledge of scripting languages (e.g., Python, PowerShell). Familiarity with source code review techniques. Understanding of frameworks like ISO 27001, NIST, CIS Security certifications such as OSCP, CEH, PEN TEST+
Job Title: Cyber Security Tester TRATON is a group of strong brands with a shared mission: transforming transportation together to create the future of sustainable transport solutions. Within TRATON, we include MAN, Scania, Volkswagen Truck & Bus, and International. As part of a global team of industry experts, you get to think bigger, experience more, and reach further. Together, we have the power to transform transportation - Let´s make a difference together. Find out more: www.traton.com Our values – customer first, respect, team spirit, responsibility, and elimination of waste – are at the heart of everything we do. Role Summary This role is a part of TRATON Group R&D, located in Södertälje, Sweden Join our Infotainment and Driver Display Testing Team and play a key role in ensuring the cyber security and quality of next-generation Digital Dashboard solutions within the TRATON Group. As a Cyber Security Test Engineer, you will be responsible for planning, designing, executing, and driving cyber security testing activities across infotainment and driver display systems. Working in a global and multicultural environment, you will collaborate closely with System Test, Function Test, Vehicle Test, and HIL teams to identify security risks, verify compliance with cyber security requirements, and contribute to the delivery of safe and reliable digital products. Job Responsibilities Plan, coordinate, and drive cyber security testing activities for Digital Dashboard systems. Analyze cyber security requirements and translate them into effective test scenarios and test cases. Design, develop, and maintain automated test scripts to support efficient and scalable testing. Execute cyber security tests, including vulnerability assessments, penetration testing, fuzz testing, and security validation activities. Investigate, analyze, and troubleshoot security-related issues and defects. Evaluate test results, identify potential security risks, and provide clear reporting to stakeholders. Collaborate with global System Test and HIL teams to ensure alignment on testing strategies and quality objectives. Support continuous improvement of cyber security testing processes, methodologies, and tools. Contribute to ensuring compliance with automotive cyber security standards and best practices. Who You Are You have proven experience in cyber security testing, preferably within embedded systems or the automotive industry. You possess a strong understanding of security testing techniques, including penetration testing, fuzz testing, vulnerability scanning, and threat analysis. You have solid programming skills in one or more languages such as Python, C++, or C#. You are familiar with automotive communication protocols, particularly CAN. You have a good understanding of software testing methodologies, test levels, and quality assurance practices. You are analytical, detail-oriented, and have strong troubleshooting and problem-solving skills. You are comfortable working in international and cross-functional teams. You communicate effectively and can clearly present technical findings to different stakeholders. You are self-driven, well-organized, and motivated to take ownership of your work. You are fluent in English, both written and spoken. We welcome applicants from all backgrounds – your unique experience and perspectives is valuable to us. This Is Us Our team focuses on testing advanced Digital Dashboard solutions, ensuring high quality, reliability, and cyber security across infotainment and driver display functions. We are a diverse, collaborative, and multicultural organization consisting of System Test, Vehicle Test, and Function Test teams located across different TRATON sites worldwide. Within TRATON Group R&D, you are an important part of something bigger. Joining us means gaining access to the ins and outs of the entire transportation industry. TRATON Offers We offer a dynamic and engaging workplace where collaboration, innovation, and continuous improvement are part of everyday life. You will be part of a strong team environment that encourages knowledge sharing and close cooperation across functions. With a structured development plan and a wide range of training opportunities, TRATON Group R&D supports your professional growth both locally and internationally. Benefits include access to our health center in Gröndal or a wellness allowance, bonus, flexible working hours, and company car leasing. We also arrange events for employees and their families, and for those living in Stockholm, convenient commuting is supported through direct Scania Job express buses to Södertälje. We Offers We offer a dynamic, flexible workplace with hybrid work options, including Scania Sergel and Midway hubs. With a structured development plan and courses, TRATON Group R&D supports your career growth both locally and internationally. Benefits include wellness allowance, bonus, flexible hours, and company car leasing. We also host events for employees and their families, and Stockholm residents enjoy direct access to Södertälje via Scania Job express buses for an easy commute to Södertälje. Application We look forward to receiving your application, consisting of your CV and kindly ask you not to share a cover letter to ensure an efficient and unbiased recruitment process for all parties. Apply as soon as possible, no later than 2026-08-31. Screening will take place on an ongoing basis during the application period. Logical and personality tests may be used as part of the selection process, and a background check may be required for this role. If you have questions or would like more information, please contact: Nuno Marques, Recruting Manager, nuno.marques@scania.com We look forward to your application! This recruitment process is handled by Scania for TRATON Group R&D
Veritaz is a leading IT staffing solutions provider in Sweden, committed to advancing individual careers and aiding employers in ensuring the perfect talent fit. With a proven track record of successful partnerships with top companies, we have rapidly grown our presence in the USA, Europe, and Sweden as a dependable and trusted resource within the IT industry. Assignment Description We are looking for an experienced Senior Application Security Coordinator What You Will Work On Coordinate remediation of findings from penetration tests and vulnerability assessments Manage and track security findings through their complete lifecycle Assess and prioritize vulnerabilities based on business risk Coordinate remediation activities across business and technical teams Work closely with application owners, infrastructure teams, and security stakeholders Establish and maintain governance, reporting, and remediation processes Monitor progress and ensure timely resolution of identified vulnerabilities Facilitate communication between multiple stakeholders Improve visibility and control of the organization's vulnerability landscape Support compliance with internal security standards and external regulatory requirements Drive continuous improvements in vulnerability management processes Ensure effective collaboration across cross-functional teams What You Bring Experience working with Jira Experience coordinating remediation of security findings Strong ability to assess risks and prioritize remediation activities Experience driving structured remediation and follow-up processes Good understanding of application security and infrastructure security Experience handling results from vulnerability scanning and penetration testing Knowledge of CVE, CWE, and CVSS Strong stakeholder management and communication skills Experience coordinating work across multiple technical and business teams Strong organizational and planning skills Experience with security governance and reporting Ability to work independently in complex environments Analytical, structured, and proactive approach to problem-solving
Natural Cycles° is a leading women’s health company that developed the world’s first birth control app, used by millions globally. We are a fast growing startup, and we promote an international working environment filled with smart and ambitious colleagues based in Stockholm, Geneva, New York, and remotely. Our mission is to pioneer women’s health through research and passion, empowering every woman with the knowledge she needs to take charge of her health. We are looking for a Security & Infrastructure Engineer to build and maintain secure tooling, integrations and infrastructure that helps Natural Cycles move fast while managing risk. The role develops internal tools, performs security reviews and security testing, improves monitoring of employee and AI-agent activity, enables teams to prototype internal tools and AI integrations safely, and turns cybersecurity and regulatory requirements into practical controls. Please note that we are hiring for this role in Sweden. What you will be doing * Develop integrations, such as Slackbots and internal assistants, to improve Infrastructure and Security workflows. * Build and maintain infrastructure that enables safe internal experimentation with POCs, helper apps, AI integrations, and automations. * Improve monitoring and detection of employee and AI-agent activity, including risks such as shadow IT, unsafe integrations, excessive permissions, and data exposure. * Protect company resources in a risk-based way according to their criticality, sensitivity, and regulatory relevance. * Use AI tools, mainly Claude, to rapidly develop code, infrastructure as code, automations, security tooling, and documentation. * Translate cybersecurity requirements, including NIS2 and medical device security expectations, into practical engineering work. * Perform security reviews, simpler penetration tests, threat modelling, and risk assessments for internal applications, integrations, and infrastructure changes. * Work independently and proactively while staying aligned with company priorities and risk appetite. What skills and experience we think you have * Strong hands-on experience with software development, infrastructure and cloud platforms. * Ability to build internal tools, automations, AI integrations, and infrastructure components using modern engineering practices. * Comfortable using AI coding assistants, especially Claude or similar tools, while maintaining quality, security, and review discipline. * Basic understanding of identity and access management, logging, monitoring, secrets management, and secure system design. * Ability to assess technical and business risk, prioritise mitigations, and document decisions clearly. * Ability to work independently in ambiguous situations while seeking alignment when needed. * Nice to have: * Practical cybersecurity experience, including security reviews, risk assessments, threat modelling, vulnerability assessment, or penetration testing. * Familiarity with compliance-driven environments and willingness to work with NIS2, medical device security, and quality-system requirements. * DevOps, platform engineering, or infrastructure as code. What we offer * Flexible work arrangement - you will be part of a team based in and around Stockholm that values effective collaboration and transparent communication, irrespective of work location * Professional development - you will work alongside knowledgeable colleagues in the continuous growth and skill enhancement environment * Modern technology - you will leverage innovative technologies and tools, within an environment that empowers you to contribute ideas and take ownership of your work * Impactful projects - you will contribute to groundbreaking projects that redefine industry standards and create tangible value * Commitment to quality - you will join a dynamic and progressive organization that prioritizes profitable, long-term product development Location We are remote-friendly, but we find great value in being able to connect with our teams in person. Most of the team you will work with is located in Sweden. Sounds interesting? If you want to be part of a successful team, we encourage you to apply for this position as soon as possible. We look forward to hearing from you! How to apply To apply, just upload your CV and answer the questions on the application form. Keep in mind that we can't accept applications through email because of GDPR, and only applications submitted via the career site (and in English) will be considered. At Natural Cycles we value diversity and inclusion because we know that teams with people from different backgrounds and experiences are stronger. We welcome candidates from all walks of life and are committed to creating an inclusive environment for all employees and candidates. Note: We are not looking for consultants or help from recruitment agencies
RaySearch develops innovative software solutions to improve cancer care. About 1000 clinics in more than 40 countries use RaySearch software to improve treatments and quality of life for patients. RaySearch was founded in 2000 and is listed on Nasdaq Stockholm. The headquarters is located in Stockholm, with subsidiaries in the US, Europe and Asia - Pacific. Today we are more than 400 employees with a common vision of improving cancer care with innovative software. Our great staff is crucial for our success and we offer a fantastic working environment in modern offices, flexibility and good opportunities for development. We believe in equal opportunities, value diversity and work actively to prevent discrimination. Are you passionate about ensuring that complex medical software is secure, resilient, and fully compliant with international standards? As Risk Manager, you will take ownership of identifying and mitigating risks within cybersecurity and information security across our products. With a structured mindset and keen attention to detail, you will play a central role in maintaining the integrity, reliability, and compliance of our software solutions. About the job As Risk Manager, you will be responsible for identifying, assessing, and mitigating cybersecurity and information security risks across all RaySearch products. As part of a smaller cybersecurity group, you will work with all aspects of cybersecurity for our product delivery including compliance, threat modelling, developer training, penetration testing, tooling and more. Your responsibilities will span the entire product lifecycle, with a particular focus on cloud-based solutions and secure software development practices. You will collaborate closely with development teams across the organization and work alongside other Risk Managers to ensure comprehensive risk management and compliance with international standards. Main responsibilities Participate in project planning together with the project management team. Support the development team with risk management related tasks, e.g., ensuring that the risk management process is applied, taking part in design and risk analysis of new and changed functionality and ensuring that risks are appropriately mitigated and tested. Own and maintain the project’s risk management documentation. Coordinate cybersecurity management activities within product development and the secure software development life cycle (SSDLC). Own the development and maintenance of cybersecurity documentation for regulated products, including FDA-related cybersecurity requirements and frameworks. Your profile We are looking for someone who understands the importance of risk management in medical software and is motivated by working in this field with all the responsibilities it entails. You are responsible, meticulous and structured, with a strong personal drive and the ability to work independently in a highly organized and efficient manner. You have experience working with or alongside software development teams and possess a strong technical understanding of software development processes, enabling you to navigate complex software environments and collaborate effectively with technical stakeholders. Requirements: BSc or MSc degree in engineering, or equivalent. 3+ years' experience working in a software development environment with complex software products. Excellent written and spoken communication skills (English and Swedish). Meriting: Experience from the medtech industry or other regulated or safety critical industries. Experience of device risk management. Experience with product safety standard requirements for medical devices (IEC/ISO standards, e.g., ISO 14971). Leadership or project management experience. Experience as a system developer. Our Culture Culture at RaySeach is the driving force behind our organization, where everything we do is driven by a shared passion for innovation and the fight against cancer. Our dedication is reflected in our ability to deliver exceptional results, pay close attention to detail, and consistently go the extra mile. Our employees stand out as experts in their field, driven by a relentless focus on solving problems - no matter how complex. At RaySearch, we take pride in leading the way in cancer treatment, leveraging cutting-edge technology to develop innovative solutions that make a real difference in patient care. Our Offer At RaySearch, we offer a diverse and inclusive work environment, fostering openness, sincerity, and collaboration. Located in Hagastaden, Stockholm's Life Science Hub, our modern and creative workspace includes an in-house gym, yoga, and social activities like ping pong, table football, and regular after-work events. Our bistro serves a fantastic lunch buffet, and we offer morning- and afternoon-fika every day. Our rooftop terrace also provides a stunning 360-degree view of Stockholm, enhancing the work experience. All of this comes attached with a competitive compensation and benefits package. Application Please apply to the position through the application form below. Selection and interviews will be ongoing. We do not accept applications by email.
RaySearch develops innovative software solutions to improve cancer care. About 1000 clinics in more than 40 countries use RaySearch software to improve treatments and quality of life for patients. RaySearch was founded in 2000 and is listed on Nasdaq Stockholm. The headquarters is located in Stockholm, with subsidiaries in the US, Europe and Asia - Pacific. Today we are more than 400 employees with a common vision of improving cancer care with innovative software. Our great staff is crucial for our success and we offer a fantastic working environment in modern offices, flexibility and good opportunities for development. We believe in equal opportunities, value diversity and work actively to prevent discrimination. We are looking for a System Developer who can blend software development expertise with a strong interest in security. In this role, you’ll contribute directly to RaySearch’s mission: advancing cancer treatment through innovative software. By ensuring that our products are designed and implemented securely, you help protect both patients and healthcare professionals and strengthen the reliability of the tools they depend on. About the role As a System Developer within cybersecurity, you will play a key role in shaping our secure development practices. You will work closely with development teams to embed security into the software development lifecycle and ensure that our products follow industry-leading standards. The role combines hands-on application security work—such as secure code reviews, threat modeling, and penetration testing—with knowledge sharing, training, and collaborative support to help teams make informed security decisions. This is an ideal role for a developer who enjoys cybersecurity and wants to contribute by guiding others, elevating security awareness, and helping teams work securely and effectively together. Your main tasks Work with development teams to implement application security best practices throughout the SDLC. Participate in threat modeling (e.g., STRIDE) and risk assessments for new and existing applications. Assist in designing and implementing cybersecurity controls in products. Ensure compliance with cybersecurity frameworks and standards. Contribute to developer security awareness training and promote secure development practices. Perform secure code reviews, static/dynamic analysis, and penetration testing. Develop and maintain secure coding guidelines and security documentation. Support the preparation of cybersecurity documentation for regulated products (including FDA-related frameworks). Your profile You are a developer with a strong interest in cybersecurity and secure design. You enjoy sharing knowledge, collaborating with others, and supporting development teams in building secure solutions. You communicate clearly, work constructively across functions, and contribute to a culture where security is a natural part of everyday development. Required skills Strong understanding of software development practices and the ability to read, analyze, and evaluate code for security and quality aspects. Strong understanding of application security principles (e.g., OWASP Top 10, secure coding). Experience with threat modeling and risk analysis. Excellent ability to produce clear, structured security and compliance documentation. It’s an advantage, but not required, if you also have experience of: Working in regulated environments (e.g., medical devices, embedded systems). Hands-on experience with security testing tools (e.g., SonarQube, Burp Suite). Familiarity with FDA cybersecurity guidelines, the IEC 8100x series, or IEC 62443 for industrial/embedded systems. Integrating security into CI/CD pipelines (Azure DevOps or GitHub Actions). Our Culture Culture at RaySearch is the driving force behind our organization, where everything we do is driven by a shared passion for innovation and the fight against cancer. Our dedication is reflected in our ability to deliver exceptional results, pay close attention to detail, and consistently go the extra mile. Our employees stand out as experts in their field, driven by a relentless focus on solving problems - no matter how complex. At RaySearch, we take pride in leading the way in cancer treatment, leveraging cutting-edge technology to develop innovative solutions that make a real difference in patient care. Our Offer At RaySearch, we offer a diverse and inclusive work environment, fostering openness, sincerity, and collaboration. Located in Hagastaden, Stockholm's Life Science Hub, our modern and creative workspace includes an in-house gym, yoga, and social activities like ping pong, table football, and regular after-work events. Our bistro serves a fantastic lunch buffet, and we offer morning- and afternoon-fika every day. Our rooftop terrace also provides a stunning 360-degree view of Stockholm, enhancing the work experience. All of this comes attached with a competitive compensation and benefits package. Application Please apply to the position through the application form below. Selection and interviews will be ongoing. We do not accept applications by e-mail.
WPP is the trusted growth partner for the world’s leading brands. We unite cutting-edge media intelligence and data solutions, world-class creativity, next-generation production, transformative enterprise solutions and expert strategic counsel in a single company – powered by exceptional talent and our agentic marketing platform, WPP Open, to help our clients navigate change, capture opportunity and deliver transformational growth. We work with the world's most valuable brands and have global reach across 100+ markets, with deep local expertise. Our people are the key to our success. We're committed to fostering a culture of creativity, belonging and continuous learning, attracting and developing the brightest talent, and providing exciting career opportunities that help our people grow. For more information, visit WPP.com. * Department: Data & Technology Solutions (DTS) * Reports To: SVP Security and Compliance * Location: [London/Hybrid 2 days a week in office] * Position Type: Full-Time ROLE OVERVIEW The Product, Application and Offensive Security Lead is responsible for embedding security directly into the design, development, testing, and operation of DTS products and platforms. This is a hands-on security engineering role. The role requires someone who can work directly with product and engineering teams, review designs, assess APIs, run threat models, test systems, coordinate penetration testing, identify vulnerabilities, and help teams remediate issues. The role ensures DTS products, APIs, data collaboration capabilities, AI-enabled workflows, and client-facing services are designed, built, and tested securely. It also owns the practical offensive security and adversarial assurance activity needed to test DTS products from an attacker’s perspective. The Product, Application and Offensive Security Lead will work closely with Product, Engineering, Architecture, Infrastructure, Security Operations, Privacy, Cloud and Platform Security, and the ISMS and Risk Officer to ensure security issues are identified early, fixed effectively, and tracked through governance where required. ---------------------------------------------------------------------------------------------------------------------------------- KEY RESPONSIBILITIES 1. HANDS-ON PRODUCT AND APPLICATION SECURITY Provide hands-on security support across DTS products and engineering teams. This includes: * Reviewing product designs, technical designs, APIs, services, and integrations. * Identifying security weaknesses in applications, workflows, and data flows. * Advising engineering teams on secure implementation. * Supporting secure design decisions during product discovery and delivery. * Helping teams resolve security issues pragmatically without creating unnecessary delivery friction. 2. SECURE SOFTWARE DEVELOPMENT LIFECYCLE (SDLC) Embed security into the software development lifecycle across DTS. This includes: * Defining and applying secure engineering standards. * Supporting secure coding practices. * Reviewing CI/CD security controls. * Supporting SAST, DAST, SCA, secrets scanning, dependency scanning, and container scanning. * Helping teams triage, prioritise, and remediate security findings. * Working with engineering teams to make security checks practical and repeatable. 3. THREAT MODELLING AND SECURITY DESIGN REVIEWS Run threat modelling and security design reviews for new and changed capabilities. This includes: * Facilitating threat modelling sessions with engineering and product teams. * Reviewing authentication and authorization designs. * Assessing API exposure, data flows, trust boundaries, and abuse cases. * Identifying risks around tenant isolation, privilege escalation, data leakage, and misuse. * Documenting key findings, recommendations, and residual risks. 4. OFFENSIVE SECURITY AND ADVERSARIAL TESTING Carry out and coordinate offensive security testing across DTS products and platforms. This includes: * Performing hands-on security testing of products, APIs, and workflows. * Coordinating external penetration tests. * Supporting red team and purple team exercises where required. * Testing abuse cases and attacker paths. * Testing access control, authentication, authorization, and data leakage risks. * Validating remediation of security findings. * Feeding material risks into the ISMS and Risk Officer for tracking. 5. API, INTEGRATION AND DATA PRODUCT SECURITY Provide security assurance for APIs, integrations, and data products. This includes: * Reviewing externally exposed APIs and partner integrations. * Assessing rate limiting, authorization, tenant isolation, logging, abuse prevention, and data leakage controls. * Supporting secure integration between InfoSum, Open Intelligence, Resolve, WPP Open, and third-party platforms. * Reviewing data product workflows for misuse, excessive access, or unintended exposure. * Working with Privacy Engineering on privacy-sensitive APIs, algorithms, and outputs. 6. AI AND AGENTIC SECURITY TESTING Provide hands-on security review and adversarial testing for AI-enabled and agentic capabilities. This includes: * Testing prompt injection, tool misuse, data leakage, and excessive agency. * Reviewing how agents access APIs, data, tools, and workflows. * Testing whether agent permissions can be bypassed or escalated. * Assessing action boundaries and human approval points. * Working with Identity, AI, and Data Access Governance to validate agent access models. * Documenting AI and agentic security risks and remediation actions. 7. VULNERABILITY TRIAGE AND REMEDIATION SUPPORT Help teams understand, prioritise, and fix security vulnerabilities. This includes: * Reviewing vulnerability findings from scans, penetration tests, code reviews, cloud tools, and external reports. * Prioritising findings based on exploitability, exposure, data sensitivity, and business impact. * Working directly with engineers to define remediation options. * Validating that fixes are effective. * Supporting exception and risk acceptance decisions where remediation is delayed. * Ensuring significant issues are visible through the DTS risk process. 8. ENGINEERING ENABLEMENT AND SECURITY COACHING Act as a practical security partner to engineering teams. This includes: * Providing secure implementation guidance. * Creating lightweight security patterns and examples. * Coaching engineers on common application, API, and AI security risks. * Helping teams understand the “why” behind security requirements. * Supporting a culture where security is part of product quality, not a separate approval gate. ---------------------------------------------------------------------------------------------------------------------------------- KEY ACCOUNTABILITIES The Product, Application and Offensive Security Lead will be accountable for: * Hands-on application and product security support across DTS. * Secure SDLC guidance and practical adoption. * Threat modelling and security design reviews. * API, integration, and data product security reviews. * Offensive security and adversarial testing activity. * AI and agentic security testing. * Vulnerability triage, remediation guidance, and fix validation. * Coordination with ISMS/Risk to ensure material risks and exceptions are tracked. * Helping engineering teams build secure systems without unnecessary delivery drag. ---------------------------------------------------------------------------------------------------------------------------------- SKILLS AND EXPERIENCE The successful candidate will have: * Strong hands-on experience in application security, product security, offensive security, security engineering, or penetration testing. * Good understanding of modern software engineering, APIs, SaaS platforms, distributed systems, and cloud-native applications. * Experience with threat modelling and secure design reviews. * Practical knowledge of common application and API security risks, including authentication, authorization, tenant isolation, injection, data leakage, privilege escalation, and supply chain risk. * Experience using security testing tools and techniques across web applications, APIs, cloud services, and CI/CD pipelines. * Familiarity with SAST, DAST, SCA, secrets scanning, dependency scanning, and vulnerability management workflows. * Experience working directly with engineers to remediate findings. * Understanding of AI and agentic security risks would be highly valuable. * Ability to communicate clearly with engineering, product, architecture, security, and leadership stakeholders. * A pragmatic, delivery-aware approach to security. ---------------------------------------------------------------------------------------------------------------------------------- LEADERSHIP EXPECTATIONS The Product, Application and Offensive Security Lead is expected to: * Be hands-on and technically credible with engineering teams. * Act as a trusted security partner, not just a reviewer or approver. * Challenge insecure designs constructively. * Help teams find practical ways to reduce risk. * Prioritise issues based on real-world exploitability and business impact. * Work across multiple DTS product areas without becoming a delivery bottleneck. * Escalate material risks clearly through the appropriate governance routes. * Promote secure engineering habits through practical guidance and example. ---------------------------------------------------------------------------------------------------------------------------------- SUCCESS MEASURES Success in the role will be measured by: * Security being embedded earlier in product and engineering delivery. * Reduction in high-risk application, API, and product vulnerabilities. * Regular threat modelling and security reviews for critical DTS capabilities. * Effective offensive and adversarial testing of products, APIs, and workflows. * Faster remediation of penetration test and security testing findings. * Improved security assurance for AI and agentic workflows. * Engineering teams receiving practical, actionable security guidance. * Material security risks being surfaced and tracked through the DTS risk process. * Security being viewed by engineering teams as an enabler of trusted delivery rather than a blocker. You're open: We are inclusive and collaborative; we encourage the free exchange of ideas; we respect and celebrate diverse views. We are open-minded: to new ideas, new partnerships, new ways of working. You're optimistic: We believe in the power of creativity, technology and talent to create brighter futures or our people, our clients and our communities. We approach all that we do with conviction: to try the new and to seek the unexpected. You're extraordinary: we are stronger together: through collaboration we achieve the amazing. We are creative leaders and pioneers of our industry; we provide extraordinary every day. What we'll give you: Passionate, inspired people – We aim to create a culture in which people can do extraordinary work. Scale and opportunity – We offer the opportunity to create, influence and complete projects at a scale that is unparalleled in the industry. Challenging and stimulating work – Unique work and the opportunity to join a group of creative problem solvers. Are you up for the challenge? #LI-Hybrid We believe the best work happens when we're together, fostering creativity, collaboration, and connection. That's why we’ve adopted a hybrid approach, with teams in the office around four days a week. If you require accommodations or flexibility, please discuss this with the hiring team during the interview process. WPP is an equal opportunity employer and considers applicants for all positions without discrimination or regard to particular characteristics. We are committed to fostering a culture of respect in which everyone feels they belong and has the same opportunities to progress in their careers. PLEASE READ OUR PRIVACY NOTICE (HTTPS://WWW.WPP.COM/EN/CAREERS/WPP-PRIVACY-POLICY-FOR-RECRUITMENT) FOR MORE INFORMATION ON HOW WE PROCESS THE INFORMATION YOU PROVIDE.
Nordnet redefined the financial world as the first digital bank in Europe. Now we are about to do it again and the aim is to create the next generation of bank, in the cloud. We know that this requires great people, great teams, and great technology. Do you want to join us and build the new Nordnet? At Nordnet we want to democratize savings and investments by giving our customers access to the best tools and information whether you are a professional investor or a small saver. With modern technologies and speed of delivery, we are building the next generation investment platform. This is part of the role Nordnet is a company with tech as the primary focus. In our agile and autonomous teams, you will be working with engaged colleagues that love to share their knowledge. As a cloud security engineer, you will drive automation and integrate DevSecOps into our cloud-based platform by embedding security in Continuous Integration/Continuous Delivery (CI/CD) pipelines, enhancing infrastructure security and ensuring secure software development practices. As a Cloud Security Engineer acting autonomously and with a clear mandate, you will: Develop and enforce cloud and Infrastructure As Code (IaC) security policies. Improve cloud security monitoring by building and managing detections. Collaborate with engineering teams to ensure security best practices and Secure Software Development Life Cycle SSDLC (Shift-Left). Facilitate threat modelling sessions, secure code review and vulnerability assessments. Coordinate penetration testing efforts and track remediations. Enable developers to ship fast by automating security Balance security rigor with business agility; we don't just secure, we enable. This is you To succeed in this role, we believe that you take great pride in your work, are curious and continuously want to learn and grow. Believing in collaboration and discussing ideas and concepts with your colleague, you will serve as the first point of contact for our Platform teams as a Cloud Security Subject Matter Expert to enable the delivery of great products. As a Cloud Security Engineer, you have: Offensive security mindset ideally with former red teamer or penetration tester experience Knowledge of Google Cloud Platform (or equivalent experience with other Cloud providers) Google Security Command Centre (SCC) Google Kubernetes Engine (GKE) Identity and Access Management (IAM) Infrastructure As Code (Terraform) Github Ability to work independently and as part of a team Strong stakeholder management skills, ability to work with both technical and non-technical stakeholders Ability define and implement security requirements in cloud environments Experience with security best practices and vulnerability management process. Familiarity with programming and major frameworks (Java, Spring, React) What we offer Your expertise and contribution will be appreciated from day one Access to the latest AI tools with cutting edge models to support your daily work. Plenty of opportunities to grow as a security professional Competitive salary and compensation Opportunity to shape the architecture, influencing the security design of Europe’s next-generation digital bank from the ground up. Access to training opportunities such as professional certifications (e.g., GCP Security, OSCP, OSAI+, CISSP), industry conferences, and dedicated time for skills development. You won't just follow a checklist; you’ll have the mandate to build and own your security automation roadmap. We offer you the opportunity to work in a Nordic environment with a strong focus on delivery, product development and technology. Our ambitions are high and you will embark on a fast and challenging journey together with a skillful team of sharp and committed colleagues. Our teams are autonomous and embrace the agile way of working. Culture is built and cared for, each day by everyone. We’re proud of ours. Having a flat organization where anyone can talk to anyone creates a warm and friendly atmosphere worth protecting. We believe in a culture where every effort counts and where everyone is being recognized. A culture embracing our core values – passion, simplicity and transparency on all levels, no matter who you are or what you do. We are over 900 employees located in Stockholm, Oslo, Helsinki, Copenhagen and Frankfurt. Visit us on: career.nordnetab.com/pages/engineering Learn more about Nordnet in our brand movie This is Nordnet, that describes our identity. Questions & Applications Please note that we will start reviewing applications after the summer holidays. To ensure a fair process and that your data is handled securely, we only accept applications through our recruitment system, applications sent via email will not be considered. If you have questions, please contact Hiring Manager Ralph Benton at ralph.benton@nordnet.se We want to inform you that Nordnet conducts mandatory credit and background checks, as well as drug testing as a part of our recruitment process. We look forward to receiving your application!
Join our global force of 400+ innovators, blending the latest in tech with the greatest in soundtracking, from our Stockholm HQ to offices in London, New York, Los Angeles, Berlin, Paris, Oslo, and Seoul. We’re an industry leader with a startup mentality. We take what we do seriously, but we don’t take ourselves too seriously. Creating and collaborating to transform the sound of streaming, content, and culture. Come join us, and let the world feel your work. As a Security Engineer at Epidemic Sound, you will help keep the company safe across three connected surfaces: the products our customers use, the platform our engineers build on, and the systems our employees rely on every day. This is a broad, generalist role where your work directly shapes how an industry-leading company with a startup mentality manages risk and builds securely at scale. Building security automations and custom AI agents is a normal part of how the team operates, and you will be expected to do the same. You will sit within the Business Tech Division and report to the Head of Security, working closely with engineers, SRE, IT, Legal, and People teams across the organisation. YOUR KEY RESPONSIBILITIES INCLUDE * Own the vulnerability management programme across our products, cloud, and corporate estate: discovery, prioritisation, remediation tracking, and reporting. * Consolidate findings across our detection stack into a single risk picture. * Partner with software engineers to grow the Secure Software Development Lifecycle, including code reviews, threat models, and pre-ship security input. * Harden the GCP estate, Kubernetes platform, and CI/CD systems our engineers depend on. * Run vendor security reviews and respond to enterprise customer security questionnaires. * Operate and tune the Elastic SIEM and broader detection stack, building new detections as the threat picture evolves. * Respond to security incidents including on-call, and run training exercises to keep the team ready. * Build and run security agents and automations that other engineers and the wider business rely on, treating them as production-grade software. * Evaluate AI models and frameworks against security standards. REQUIREMENTS * Around five years in security engineering, with depth in at least one of application security, infrastructure security, enterprise security, or vulnerability management, and solid breadth across the others. * Hands-on experience running or contributing to a vulnerability management programme, including prioritisation, SLA setting, remediation tracking, and reporting. * Working knowledge of SCA/SAST tooling, Internal Developer Portals, and SIEM; we use Snyk, Port, and Elastic. * Working knowledge of the security features of the major public cloud providers, with GCP preferred. * Comfort with Kubernetes, Docker, or other container architectures. * Confident with at least one programming or scripting language such as Python, Go, or Bash. * Solid experience with Git, GitHub Actions, and Terraform. * Active, daily use of AI and agentic tools, with concrete examples of agents you have built and outputs you have shipped. * Experience with vendor security questionnaires. * Familiarity with common security frameworks such as PCI DSS and NIST. IT WOULD ALSO BE MUSIC TO OUR EARS IF YOU HAVE * Penetration testing background or OWASP Top 10 fluency. * Experience with CI/CD security hardening at scale. * A track record of building security tools other engineers want to use. * Experience reporting vulnerability management and security posture metrics to leadership. * Familiarity with social engineering attacks, especially phishing, and the controls that reduce them. Equal opportunity employer We believe that bringing people together from different backgrounds, experiences and perspectives makes for a healthy workplace, a more successful business and a better world. We value diversity and encourage everyone to come and soundtrack the world with us. Application Ready to make the world feel your work? Please apply, in English.
Multiply is an end-to-end provider of products, services, and training within embedded systems, functional safety, and automotive cybersecurity among other aspects of Engineering & IT. Our flagship product, VisFlow, enables structured development, compliance, and governance for safety- and security-critical automotive systems across the full lifecycle. We are now expanding our teams and are looking for Embedded Engineers with experience in AUTOSAR, Cybersecurity, Functional Safety, and Electrified Systems to support both product development and customer delivery using VisFlow. What You Will Do Develop and integrate embedded software using AUTOSAR (Classic and/or Adaptive). Work in Linux-based embedded environments across in-vehicle platforms (IHU, DHU, UXC). Contribute to High Voltage system software and interface with Battery Management Systems (BMS). Enable SBOM generation in build systems and establish continuous SBOM for all releases. Integrate vulnerability and OSS regression scanning into CI/CD pipelines. Support cybersecurity certifications for EU, US, and China markets. Produce and maintain cybersecurity documentation (TARA, CSPD, CS-CASE) in Teamcenter. Participate in CSMS reviews, penetration testing support, and governance reporting. Provide compliance evidence for UNECE WP.29 R155 and ISO/SAE 21434. What We Are Looking For Experience in embedded software engineering and AUTOSAR. Background in automotive cybersecurity and/or functional safety. Experience working with Linux-based embedded systems. Exposure to High Voltage systems; BMS experience is meriting. Familiarity with CI/CD, SBOM, vulnerability management, and structured compliance work. Why VisFlow & Multiply Work on safety-critical, electrified, and connected vehicle systems. Exposure to global platforms and regulations. Long-term assignments with strong technical depth. Competitive compensation and flexible working models.
Tech Innovation at Apotea Apotea is Sweden’s largest online pharmacy, committed to making healthcare products accessible and efficient for everyone. Our Tech department aims to redefine how AI and automation drive modern businesses — not by forcing AI into traditional workflows, but by creating AI-driven systems that give humans control, insight, and the ability to apply their expertise where it matters most. The Core Technology team builds the architectural foundation supporting e-commerce, logistics, data, AI/ML, and customer experience. We ensure all development aligns with our long-term vision and contributes to Apotea’s growth. We are now looking for a Lead Security Engineer to take full ownership of Apotea’s security strategy, ensure compliance, and enable teams to build and innovate securely at scale. The Role As Lead Security Engineer, you will define, implement, and evolve security practices across AWS (serverless-first), e-commerce, logistics, and data platforms. The role combines strategic leadership with hands-on engineering — you will implement security yourself while empowering others to do so. You will act as the first-line technical security lead, defining guardrails, monitoring risks, and leading incident response. You will develop secure practices for coding with AI assistants, ensuring generated code meets security standards, avoids data leakage, and aligns with regulations. You will also communicate complex security concepts clearly across the organization. Location: Sveavägen 168, Stockholm, Sweden (On-site) Key Responsibilities Security Leadership Own and evolve Apotea’s security strategy across cloud, applications, and infrastructure. Translate business and regulatory requirements into sustainable security practices. Define guardrails, best practices, and reference implementations for teams. Hands-On Security Engineering Design and implement secure AWS serverless and data-driven systems. Lead IAM practices, enforcing least-privilege and zero-trust. Oversee vulnerability management, penetration testing, and patching. Ensure secure DevSecOps pipelines and IaC security. Monitoring & Incident Response Build and operate monitoring, detection, and alerting systems (SIEM, EDR, GuardDuty, Security Hub). Lead incident response: investigate, contain, and recover from security events. Maintain and test playbooks for emerging threats. Governance & Compliance Ensure GDPR, healthcare regulations, and industry standards compliance. Embed security and privacy by design across development. Partner with legal, compliance, and business units for regulatory readiness. Provide training and frameworks for safe AI usage without compromising security. Collaboration & Culture Work closely with engineers, architects, and product teams to integrate security early. Mentor engineers in secure coding and infrastructure practices. Advocate for a strong security culture. Qualifications Extensive experience as a security engineer and organization’s main security expert. Proven expertise in securing AWS (IAM, networking, serverless, encryption, monitoring). Strong background in designing secure, scalable, cloud-native systems. Hands-on experience with SIEM, EDR, vulnerability scanners, secrets management. Deep knowledge in DevSecOps and IaC (CDK, Terraform, CloudFormation). Programming/scripting skills: Go, TypeScript, .NET, Python, or similar. Nice to Have: experience in regulated industries, compliance frameworks (ISO 27001, NIST, PCI-DSS), or red/blue team operations. Why Join Apotea? Stable company with a meaningful mission: improving healthcare accessibility. Work on cutting-edge AI, ML, and automation impacting millions of customers. Modern cloud-native technologies (serverless, AI, event-driven). Flat, agile organization with minimal bureaucracy. Career growth through training, mentorship, and conferences. End-to-end project ownership from concept to deployment. Culture of experimentation, collaboration, and innovation. About Apotea Apotea.se is Sweden’s largest online pharmacy, with the country’s broadest range of over 32,000 non-prescription items and nearly 19,000 prescription drugs for humans and animals. Recognized as Sweden’s most sustainable e-commerce company (Sustainable Brand Index 2021), we simplify everyday life for our customers with fast deliveries and expert advice. In 2024, Apotea reached a turnover of SEK 6.5 billion and currently employs about 1,000 people across Stockholm, Lidingö, and Morgongåva. Apotea is an inclusive employer that values diversity. We welcome all applicants and strive to create a work environment where people, regardless of background, gender, age, religion, or disability, can thrive and grow. Recruitment Process Apply Interview: Screening Interview: Technical Capabilities Interview: Culture Fit Background Check: As a pharmacy, we always conduct a background check. Offer Presented Application Do not hesitate to send in your application already today. For more information or questions, visit our career page or contact us at jobb@apotea.se. We do not accept applications via email. LinkedIn Instagram Join Us and Make a Difference - We hope you want to be a part of our team! Submit your application today—interviews are conducted on an ongoing basis, and the position may be filled immediately. Start date by agreement. Welcome to Apotea – where technology meets health and creates magic!
Tech Innovation at Apotea Apotea is Sweden’s largest online pharmacy, committed to making healthcare products accessible and efficient for everyone. Our Tech department aims to redefine how AI and automation drive modern businesses — not by forcing AI into traditional workflows, but by creating AI-driven systems that give humans control, insight, and the ability to apply their expertise where it matters most. The Core Technology team builds the architectural foundation supporting e-commerce, logistics, data, AI/ML, and customer experience. We ensure all development aligns with our long-term vision and contributes to Apotea’s growth. We are now looking for a Lead Security Engineer to take full ownership of Apotea’s security strategy, ensure compliance, and enable teams to build and innovate securely at scale. The Role As Lead Security Engineer, you will define, implement, and evolve security practices across AWS (serverless-first), e-commerce, logistics, and data platforms. The role combines strategic leadership with hands-on engineering — you will implement security yourself while empowering others to do so. You will act as the first-line technical security lead, defining guardrails, monitoring risks, and leading incident response. You will develop secure practices for coding with AI assistants, ensuring generated code meets security standards, avoids data leakage, and aligns with regulations. You will also communicate complex security concepts clearly across the organization. Location: Sveavägen 168, Stockholm, Sweden (On-site) Key Responsibilities Security Leadership * Own and evolve Apotea’s security strategy across cloud, applications, and infrastructure. * Translate business and regulatory requirements into sustainable security practices. * Define guardrails, best practices, and reference implementations for teams. Hands-On Security Engineering * Design and implement secure AWS serverless and data-driven systems. * Lead IAM practices, enforcing least-privilege and zero-trust. * Oversee vulnerability management, penetration testing, and patching. * Ensure secure DevSecOps pipelines and IaC security. Monitoring & Incident Response * Build and operate monitoring, detection, and alerting systems (SIEM, EDR, GuardDuty, Security Hub). * Lead incident response: investigate, contain, and recover from security events. * Maintain and test playbooks for emerging threats. Governance & Compliance * Ensure GDPR, healthcare regulations, and industry standards compliance. * Embed security and privacy by design across development. * Partner with legal, compliance, and business units for regulatory readiness. * Provide training and frameworks for safe AI usage without compromising security. Collaboration & Culture * Work closely with engineers, architects, and product teams to integrate security early. * Mentor engineers in secure coding and infrastructure practices. * Advocate for a strong security culture. Qualifications * Extensive experience as a security engineer and organization’s main security expert. * Proven expertise in securing AWS (IAM, networking, serverless, encryption, monitoring). * Strong background in designing secure, scalable, cloud-native systems. * Hands-on experience with SIEM, EDR, vulnerability scanners, secrets management. * Deep knowledge in DevSecOps and IaC (CDK, Terraform, CloudFormation). * Programming/scripting skills: Go, TypeScript, .NET, Python, or similar. Nice to Have: experience in regulated industries, compliance frameworks (ISO 27001, NIST, PCI-DSS), or red/blue team operations. Why Join Apotea? * Stable company with a meaningful mission: improving healthcare accessibility. * Work on cutting-edge AI, ML, and automation impacting millions of customers. * Modern cloud-native technologies (serverless, AI, event-driven). * Flat, agile organization with minimal bureaucracy. * Career growth through training, mentorship, and conferences. * End-to-end project ownership from concept to deployment. * Culture of experimentation, collaboration, and innovation. About Apotea Apotea.se is Sweden’s largest online pharmacy, with the country’s broadest range of over 32,000 non-prescription items and nearly 19,000 prescription drugs for humans and animals. Recognized as Sweden’s most sustainable e-commerce company (Sustainable Brand Index 2021), we simplify everyday life for our customers with fast deliveries and expert advice. In 2024, Apotea reached a turnover of SEK 6.5 billion and currently employs about 1,000 people across Stockholm, Lidingö, and Morgongåva. Apotea is an inclusive employer that values diversity. We welcome all applicants and strive to create a work environment where people, regardless of background, gender, age, religion, or disability, can thrive and grow. Recruitment Process 1. Apply 2. Interview: Screening 3. Interview: Technical Capabilities 4. Interview: Culture Fit 5. Background Check: As a pharmacy, we always conduct a background check. 6. Offer Presented Application Do not hesitate to send in your application already today. For more information or questions, visit our career page or contact us at jobb@apotea.se. We do not accept applications via email. LinkedIn Instagram Join Us and Make a Difference - We hope you want to be a part of our team! Submit your application today—interviews are conducted on an ongoing basis, and the position may be filled immediately. Start date by agreement. Welcome to Apotea – where technology meets health and creates magic!
Roxtec is the world-leading developer and manufacturer of modular-based sealing solutions for cable and pipe penetrations. Our solutions are used in everything from the energy industry to shipbuilding to protect life and assets from risks such as fire, gas, and water. We are a rapidly growing group, serving customers in more than 80 markets worldwide. Do you want to be part of building digital solutions that make a real difference? At Roxtec, your work contributes to protecting people and critical infrastructure worldwide, while you develop your skills and make an impact in a global and collaborative environment. Your role As a Software Developer at Roxtec, you will join our global IT team in Karlskrona, working closely with IT and business stakeholders worldwide. You will build and develop scalable, secure solutions while helping shape how we evolve our systems, with a strong focus on quality and performance. How you contribute • Design and develop solutions aligned with business needs and long-term goals • Improve and automate development, testing, and deployment processes • Monitor systems, troubleshoot issues, and ensure stable operations • Contribute to secure, compliant, and highly available IT environments • Collaborate with developers, engineers, and stakeholders globally • Drive improvements through new technologies and innovative ways of working • Build and maintain integrations between systems and platforms Your qualifications • Bachelor’s degree in computer science, engineering, or a related field • At least 3 years of experience as a developer, DevOps engineer, or similar • Experience in solution architecture • Experience with cloud or hosting platforms such as Azure, AWS, GCP, or on-prem • Experience with DevOps tools (e.g., Terraform, Docker, GitHub) • Experience with programming languages such as C#, Java, or TypeScript Who you are You are a curious and driven team player who takes ownership, enjoys solving problems, and builds strong relationships across teams. Speed, simplicity, and flexibility are guiding principles in how we work at Roxtec, and something that feels natural to you. Read more about our Core Values here (https://www.roxtec.com/en/about-us/about-roxtec/roxtec-core-values/). What we offer you • The opportunity to work with meaningful solutions that protect people and critical infrastructure worldwide • A global environment with close collaboration across teams and markets • Opportunities to grow and develop your skills through new technologies and challenges • A workplace built on trust, collaboration, and continuous improvement Application Want to learn more? Feel free to reach out to Per Fridberg, Manager Product & Data Management, at +46 733 15 53 70, or Elin Jurjaks, HR Manager Sweden, at +46 733 31 31 89. We review applications on an ongoing basis, so please apply as soon as you are ready, no later than 2026-08-10. The final candidate will be subject to a background check.