
Qred Bank AB · Stockholm
At Qred, we’re building the bank for small businesses. Since launching 11 years ago, we’ve grown from startup to profitable fintech scale-up, now generating ove...
At Qred, we’re building the bank for small businesses. Since launching 11 years ago, we’ve grown from startup to profitable fintech scale-up, now generating over 1 billion SEK in annual revenue and supporting 50,000+ entrepreneurs across Northern Europe. We combine smart technology, real data, and human judgment to make financing simple, fast, and fair. With bold growth plans and strong momentum across multiple markets, we’re now looking for a SecOps Engineer for the next phase of growth.
About the Role
As a SecOps Engineer within our Engineering Enablers domain, you will bridge the gap between rigorous security standards and high-velocity product delivery. You will have end-to-end ownership of the security guardrails that protect our platform, moving away from manual gates toward automated, self-service security. Your mission is to empower our engineering teams to ship code confidently by embedding security into the very fabric of our scaling financial systems.
Key responsibilities
Architect and implement automated security guardrails within our AWS environment to ensure proactive risk mitigation.
Support and mentor product teams during the discovery phase to integrate security requirements into the initial design of new features.
Define and manage company-wide security policies, translating complex compliance needs into actionable engineering practices.
Lead the response to security incidents, driving the process from initial detection and analysis through to containment and long-term resolution.
Drive the adoption of security awareness programs across the organization, using data to measure and improve our collective security posture.
What we’re looking for
We are looking for a professional who thrives in a decentralized environment and values enablement over enforcement. As we are highly invested in AI, you possess a strong understanding of how to enable secure development processes and data integrity within that space. You are motivated by the challenge of building scalable frameworks that reduce cognitive load for other engineers while maintaining the high integrity required of a regulated bank.
Qualifications
Several years of experience in security engineering or DevSecOps, ideally within Fintech or another highly regulated industry.
Deep technical knowledge of AWS security services, IAM frameworks, and cloud infrastructure.
Practical experience in incident management and the development of automated security tooling.
Strong communication skills with the ability to influence technical roadmaps and drive alignment across distributed teams.
Practical experience with EDR/XDR solutions and MDM frameworks is preferred.
Why Qred?
This is the place to be if you’re looking for a place to grow. Qred is growing fast, and our Qredsters along with it. With a non-bureaucratic organization and delegated responsibilities, we make sure there’s a short path from idea to action. In addition to our great culture, you get to work with the latest cutting-edge techniques, full ownership, and last but not least a bunch of great competent colleagues to learn from!
One Last Thing
This is a full-time, permanent position based in our headquarters in Stockholm. We believe our culture thrives when we work together, which is why we have an office-first approach. To balance this with some flexibility, we have the option of working remotely one day per week. We review applications on a rolling basis and while the start date is flexible, the right candidate can join us immediately.
Qred celebrates diversity and does not discriminate based on ethnicity, religion, national origin, gender, sexual orientation, age, disability status, or any other applicable characteristics protected by law.
About us We are champions of rail, inspired to build a greener, more sustainable future of travel. Trainline enables millions of travellers to find and book the best value tickets across carriers, fares, and journey options through our highly rated mobile app, website, and B2B partner channels. Great journeys start with Trainline 🚄 Now Europe’s number 1 downloaded rail app, with over 135 million monthly visits and £6.3 billion in annual ticket sales, we collaborate with 270+ rail and coach companies in over 40 countries. We want to create a world where travel is as simple, seamless, eco-friendly and affordable as it should be. Today, we're a FTSE 250 company driven by our incredible team of over 1,000 Trainliners from 50+ nationalities, based across London, Paris, Barcelona, Milan, Edinburgh and Madrid. With our focus on growth in the UK and Europe, now is the perfect time to join us on this high-speed journey. Introducing Security Operations @ Trainline 👋 Our Security Operations team plays a vital role in protecting Trainline's people, platforms and data. As a Security Operations Engineer, you'll primarily working on monitoring, investigating and responding to security events while helping to strengthen our detection and response capabilities through continuous engineering and automation improvements. Working closely with Security, Engineering and Technology teams, you'll combine operational analysis with hands-on engineering, using Splunk, automation and AI to improve threat detection, streamline investigations and enhance our overall security posture. You'll optimise our security tooling, improve detection capabilities and support incident response across the business through threat hunting, continuous improvement and meaningful reporting that enables informed security decisions. If you're passionate about cybersecurity and enjoy solving complex problems in a collaborative environment, we'd love to hear from you. In this role as the Security Operations Engineer, you will... 🚄 * Monitor, triage and investigate security alerts, leading technical investigations and working with stakeholders to contain, remediate and learn from security incidents. * Use Splunk Search Processing Language (SPL) to investigate security events, identify patterns of malicious activity and support incident response. * Design, develop, automate and continuously tune Splunk detection rules, improving alert fidelity, reducing false positives and expanding visibility across our technology estate. * Build and enhance automation and AI-driven workflows to improve threat detection, investigation and alert triage, enabling the team to respond more effectively and efficiently at scale. * Perform proactive threat hunting using threat intelligence and security telemetry to identify emerging threats, improve detection capabilities and help shape our Security Operations roadmap. * Support the administration, configuration and continuous optimisation of our SIEM platform (Splunk), ensuring it remains resilient, up to date, cost effective and aligned with industry best practice. * Partner with Engineering and Technology teams to embed security best practices into systems, tooling and operational processes, while supporting vulnerability management activities, including the assessment and response to critical and zero-day vulnerabilities. * Participate in the On-Call Rota with the Team. * Produce clear documentation, dashboards and reporting that provide operational insight, support knowledge sharing and enable stakeholders to make informed security decisions. You'll also contribute to the wider Security function by participating in the on-call rota (once established in the role) and supporting compliance and certification activities, including GDPR, PCI DSS and ISO 27001. We'd love to hear from you if you have... 🔍 * Hands-on experience with Splunk, including developing and tuning detection rules, log management and investigating security events using Splunk Search Processing Language (SPL). * Experience designing, automating and continuously improving threat detection capabilities using automation and AI to enhance Security Operations. * Experience applying AI, whether through vendor-provided capabilities or custom workflows, to improve threat detection, investigations or operational efficiency would be highly beneficial. * Strong technical knowledge across cybersecurity, infrastructure, networking or cloud technologies, with the ability to investigate security events and make informed, risk-based decisions. * Experience working with security technologies such as Microsoft Defender, endpoint detection and response (EDR) solutions and SIEM platforms. * Experience working with Web Application Firewalls (WAF), including creating, tuning and maintaining WAF rules to protect internet-facing applications, would be highly beneficial. * Experience with vulnerability management, including assessing, prioritising and responding to critical vulnerabilities and zero-day exploits, would be beneficial. * Experience working within an e-commerce or high-traffic digital environment would be highly beneficial, with an understanding of the unique security challenges associated with customer-facing platforms. * Excellent analytical, communication and documentation skills, with the ability to collaborate effectively across teams and explain technical concepts clearly to both technical and non-technical stakeholders. Experience supporting compliance frameworks such as GDPR, PCI DSS or ISO 27001 would be helpful but isn't essential. More information: Enjoy fantastic perks like private healthcare & dental insurance, a generous work from abroad policy, 2-for-1 share purchase plans, an EV Scheme to further reduce carbon emissions, extra festive time off, and excellent family-friendly benefits. We prioritise career growth with clear career paths, transparent pay bands, personal learning budgets, and regular learning days. Jump on board and supercharge your career from day one! We're operating a hybrid model and ask that Trainliners work from the office a minimum of 60% of their time over a 12-week period. We also have a 28-day Work from Abroad policy. Our values represent the things that matter most to us and what we live and breathe everyday, in everything we do: * 💭 Think Big - We're building the future of rail * ✔️ Own It - We focus on every customer, partner and journey * 🤝 Travel Together - We're one team * ♻️ Do Good - We make a positive impact We know that having a diverse team makes us better and helps us succeed. And we mean all forms of diversity - gender, ethnicity, sexuality, disability, nationality and diversity of thought. That's why we're committed to creating inclusive places to work, where everyone belongs and differences are valued and celebrated. Interested in finding out more about what it's like to work at Trainline? Why not check us out on LinkedIn, Instagram and Glassdoor!
Here at Acorn we are looking for a passionate Senior Infrastructure Engineer to join us in Hands-on multi-disciplined technical support role within the IT infrastructure support and 3rd line escalation team. Within this team you will be supporting the Infrastructure Support Manager in driving delivery of robust, performant, resilient and recoverable infrastructure and systems, a mixture of on-premises and Azure. You will be supporting the technical development of the internal infrastructure team, maintaining infrastructure best practice and standards as well as ensuring all platforms are secure and meet all legislative compliance requirements. Role: Senior Infrastructure Engineer Location: Liverpool City Centre HQ Salary: £50,000–£58,000 depending on experience What you will be doing: * You will be in a hands-on technical lead role within the infrastructure team, supporting the promotion of technical excellence and quality across the team and leading knowledge transfer. * Use your expertise of classic infrastructure disciplines, technologies & best practices to drive the deployment and management of the on-premises infrastructure, ensuring all infrastructure assets and interfaces have appropriate monitors, alerts, backups and recovery plans in place. * Although this role does not directly manage the Azure platform, it is expected that this role will manage aspects with the platform, requiring knowledge and close collaboration with the cloud platform team * Use your experience to help the delivery of best-of-breed 3rd line support function, ensuring tickets and issues raised are managed efficiently and to expected quality, within SLA. * Be continually aware of enhancements available within current deployed infrastructure solutions as well as any shifts in technology & enhancements benefitting the business. * Work cross functionally with our Project, Development, Cloud Platform, and SecOps teams for new deployments, providing continual management and maintenance. * Supporting the development of disaster recovery plans and maintaining operational resilience within the infrastructure remit. * Lead technical evaluation of products within the infrastructure domain, participating in the deployment & implementation of the infrastructure technologies. * Contribute to the technical design of best of breed infrastructure solutions, exploiting industry best practice. * Work with the SecOps engineers to remediate any vulnerabilities identified within remit. Critical Competencies: * Minimum 4 years’ Infrastructure experience, with minimum of 1yrs in a similar senior capacity or performing senior duties within a team of engineers with a support background. * Excellent Active Directory and associated services skills * Experience with broad variety of classic infrastructure disciplines & technologies; Network, Windows Server, Storage, Virtualisation, Security and Mail and associated services and functions * Experience of team supervision, or mentoring would be an advantage. * High level of knowledge with Office 365 suite of applications, security, and tools * Excellent Microsoft Exchange skills, ideally in Hybrid solution * Previous experience in designing and leading implementation of infrastructure solutions. * Experience using infrastructure auto-deployment and scripting techniques; PowerShell, Ansible * Experience of the development of design and documenting technical solutions * Proactive and logical approach to fault identification, troubleshooting and problem solving. * Working knowledge of ITIL What we are looking for: * Network technologies; All LAN/WAN components, routing and protocols * Windows Server and storage architecture solutions * MS Exchange and messaging techniques and troubleshooting, ideally in hybrid setup * An understanding of cloud computing platforms, principals, and services * PowerShell or similar Scripting solutions * Zero-trust solutions, VPN, SSO setup, PIM and MFA solutions * Perimeter and Endpoint Security solutions, SWEG, Web Access, Anti-Malware config * Microsoft Windows Server OS, updating, upgrading, Linux experience an advantage * Backup & Recovery design and testing * Mitigating infrastructure and operating system security vulnerabilities * MS Office 365 platform support; SharePoint, OneDrive, Teams, Intune management * Working within a ticket management system with SLA and KPI adherence Any certification or working experience supporting or implementing several of the infrastructure technologies listed below would be an advantage. * Linux Server configuration and support * MS SQL server and support * Deploying and supporting cloud infrastructure, any platform an advantage * Web application development techniques and tools, XML, .Net framework, and development lifecycle, to provide adequate support to the developer teams * Jira helpdesk and confluence * Terraform IaC deployments * Remote Desktop RDS/AVD/VDI environments * Supporting and securing Macbook devices * IP Telephony design, implementation and/or support Why Join Us: * A modern tech stack and a culture that values craftsmanship * A supportive team where you’ll learn from experienced developers and designers * Opportunities for training, mentorship and career progression * Freedom to experiment, ask questions and influence how we work * Top-tier tools and a workspace built for creativity and collaboration Team and Culture You’ll join a friendly, collaborative squad that brings together designers, engineers and product thinkers. We work closely, share ideas openly and always look for ways to get better. We believe in ownership, curiosity and constant learning. You’ll be encouraged to ask questions, try new things and take on challenges that stretch your skills. If you’re looking for a place to grow, learn from others and build products you can be proud of, this is the team for you. Grow with Acorn At Acorn Insurance, we’re proud of our Liverpool roots — and even prouder of how far we’ve come. As part of the Acorn Group, we bring over 40 years of specialist insurance expertise to the table. From humble beginnings, we’ve grown into a national leader, now employing 1,700+ people across the UK and reached a milestone £750 million in total value of insurance policies written in 2024. We’re growing fast, with new opportunities emerging every week. That growth is largely due to the values we share: * 🦏 We run through walls for our customers and each other * 🐐 We challenge the status quo * 🐧 We succeed when we help those around us succeed * 🐆 We decide quickly when the smart thing to do is use our judgement Benefits: * 🌴 35 days’ holiday (including bank holidays) with additional buy/sell options * 🧠 24/7 mental health support & free counselling available * ☝ Grow with us: Through career fairs, leadership programs, and learning on the go! * 💸 Flexible benefits, including early access to salary via our internal platform * 🏡 Hybrid working options to support work-life balance and individual needs * 🎉 Recognition awards, social events & more Our Commitment to our colleague’s: These aren’t just words — they’re the principles we live by. And we’re proud to back them up with real action, earning recognition and accreditation from leading organisations that share our commitment to people and growth: * 🧠 Mindful Employer – championing mental health and wellbeing * ♿ Disability Confident Level 1 & 2 – creating accessible, inclusive opportunities * 🌸 Menopause Friendly accredited – supporting every stage of life * 🎖️ Armed Forces Covenant signatory – honouring those who serve * 🏆 Great Places to Work 2024/25 – fostering an engaging and positive workplace culture * 📈 Best Place to Work for Development – proud to be investing in people’s future * 👩💼 Best Place to Work for Women – breaking down barriers to women's career progression If you’re looking for a company with a strong culture, real career progression, and a people-first approach — all rooted in the heart of Liverpool — Grow with Acorn. A Few Things to Know Before You Apply We’re really excited that you’re considering joining Acorn! To help everything go smoothly, here are a couple of things to keep in mind: 🔍 Checks & Clearances All roles at Acorn are subject to DBS and financial checks. Any offer we make will be conditional until these are completed to a satisfactory standard. 🌍 Visa Requirements Because our training is quite comprehensive, we can only consider applicants who have at least one year remaining on their Graduate or Post-Study Work visa. At the moment, we’re not able to offer visa sponsorship. 💬 We’re Here to Support You We’re committed to creating an inclusive, supportive workplace where everyone can flourish. If you need any adjustments during the recruitment process—or once you’re part of the team—just let us know. Whether it’s flexible hours, adapted equipment, or a bit of extra support, we’ll work with you to make sure you can do your best work. #LI-JL1
L’histoire du groupe Theodo et son succès Theodo accompagne depuis 2009 les entreprises innovantes dans la conception, le développement et le déploiement de produits digitaux ingénieux - tels que la plateforme TF1+, l'application LCL Pro ou l'application France Identité Numérique - en tirant parti du meilleur de la technologie et de l’approche Lean. Theodo connait une croissance exceptionnelle depuis 15 ans : nos équipes rassemblent plus de 700 Theodoers, principalement des Software Engineers, passionnés de technologie et d’amélioration continue. En 2025, le groupe Theodo génère 100M€ de CA. En 2021, Theodo lance une practice experte en cybersécurité pour aider nos clients à sécuriser leur environnement Cloud. Aujourd'hui, l'équipe compte 11 SecOps Engineers. Tes missions : Nous intervenons en équipe sur l'essentiel de nos projets : Lead SecOps, SecOps et Project Manager travaillent main dans la main pour garantir l’impact de nos actions chez nos clients. En tant que Lead SecOps / DevSecOps, tu seras responsable : - de la stratégie sécurité des projets sur lesquels tu interviens (audits de sécurité, identification de failles, conception d'architectures "secure-by-design", remédiations pragmatiques, mise en conformité…) - du delivery, tu gardes les mains dans la tech pour contribuer à l'avancée du projet (IAM, sécurité réseau, pentest, outils de sécurité Cloud et CI/CD, hardening, secrets management… feront partie de ton quotidien) - de la progression de ton équipe, via de la formation, du pair programming et du coaching des SecOps Tu auras également l'opportunité de t'impliquer sur des projets internes à Theodo Cloud : l'amélioration de nos standards de sécurité, la construction de formations, la veille technique et le thought leadership (articles, talks)... Les opportunités d’évolution : Nous proposons une évolution possible à nos Leads SecOps vers un rôle d’Engineering Manager (Management et/ou Expertise) Profil recherché : Nous recherchons une personne ayant : - 3 ans d’expérience minimum sur un poste de SecOps ou DevSecOps - l’habitude de travailler sur une stack technique moderne : Kubernetes, Terraform, cloud providers publics,… - connaître les particularités de l'hébergement on premises / cloud privé est un plus - une maîtrise des concepts de sécurité infrastructure : IAM avancé, sécurité réseau (VPC, firewalls, WAF), CI/CD, méthodologies de pentest et d'audit - l’envie de travailler en équipe - la volonté de participer au développement de l'entreprise Tu ne coches pas 100% des critères mais tu penses tout de même correspondre à notre recherche ? Ne t’auto-censure pas et envoie-nous ta candidature, on se fera un plaisir de l’étudier ! Pour information : - Le poste est proposé en CDI, basé depuis nos locaux à Paris. - Nous permettons à nos équipes de télé-travailler jusqu’à 2 jours par semaine. - Le salaire proposé dépend du niveau d’expérience de chacun : nous en parlons toujours dès le premier appel téléphonique. Déroulement des entretiens : Nous répondons à toutes les candidatures dans un délai de 3 jours. Si ton profil nous intéresse, nous te proposons le process suivant : - un appel téléphonique de 30 minutes avec un membre de l’équipe recrutement, pour comprendre tes critères de recherche - un entretien d’une heure avec le recruteur ou la recruteuse avec qui tu as échangé à la première étape, pour parler plus en détail de la culture Theodo Cloud - un entretien technique pour évaluer tes compétences en architecture de sécurité avec un ou une Engineering Manager - un entretien technique pour évaluer tes compétences sur Kubernetes et Terraform avec un ou une Engineering Manager - un échange avec notre Partner cybersécurité Notre process dure 2 à 3 semaines en moyenne. Tu seras accompagné(e) par une personne de l’équipe recrutement, qui sera là pour te coacher tout au long du process.