Sida 1 av 23
Veritaz is a leading IT staffing solutions provider in Sweden, committed to advancing individual careers and aiding employers in ensuring the perfect talent fit. With a proven track record of successful partnerships with top companies, we have rapidly grown our presence in the USA, Europe, and Sweden as a dependable and trusted resource within the IT industry. Assignment Description We are looking for an experienced Senior Application Security Coordinator What You Will Work On Coordinate remediation of findings from penetration tests and vulnerability assessments Manage and track security findings through their complete lifecycle Assess and prioritize vulnerabilities based on business risk Coordinate remediation activities across business and technical teams Work closely with application owners, infrastructure teams, and security stakeholders Establish and maintain governance, reporting, and remediation processes Monitor progress and ensure timely resolution of identified vulnerabilities Facilitate communication between multiple stakeholders Improve visibility and control of the organization's vulnerability landscape Support compliance with internal security standards and external regulatory requirements Drive continuous improvements in vulnerability management processes Ensure effective collaboration across cross-functional teams What You Bring Experience working with Jira Experience coordinating remediation of security findings Strong ability to assess risks and prioritize remediation activities Experience driving structured remediation and follow-up processes Good understanding of application security and infrastructure security Experience handling results from vulnerability scanning and penetration testing Knowledge of CVE, CWE, and CVSS Strong stakeholder management and communication skills Experience coordinating work across multiple technical and business teams Strong organizational and planning skills Experience with security governance and reporting Ability to work independently in complex environments Analytical, structured, and proactive approach to problem-solving
TL;DR We are seeking an Application Security Engineer to champion security across our entire development lifecycle. You’ll play a pivotal role in reviewing code, designing secure features, and mentoring engineers, ensuring security is at the heart of everything we build. If you’re passionate about application security, thrive on close collaboration with developers, and want to do the work of your life, this is your opportunity WHY LOVABLE? Lovable lets anyone and everyone build software with any language. From solopreneurs to Fortune 100 teams, millions of people use Lovable to transform raw ideas into real products - fast. We are at the forefront of a foundational shift in software creation, which means you have an unprecedented opportunity to change the way the digital world works. Lovable-built applications and websites are visited hundreds of millions of times a month, and our enterprise footprint is compounding fast. And we’re just getting started. We’re a small, talent-dense team building a generation-defining company from Stockholm. We value extreme ownership, high velocity, and low-ego collaboration. We seek out people who care deeply, ship fast, and are eager to make a dent in the world. WHAT YOU’LL BRING * 5+ years of experience in application security, securing cloud-native environments at product-focused tech companies, high-growth startups, or leading AI labs. * Strong programming and engineering skills. * Deep expertise in application security: secure code review, threat modeling, SAST/DAST, supply chain security, product patching, and vulnerability management. * Strong background in securing engineering infrastructure: CI/CD pipelines, secrets management, service-to-service authentication, containerized workloads, and public cloud platforms. * Hands-on experience collaborating with developers to design and implement security features and best practices. * Passion for educating and mentoring engineers on secure coding, vulnerability remediation, and emerging threats. * Systems mindset: comfortable reading and contributing to codebases, building security tooling, and integrating security into engineering workflows. * Bonus: Experience building internal security tools or contributing to open-source security projects. WHAT YOU’LL DO * Conduct secure code reviews, threat modeling, and architecture assessments to identify and mitigate vulnerabilities early. * Work closely with engineering teams to design and implement security features, provide actionable feedback, and ensure security is embedded in product development. * Lead security training, workshops, and 1:1 mentoring to upskill developers and foster a security-first culture. * Integrate SAST/DAST and supply chain security tools into our CI/CD pipelines for continuous, automated protection. * Detect, triage, and respond to application vulnerabilities and incidents, driving remediation and continuous improvement. * Monitor and address emerging risks in AI infrastructure, LLM pipelines, and third-party dependencies. * Secure the last piece of software. OUR TECH STACK * Frontend: React and Typescript * Backend: Golang and Rust * Cloud: Cloudflare, Google Cloud, AWS, Terraform * DevOps & Tooling: CI/CD pipelines, observability, infrastructure-as-code And always exploring what’s next. HOW TO APPLY * Please submit your application in English—our working language at Lovable. * We’re committed to fair and equal treatment for all candidates. If you’re interested, apply via our careers portal
EQT is looking for an Application & AI Cyber Security Engineer to join our Cyber Security Engineering team, owning the security posture of our hosted applications, container platforms, and AI environments. This is a hands-on engineering role where you will build automated guardrails and real-time visibility — making the secure path the easy path across a modern, globally distributed technology landscape. ABOUT THE TEAM The Cyber Security Engineering team defines and validates security standards across EQT's technology landscape. Operating as a trusted security function, the team works closely with platform engineering, cloud infrastructure, identity, and technology assurance teams to strengthen controls while enabling innovation. This role sits within a small, high-trust team where collaboration, curiosity, and technical depth are core to how we work. The team supports both traditional application environments and emerging AI and agentic platforms, helping EQT navigate a rapidly evolving threat landscape with practical, engineering-led security standards. You will report to the Head of Digital Employee Experience and partner closely with the CISO function, contributing engineering depth directly to governance and policy decisions. ABOUT THE ROLE This role brings together application security, container security, and AI security into one evolving discipline — giving you the scope to influence standards, technical controls, and governance frameworks across a global technology environment. The mandate is to build automated guardrails and observability at scale, not to review individual applications by hand. * Design and deploy automated controls for container platforms and application deployments — admission controllers, policy-as-code, and pre-configured scanning — that enforce standards at the point of deployment rather than after the fact. * A growing part of the job is enabling citizen development — making sure non-technical teams can use AI coding tools like Claude Code and CoWork without needing to come through security first, because the guardrails are already there. * Curate internal security tooling, automation, and AI skills for cost, reliability, and security posture — favouring deterministic, scripted components that run fast and cheap over token-intensive approaches, and tracking cost-per-outcome across security controls as a core operating discipline. * Own container security standards as enforceable controls: image scanning policy, runtime baselines, and registry governance across all deployment paths, including workloads outside formal pipelines. * Manage software supply chain risk end-to-end, including dependency scanning, build-time and runtime composition analysis, and identifying high-propagation risk junctions. * Build application security observability that goes beyond static inventories — a live picture of what is deployed, what it is composed of, and where risk is concentrated — and provide actionable dashboards for engineering leadership and the CISO function. * Own the security configuration of EQT's AI platforms, including hardening, access controls, data flow governance, and defences against prompt injection and data exfiltration. * Assess MCP connector risk — API call patterns, data processing terms, allowlist maintenance, and dependency chains — and evaluate new AI tools with enough technical depth to inform CISO-level approval decisions. * Define behavioural baselines for agentic execution environments and close AI-specific insider threat gaps, ensuring monitoring tools can see into AI data flows. * Collaborate with Detection & Insider Threat Engineers on container runtime telemetry, and with Identity & Cloud Security Engineers on service identity, workload access, and secrets management. TOOLS YOU'LL WORK WITH Kubernetes, CI/CD platforms, SBOM tooling, Aikido, Claude Enterprise, Claude Code, MCP, CoWork, DTEX, Datadog, policy-as-code frameworks. ABOUT YOU You are a technically grounded security engineer who cares deeply about developer experience and approaches security friction as a design problem to solve, not a trade-off to accept. You work with clarity and ownership, communicate technical findings to senior stakeholders with confidence, and are actively building your knowledge of AI and agentic security. What you'll bring (must-have): * Proven hands-on experience with container security — Kubernetes, image scanning, admission control, runtime protection, and policy-as-code. * A track record of building automated security controls that scale, with an instinct for making the right path easy and the wrong path hard rather than relying on manual review. * Solid application security fundamentals, including familiarity with OWASP Top 10, secure development lifecycle, and software supply chain risk, with an orientation toward enforcement over assessment. * Experience building security visibility into running systems through instrumentation, runtime analysis, or operational dashboards — understanding the difference between knowing what was shipped and knowing what is actually executing in production. * Active use of AI-assisted development tools in your own engineering work (such as Claude Code, GitHub Copilot, or equivalent); this role is designed around that way of working. * Early or growing experience in AI and LLM security — including prompt injection, data exfiltration, model API security, or agentic system controls — and a clear appetite to develop expertise in this space. * The ability to communicate complex technical findings clearly and concisely to senior stakeholders who will translate them into policy and governance decisions. Nice to have: * Familiarity with tools such as CrowdStrike, Aikido, Bold Security, Nightfall, Zscaler, or Lakera Guard. * Experience with MCP (Model Context Protocol), agentic frameworks, or AI platform administration. * Background working in private equity, financial services, or other environments where non-public information is a primary asset requiring protection. * Experience measuring and optimising the operational cost of security controls. * Comfort deploying and working with local open-source LLMs for automation use cases. HOW WE THINK ABOUT THIS ROLE Application security and AI security share a common threat model — data exfiltration, supply chain compromise, and the boundary between trusted and untrusted code. AI connectors that interact with hosted services sit squarely in both domains. Splitting them into separate roles at a five-person team would create seams in exactly the places attackers exploit. The role is also shaped by a bet on AI-augmented engineering. An engineer with good tooling, a real token budget, and the discipline to automate before they assess can cover ground that would have required a larger team not long ago. We've designed the headcount around that — not to cut corners, but because the best security engineering now looks like one person building excellent guardrails with AI, not several people reviewing things by hand. WHAT WE OFFER At EQT, you will work in an environment that combines high impact with high trust, contributing to security challenges that matter at a global scale. You will help shape practices in areas that are rapidly evolving across the industry — AI security, software supply chain security, and modern application platforms — with direct influence on governance decisions and engineering standards. We offer meaningful and complex work with global reach, close collaboration with experienced colleagues across security, engineering, and technology, and genuine exposure to emerging AI technologies and cloud-native platforms. EQT has a culture that values curiosity, ownership, and continuous learning, with real opportunities for professional development in a fast-moving environment. COMPENSATION & BENEFITS NOTICE We offer a competitive total rewards package including base salary, determined based on the role, experience, skill set, and location. Eligible employees may also receive discretionary incentive compensation, awarded in recognition of individual performance and company results. EQT provides a comprehensive benefits offering designed to support employee wellbeing, development, and work-life balance. Benefits include paid time off, parental leave, wellbeing and wellness support, flexible working arrangements, and learning and development opportunities. Benefits are effective from the first day of employment and may vary by location and role. Inclusion at EQT Our vision for EQT employees is to build high performing & engaged teams. Our competitive edge comes from fostering an environment where every individual feels valued, empowered, and motivated to drive business impact. Our commitment to inclusion is not just about fairness; We understand and believe that being a great place to work drives the best performance.At EQT, inclusion is a business imperative and it's embedded into our talent strategy, decision-making, and culture to ensure that every individual and team operates at their full potential. By doing so, we unlock better collaboration, stronger innovation, and superior investment outcomes. About EQT EQT is a purpose-driven global investment organization focused on active ownership strategies. With a Nordic heritage and a global mindset, EQT has a track record of over three decades of developing companies across multiple geographies, sectors and strategies. EQT has investment strategies covering all phases of a business’ development, from start-up to maturity. EQT has EUR 270 billion in total assets under management (EUR 141 billion in fee-generating assets under management), within two business segments – Private Capital and Real Assets. With its roots in the Wallenberg family’s entrepreneurial mindset and philosophy of long-term ownership, EQT is guided by a set of strong values and a distinct corporate culture. EQT manages and advises funds and vehicles that invest across the world with the mission to future-proof companies, generate attractive returns and make a positive impact with everything EQT does. EQT has offices in more than 25 countries across Europe, Asia and the Americas and has more than 1,900 employees. More info: www.eqtgroup.com Follow EQT on LinkedIn, X, YouTube and Instagram
Join our global force of 400+ innovators, blending the latest in tech with the greatest in soundtracking, from our Stockholm HQ to offices in London, New York, Los Angeles, Berlin, Paris, Oslo, and Seoul. We’re an industry leader with a startup mentality. We take what we do seriously, but we don’t take ourselves too seriously. Creating and collaborating to transform the sound of streaming, content, and culture. Come join us, and let the world feel your work. As a Security Engineer at Epidemic Sound, you will help keep the company safe across three connected surfaces: the products our customers use, the platform our engineers build on, and the systems our employees rely on every day. This is a broad, generalist role where your work directly shapes how an industry-leading company with a startup mentality manages risk and builds securely at scale. Building security automations and custom AI agents is a normal part of how the team operates, and you will be expected to do the same. You will sit within the Business Tech Division and report to the Head of Security, working closely with engineers, SRE, IT, Legal, and People teams across the organisation. YOUR KEY RESPONSIBILITIES INCLUDE * Own the vulnerability management programme across our products, cloud, and corporate estate: discovery, prioritisation, remediation tracking, and reporting. * Consolidate findings across our detection stack into a single risk picture. * Partner with software engineers to grow the Secure Software Development Lifecycle, including code reviews, threat models, and pre-ship security input. * Harden the GCP estate, Kubernetes platform, and CI/CD systems our engineers depend on. * Run vendor security reviews and respond to enterprise customer security questionnaires. * Operate and tune the Elastic SIEM and broader detection stack, building new detections as the threat picture evolves. * Respond to security incidents including on-call, and run training exercises to keep the team ready. * Build and run security agents and automations that other engineers and the wider business rely on, treating them as production-grade software. * Evaluate AI models and frameworks against security standards. REQUIREMENTS * Around five years in security engineering, with depth in at least one of application security, infrastructure security, enterprise security, or vulnerability management, and solid breadth across the others. * Hands-on experience running or contributing to a vulnerability management programme, including prioritisation, SLA setting, remediation tracking, and reporting. * Working knowledge of SCA/SAST tooling, Internal Developer Portals, and SIEM; we use Snyk, Port, and Elastic. * Working knowledge of the security features of the major public cloud providers, with GCP preferred. * Comfort with Kubernetes, Docker, or other container architectures. * Confident with at least one programming or scripting language such as Python, Go, or Bash. * Solid experience with Git, GitHub Actions, and Terraform. * Active, daily use of AI and agentic tools, with concrete examples of agents you have built and outputs you have shipped. * Experience with vendor security questionnaires. * Familiarity with common security frameworks such as PCI DSS and NIST. IT WOULD ALSO BE MUSIC TO OUR EARS IF YOU HAVE * Penetration testing background or OWASP Top 10 fluency. * Experience with CI/CD security hardening at scale. * A track record of building security tools other engineers want to use. * Experience reporting vulnerability management and security posture metrics to leadership. * Familiarity with social engineering attacks, especially phishing, and the controls that reduce them. Equal opportunity employer We believe that bringing people together from different backgrounds, experiences and perspectives makes for a healthy workplace, a more successful business and a better world. We value diversity and encourage everyone to come and soundtrack the world with us. Application Ready to make the world feel your work? Please apply, in English.
Summary of the Role: As Security Research Lead at Maze, your research directly shapes our products and how our AI understands real risk. This is a unique opportunity to join a well-funded Series A startup building at the intersection of generative AI and cybersecurity, leading the research function that makes our products sharper than anything else on the market — and gives Maze a credible technical voice in the security community. You'll set the bar for our vulnerability research: defining the methodologies that separate critical risk from noise, validating and contextualising the threats our AI surfaces, and feeding that expertise straight into product and engineering to improve how we detect, prioritise, and remediate. You'll work hand-in-hand with our AI/ML, product, and engineering teams — close to the roadmap and the code, not off to one side — turning what you find into capabilities that crush the competition. Alongside that, you'll amplify the work externally: surfacing novel vulnerabilities and building research narratives that earn real reach, giving Maze technical credibility with practitioners and customers. This role is perfect for a security researcher with real depth in cloud and application security who is ready to step up: someone who wants their research to ship as product, can lead a small research team, and can tell a story that lands with a technical audience. The ideal candidate has done this inside another security vendor and wants to build both great products and a research brand from a strong foundation. What you'll work on: * Make Our Products Brilliant: Feed research directly into product and engineering — work close to the roadmap and the codebase to sharpen how we detect, prioritise, and remediate, building capabilities that outclass the competition * Shape How Our AI Understands Risk: Translate deep threat research into the labels, signals, and product feedback that train our models to prioritise vulnerabilities like a seasoned researcher * Lead Our Security Research Function: Set the direction, standards, and methodologies for how Maze researches, validates, and prioritises cloud and application security threats, scaling a small team of researchers as we grow * Find Novel Vulnerabilities That Get Reach: Surface original research and build narratives — blog posts, technical talks, podcasts, video, conference presentations — that earn real reach and give Maze technical credibility with the security community * Build Authoritative Technical Intelligence: Produce detailed research on exploitation techniques, attack vectors, and remediation across cloud infrastructure and application security, enriched with CVE, advisory, and threat-intel sources * Set the Standard for Research Quality: Establish the frameworks and review processes that keep our vulnerability assessment consistent, defensible, and ahead of the threat landscape * Grow the Bench: Mentor and develop researchers, raising the technical bar of the team and creating a research culture others want to join What You Need to Be Successful: * Proven Security Research Depth:** 6+ years in hands-on security research, with a strong track record investigating complex vulnerabilities, building proof-of-concepts, and validating real-world threats * Cloud & Application Security Expertise: Deep knowledge of cloud (AWS) and application security vulnerabilities, attack vectors, and how they actually get exploited at scale * Research That Ships as Product: A track record of turning research into product and engineering outcomes — working closely with eng, product, and ML teams to translate findings into shipped capabilities, not reports that sit on a shelf * A Public Track Record: Demonstrated ability to be the voice of security research externally — published research, conference talks, well-received technical content, or a recognised presence in the community * Vendor-Grade Perspective: Direct experience inside a security tooling or research organisation, with a view on what good research operations look like and how to build credibility in market * Technical Investigation Skills: Strong coding and scripting (Python, Go, or similar) for automating research, building validation tooling, and creating PoCs * Communication That Lands: Ability to translate complex security research for technical practitioners, customers, and internal AI/ML and product teams without losing rigour * Leadership Instinct: Experience leading or mentoring researchers, setting standards, and owning a domain end-to-end in a fast-moving environment * Startup Readiness: Comfortable operating with ambiguity and limited structure, prioritising ruthlessly, and building the function as you run it * Nice to haves: * Experience with AI/ML security or working with AI-generated security findings * An established personal brand or following in the security research community * Open-source contributions to security tools or research * Experience setting up or scaling a research/labeling operation * Industry certifications (OSCP, AWS Security, CISSP, etc.) Why Join Us: * Ambitious Challenge: We're using generative AI (LLMs and agents) to solve some of the most pressing challenges in cloud and application security. You'll define how AI understands and prioritises vulnerabilities — and how the market talks about it. * Expert Team: We are a team of hands-on leaders with experience in Big Tech and Scale-ups, who have been part of the leadership teams behind multiple acquisitions and an IPO. * Build Products and a Research Brand: A rare chance to build a security research function from a strong foundation where your research ships as product — directly shaping what we build and how Maze is seen in the security community. * Impactful Work: Cybersecurity is a force for good. Your research will directly improve how thousands of organisations understand and respond to threats, scaling expert security knowledge through AI. * Build an AI-native Company: Join early enough to shape everything from the ground up, with significant equity upside and the room to grow into senior security leadership.
Summary of the Role: As Security Engineer (Internal) at Maze, you'll own how we secure ourselves — our cloud, our applications, and the way our engineers build. This is a unique opportunity to join a well-funded Series A startup building at the intersection of generative AI and cybersecurity, establishing the internal security foundation that lets a three-product company keep moving fast as it scales. You'll take hands-on ownership of cloud infrastructure security, application security, security tooling, and the compliance work that unlocks enterprise deals. We're deliberately looking for a strong generalist rather than a narrow specialist: someone who can harden our AWS environment and identity model, get into the weeds on application security, and run a pragmatic compliance program — and who knows when a control is worth the friction and when it isn't. Your success will be measured by the robustness of our security posture, our readiness for enterprise customer requirements, and your ability to make secure the default path for engineering rather than a blocker. This role is perfect for a pragmatic, broad security engineer who has built and run security at a startup, thrives with autonomy, and wants to own a domain end-to-end. You'll be our founding internal security hire — but not a lone wolf for long: this is the first role in a function we expect to grow, and as we scale we'll add to the team and bring in dedicated security leadership. You'll set the foundations the rest of that team is built on, and have a clear runway to grow alongside it. YOUR CONTRIBUTIONS TO OUR JOURNEY: * Harden Our Cloud Infrastructure: Secure our AWS environment by design — identity and access management, hardening, network and infrastructure-as-code controls (Terraform) — closing real risk rather than chasing checkboxes * Own Application Security: Embed application security into how we build, from secure-by-default patterns and code review guidance to triaging and driving down vulnerabilities across our own products and services * Build Security Tooling and Monitoring: Stand up the monitoring, logging, and alerting that gives us visibility across infrastructure and applications, and serve as our first line of defence * Run Compliance Pragmatically: Lead readiness for SOC2, ISO27001, and similar frameworks — building the controls, documentation, and evidence that support enterprise sales without drowning the team in process * Establish Security Policies That Enable: Create practical security policies and procedures that keep standards high while letting the team move quickly — no security theatre * Automate Security Operations: Build security automation and tooling in code, using AI-assisted workflows to ship faster while keeping quality high * Manage Vendor and Supply-Chain Security: Assess third-party vendors and tools so our supply chain meets enterprise expectations * Enable Incident Response: Develop incident response plans and runbooks, and establish clear processes for detecting, responding to, and recovering from security incidents WHAT YOU NEED TO BE SUCCESSFUL: * Broad, Hands-On Security Engineering: 5+ years building and running security, with genuine breadth across cloud security and application security rather than depth in only one — comfortable being the person who covers the whole surface area * AWS Security Expertise: Deep, hands-on knowledge of AWS security — IAM, hardening, and AWS-native security tooling — with the judgement to prioritise what matters * Application Security Capability: Real experience finding and fixing application-layer vulnerabilities, and embedding secure development practices into engineering workflows * Infrastructure as Code Proficiency: Strong experience managing security controls programmatically with Terraform, building secure, scalable infrastructure through code * Coding and Scripting Skills: Proficiency in Python, Bash, or similar for security automation, custom tooling, and integrating security into development workflows * Compliance and GRC Know-How: Practical experience translating SOC2, ISO27001, or similar requirements into technical controls — without letting process become the product * Pragmatic Security Mindset: A track record of balancing security rigour with business velocity, implementing controls that enable engineering rather than block it * Startup Self-Direction: Proven ability to operate autonomously as an early security hire, prioritise ruthlessly, and build without extensive oversight — and to thrive in the ambiguity of an early-stage company * Foundation-Setter: Mindset to build security in a way others can build on as the team grows — clear documentation, repeatable processes, and standards a future team and security leadership inherit cleanly * Nice to haves: * Experience building security programs at early-stage startups (seed through Series B) * Background in DevOps or SRE that grew into security engineering * Familiarity with container security (Docker, Kubernetes) * Experience at a cybersecurity product company * A bias toward building vs buying security tooling under startup constraints * AI-assisted security workflow experience WHY JOIN US: * Ambitious Challenge: We're building at the intersection of generative AI (LLMs and agents) and cybersecurity — and you'll secure the company doing it, across cloud and application security. * Build Security from Zero: Own the internal security function from day one, establishing the architecture, tooling, and practices that scale Maze through hypergrowth — then help grow the team and function around you as we scale. * Expert Team: Work alongside a CTO and engineering team with deep experience in AI and cybersecurity — hands-on leaders who have been part of multiple acquisitions and an IPO — giving you strong technical partnership while you own security. * Impactful Work: Cybersecurity is a force for good. Your work directly enables AI-powered security solutions that protect organisations worldwide — making security an enabler of innovation, not a blocker. * Build an AI-native Company: Join early enough to design everything from the ground up, with significant equity upside and a clear path to grow as our security organisation matures.
Are you passionate about ethical hacking and eager to develop the skills that keep modern applications safe? Do you dream of finding the weaknesses others miss — and helping organisations fix them before attackers do? If so, we have the perfect opportunity for you! ABOUT THE INTERNSHIP Our Application Security & Penetration Testing Internship is designed for ambitious individuals who want to explore the exciting world of offensive security and gain hands-on experience. This program offers the chance to work on real client engagements, learn industry-standard testing methodologies, and collaborate with experienced security consultants. WHAT YOU'LL LEARN As an intern, you will: Test modern web applications, APIs and mobile apps for real security weaknesses. Learn how professional penetration tests are planned, executed and reported. Turn technical findings into clear, practical advice that clients can act on. Gain hands-on experience with the tools and methodologies used on live engagements. This internship is designed for individuals eager to dive deep into application security and apply their curiosity to problems that matter. Every vulnerability you help find and every report you help write makes a real system secure and safer for the people who depend on it. WHY JOIN US? Hands-on experience with state-of-the-art security tools and technologies. Guidance and mentorship from seasoned penetration testers. Opportunity to work on real-world client engagements that make an impact. A collaborative and supportive environment where questions are always welcome. WHO WE'RE LOOKING FOR We welcome interns who: Have a strong interest in cybersecurity and ethical hacking. Have a solid grasp of web technologies, networking, and Linux or Windows OS. You don't need to be an expert, but we expect you to be very comfortable working in these environments. Good knowledge of mobile app development (iOS/Android) and APIs. Good knowledge of any major cloud technologies/platforms (AWS/Azure/GCP). Have some awareness of common application vulnerabilities, such as the OWASP Top 10. Exposure to web application penetration testing, API security testing, or mobile application security through academic projects or self-learning. Have tried their hand at CTFs or practice labs such as Hack The Box, TryHackMe or PortSwigger Web Security Academy, or personal projects or home labs. Good programming/scripting experience, for example, Python or Bash, is a bonus. Strong analytical and problem-solving skills with the ability to think creatively, eager to learn and solve complex problems. Are ready to contribute ideas and collaborate with a dynamic team. Approach security work with care, discretion and a strong ethical mindset. HOW TO APPLY Send your resume and a cover letter explaining why you're excited about penetration testing and why you are an ideal candidate for the role. It is recommended to include any personal security projects, CTF write-ups or lab platform profiles you have worked on. Applications are open until 31st August 2026. Don't miss this chance to kickstart your career in offensive security! Join us, and let's build a safer digital world together! Please note: This is an unpaid, full-time, 6-month onsite internship starting September 2026 at our offices in Lindholmen, Gothenburg.
WPP is the trusted growth partner for the world’s leading brands. We unite cutting-edge media intelligence and data solutions, world-class creativity, next-generation production, transformative enterprise solutions and expert strategic counsel in a single company – powered by exceptional talent and our agentic marketing platform, WPP Open, to help our clients navigate change, capture opportunity and deliver transformational growth. We work with the world's most valuable brands and have global reach across 100+ markets, with deep local expertise. Our people are the key to our success. We're committed to fostering a culture of creativity, belonging and continuous learning, attracting and developing the brightest talent, and providing exciting career opportunities that help our people grow. For more information, visit WPP.com. * Department: Data & Technology Solutions (DTS) * Reports To: SVP Security and Compliance * Location: [London/Hybrid 2 days a week in office] * Position Type: Full-Time ROLE OVERVIEW The Product, Application and Offensive Security Lead is responsible for embedding security directly into the design, development, testing, and operation of DTS products and platforms. This is a hands-on security engineering role. The role requires someone who can work directly with product and engineering teams, review designs, assess APIs, run threat models, test systems, coordinate penetration testing, identify vulnerabilities, and help teams remediate issues. The role ensures DTS products, APIs, data collaboration capabilities, AI-enabled workflows, and client-facing services are designed, built, and tested securely. It also owns the practical offensive security and adversarial assurance activity needed to test DTS products from an attacker’s perspective. The Product, Application and Offensive Security Lead will work closely with Product, Engineering, Architecture, Infrastructure, Security Operations, Privacy, Cloud and Platform Security, and the ISMS and Risk Officer to ensure security issues are identified early, fixed effectively, and tracked through governance where required. ---------------------------------------------------------------------------------------------------------------------------------- KEY RESPONSIBILITIES 1. HANDS-ON PRODUCT AND APPLICATION SECURITY Provide hands-on security support across DTS products and engineering teams. This includes: * Reviewing product designs, technical designs, APIs, services, and integrations. * Identifying security weaknesses in applications, workflows, and data flows. * Advising engineering teams on secure implementation. * Supporting secure design decisions during product discovery and delivery. * Helping teams resolve security issues pragmatically without creating unnecessary delivery friction. 2. SECURE SOFTWARE DEVELOPMENT LIFECYCLE (SDLC) Embed security into the software development lifecycle across DTS. This includes: * Defining and applying secure engineering standards. * Supporting secure coding practices. * Reviewing CI/CD security controls. * Supporting SAST, DAST, SCA, secrets scanning, dependency scanning, and container scanning. * Helping teams triage, prioritise, and remediate security findings. * Working with engineering teams to make security checks practical and repeatable. 3. THREAT MODELLING AND SECURITY DESIGN REVIEWS Run threat modelling and security design reviews for new and changed capabilities. This includes: * Facilitating threat modelling sessions with engineering and product teams. * Reviewing authentication and authorization designs. * Assessing API exposure, data flows, trust boundaries, and abuse cases. * Identifying risks around tenant isolation, privilege escalation, data leakage, and misuse. * Documenting key findings, recommendations, and residual risks. 4. OFFENSIVE SECURITY AND ADVERSARIAL TESTING Carry out and coordinate offensive security testing across DTS products and platforms. This includes: * Performing hands-on security testing of products, APIs, and workflows. * Coordinating external penetration tests. * Supporting red team and purple team exercises where required. * Testing abuse cases and attacker paths. * Testing access control, authentication, authorization, and data leakage risks. * Validating remediation of security findings. * Feeding material risks into the ISMS and Risk Officer for tracking. 5. API, INTEGRATION AND DATA PRODUCT SECURITY Provide security assurance for APIs, integrations, and data products. This includes: * Reviewing externally exposed APIs and partner integrations. * Assessing rate limiting, authorization, tenant isolation, logging, abuse prevention, and data leakage controls. * Supporting secure integration between InfoSum, Open Intelligence, Resolve, WPP Open, and third-party platforms. * Reviewing data product workflows for misuse, excessive access, or unintended exposure. * Working with Privacy Engineering on privacy-sensitive APIs, algorithms, and outputs. 6. AI AND AGENTIC SECURITY TESTING Provide hands-on security review and adversarial testing for AI-enabled and agentic capabilities. This includes: * Testing prompt injection, tool misuse, data leakage, and excessive agency. * Reviewing how agents access APIs, data, tools, and workflows. * Testing whether agent permissions can be bypassed or escalated. * Assessing action boundaries and human approval points. * Working with Identity, AI, and Data Access Governance to validate agent access models. * Documenting AI and agentic security risks and remediation actions. 7. VULNERABILITY TRIAGE AND REMEDIATION SUPPORT Help teams understand, prioritise, and fix security vulnerabilities. This includes: * Reviewing vulnerability findings from scans, penetration tests, code reviews, cloud tools, and external reports. * Prioritising findings based on exploitability, exposure, data sensitivity, and business impact. * Working directly with engineers to define remediation options. * Validating that fixes are effective. * Supporting exception and risk acceptance decisions where remediation is delayed. * Ensuring significant issues are visible through the DTS risk process. 8. ENGINEERING ENABLEMENT AND SECURITY COACHING Act as a practical security partner to engineering teams. This includes: * Providing secure implementation guidance. * Creating lightweight security patterns and examples. * Coaching engineers on common application, API, and AI security risks. * Helping teams understand the “why” behind security requirements. * Supporting a culture where security is part of product quality, not a separate approval gate. ---------------------------------------------------------------------------------------------------------------------------------- KEY ACCOUNTABILITIES The Product, Application and Offensive Security Lead will be accountable for: * Hands-on application and product security support across DTS. * Secure SDLC guidance and practical adoption. * Threat modelling and security design reviews. * API, integration, and data product security reviews. * Offensive security and adversarial testing activity. * AI and agentic security testing. * Vulnerability triage, remediation guidance, and fix validation. * Coordination with ISMS/Risk to ensure material risks and exceptions are tracked. * Helping engineering teams build secure systems without unnecessary delivery drag. ---------------------------------------------------------------------------------------------------------------------------------- SKILLS AND EXPERIENCE The successful candidate will have: * Strong hands-on experience in application security, product security, offensive security, security engineering, or penetration testing. * Good understanding of modern software engineering, APIs, SaaS platforms, distributed systems, and cloud-native applications. * Experience with threat modelling and secure design reviews. * Practical knowledge of common application and API security risks, including authentication, authorization, tenant isolation, injection, data leakage, privilege escalation, and supply chain risk. * Experience using security testing tools and techniques across web applications, APIs, cloud services, and CI/CD pipelines. * Familiarity with SAST, DAST, SCA, secrets scanning, dependency scanning, and vulnerability management workflows. * Experience working directly with engineers to remediate findings. * Understanding of AI and agentic security risks would be highly valuable. * Ability to communicate clearly with engineering, product, architecture, security, and leadership stakeholders. * A pragmatic, delivery-aware approach to security. ---------------------------------------------------------------------------------------------------------------------------------- LEADERSHIP EXPECTATIONS The Product, Application and Offensive Security Lead is expected to: * Be hands-on and technically credible with engineering teams. * Act as a trusted security partner, not just a reviewer or approver. * Challenge insecure designs constructively. * Help teams find practical ways to reduce risk. * Prioritise issues based on real-world exploitability and business impact. * Work across multiple DTS product areas without becoming a delivery bottleneck. * Escalate material risks clearly through the appropriate governance routes. * Promote secure engineering habits through practical guidance and example. ---------------------------------------------------------------------------------------------------------------------------------- SUCCESS MEASURES Success in the role will be measured by: * Security being embedded earlier in product and engineering delivery. * Reduction in high-risk application, API, and product vulnerabilities. * Regular threat modelling and security reviews for critical DTS capabilities. * Effective offensive and adversarial testing of products, APIs, and workflows. * Faster remediation of penetration test and security testing findings. * Improved security assurance for AI and agentic workflows. * Engineering teams receiving practical, actionable security guidance. * Material security risks being surfaced and tracked through the DTS risk process. * Security being viewed by engineering teams as an enabler of trusted delivery rather than a blocker. You're open: We are inclusive and collaborative; we encourage the free exchange of ideas; we respect and celebrate diverse views. We are open-minded: to new ideas, new partnerships, new ways of working. You're optimistic: We believe in the power of creativity, technology and talent to create brighter futures or our people, our clients and our communities. We approach all that we do with conviction: to try the new and to seek the unexpected. You're extraordinary: we are stronger together: through collaboration we achieve the amazing. We are creative leaders and pioneers of our industry; we provide extraordinary every day. What we'll give you: Passionate, inspired people – We aim to create a culture in which people can do extraordinary work. Scale and opportunity – We offer the opportunity to create, influence and complete projects at a scale that is unparalleled in the industry. Challenging and stimulating work – Unique work and the opportunity to join a group of creative problem solvers. Are you up for the challenge? #LI-Hybrid We believe the best work happens when we're together, fostering creativity, collaboration, and connection. That's why we’ve adopted a hybrid approach, with teams in the office around four days a week. If you require accommodations or flexibility, please discuss this with the hiring team during the interview process. WPP is an equal opportunity employer and considers applicants for all positions without discrimination or regard to particular characteristics. We are committed to fostering a culture of respect in which everyone feels they belong and has the same opportunities to progress in their careers. PLEASE READ OUR PRIVACY NOTICE (HTTPS://WWW.WPP.COM/EN/CAREERS/WPP-PRIVACY-POLICY-FOR-RECRUITMENT) FOR MORE INFORMATION ON HOW WE PROCESS THE INFORMATION YOU PROVIDE.
HiQ i Göteborg växer inom cybersäkerhet och vi söker dig som vill hjälpa våra kunder att göra digitala produkter säkrare. Vi har ett starkt team i Stockholm och teamet i Göteborg är under uppbyggnad. Det är där du kommer in! Som lead inom produktsäkerhet kommer du att stötta i rekrytering samt utveckla affären tillsammans med lokala säljare och konsultchefer. Samtidigt kommer du som konsult själv att hjälpa våra kunder att bygga in säkerhet i sina produkter och system från början. Du jobbar nära utvecklingsteam, gör riskanalyser och threat modeling, tar fram säkerhetsarkitektur och hjälper kunderna att tolka regelverk och standarder i praktiken. Vi söker dig som: * har minst 5 års erfarenhet inom t.ex. Cybersecurity, Application Security, OT/Embedded Security eller System-/Produktsäkerhet. * har affärsförståelse och kunskap om marknaden och du har gärna tidigare erfarenhet från konsultbranschen. * har goda kunskaper inom produktutveckling och utveckling av inbyggd programvara tex i C/C++ eller modellbaserad utveckling. * har vana att arbeta nära utveckling eller produktutveckling. * har erfarenhet och/eller ett intresse av ledarskap och vill vara med på resan att bygga upp teamet i Göteborg! * talar och skriver svenska obehindrat. Meriterande: * Goda kunskaper inom Embedded systems. * Programmering i python eller java. * IoT-säkerhet, system security eller ICS/industriella system. * Erfarenhet av kryptografi och/eller säkra kommunikationsprotokoll. * Erfarenhet av någon cybersäkerhetsstandard eller ramverk för säker utveckling. Som person gillar du att förstå hur saker fungerar “under huven”, trivs i samarbeten och är trygg i dialogen både med utvecklare och beslutsfattare. Du delar gärna med dig av din kunskap och är nyfiken på att lära av andra. Det här är en fantastisk möjlighet att vara med och bygga upp en cybersäkerhetsverksamhet på ett av Sveriges mest tekniktunga och spännande konsultbolag! Om HiQ: Att vara HiQare är både utmanande och omväxlande. Vi är alla konsulter vilket innebär att vi i våra projekt hos kund eller in-house får prova nytt och bli exponerad för nya branscher, arbetsplatser och tech-stacks. Variationen är stor och utvecklingstakten snabb. Hos oss får du bidra och bemästra dina starkaste kompetenser, men även utforska och utveckla nya. Med rätt attityd och kompetens bidrar du med värde både i ditt uppdrag och till dina kollegor på HiQ. Hos oss hittar du allt från marknadens vassaste utvecklare, testare och hackers, till projektledare, agila coacher och designers. Även om våra kompetenser är många och olika så har vi mycket gemensamt – vi tycker om att driva utveckling, att förbättra och förenkla... och framför allt – att ha kul på vägen! HiQ är kulturdrivet, inte regelstyrt, och det gör att man kan vara sig själv till 100%. En följd av det är att man som HiQ:are tar sitt jobb seriöst, men inte alltid sig själva :) Det som genomsyrar oss all är viljan och ambitionen att bidra till att göra världen lite bättre med hjälp av teknik och kommunikationslösningar som förenklar människors liv. På riktigt. Vi ser fram emot din ansökan<3
Är du en utvecklare med passion för att bygga säkra lösningar? Säkerhet har aldrig varit viktigare för oss och våra kunder! Nu söker vi dig som tillsammans med oss vill ta på sig ledartröjan i säker systemutveckling! Säkerhet måste byggas från grunden och vi har ambitionen att leda arbetet från start till mål! Vi tror följande beskrivning passar in på dig: * Förstår vikten av att beakta risk tidigt i utvecklingsprocessen genom att delta i eller leda workshops i hotmodellering * Har kunskap om tekniska verktyg för automatisering och säkerhetstestning, tex. Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST) * Har kunskap och praktisk erfarenhet att använda OWASP som guide och ramverk för säker utveckling * Har erfarenhet eller intresse av penetrationstestning och sårbarhetsskanning * Älskar att dela med dig av din kunskap till övriga i teamet * Kommunicerar flytande i svenska och engelska i tal och skrift HiQ då? Vi gillar att bygga saker. Man kan skriva mycket om att förbättra världen och saker som att “forma framtiden genom skapandet av produkter som engagerar, förundrar och som användare blir förälskade i"… men i slutändan handlar det om en sak: Det är svårt att slå känslan av att skapa något som gör nytta, som gör någons vardag bättre än vad den var igår. Hos oss kommer du ha möjlighet att bygga saker för både stora och små kunder och projekt. Så oavsett om du drömmer om att vara med och skapa stora projekt som når en bred publik, eller om du brinner för att bygga små specialiserade lösningar så kommer du hitta sådana möjligheter hos oss. Dessutom så är det viktigt för oss att “Bygga företaget du alltid velat jobba på”. HiQ har en väldigt flexibel företagskultur, även mellan våra olika kontor. Vi är en produkt av individerna som jobbar här och är stolta över att vara en arbetsplats där man känner att man kan vara sig själv.
At Securitas, Digital Security (Cyber Security) is focused on protecting our systems, applications, data, and services while enabling secure and reliable business operations. All countries within our scope are either certified against ISO/IEC 27001 or actively implementing it, ensuring a consistent and structured approach to information security management across the organisation. Your Role – Cluster Digital Security Officer (Cluster North) As a Cluster Digital Security Officer, you will support the technical execution, coordination, and oversight of Digital Security across Cluster North (Sweden, Norway, Finland, Denmark, the UK, and Ireland), while also contributing to Group/ Division-level security priorities. This is a hands-on, operational role, delivered as part of a wider Digital Security organization. You will work closely with different Division/Group IT teams, Digital Security Operations, Digital Security, and Country IT teams, operating in a collaborative, multi-country and multi-layer (Cluster–Division–Group) environment. Key Responsibilities Security Coordination & Team Collaboration (Cluster & Division) Coordinate Digital Security activities across the Cluster and support execution of the security roadmap aligned with Division priorities, including application security initiatives Ensure consistent implementation of security controls, baselines, and services across infrastructure and applications Work closely with GITS, Application teams, Domain and other IT teams to ensure alignment and effective execution Contribute actively to the Digital Security community, including sharing practices related to application and platform security Provide regular, transparent, and data-driven reporting on risk posture, control effectiveness, and remediation progress Technical Security Oversight (Infrastructure & Applications) Monitor and assess the security posture of platforms, infrastructure, and applications (on-prem and cloud) Oversee key control areas including vulnerability management, patching, identity and access management, endpoint security, and application security Support secure practices across the application lifecycle (SDLC), including awareness of secure design and common vulnerabilities (e.g. OWASP Top 10) Ensure effective logging, monitoring, and incident detection capabilities are in place across infrastructure and applications Track and assess third-party and supplier risks, including risks related to applications and integrations Risk, Compliance & Assurance Identify and track gaps against security policies, standards, and mandates, including application security requirements Support/execute risk assessments, internal and external audits, and customer assurance activities across Cluster environments Drive and follow up on risk remediation plans, ensuring clear ownership and execution across technical teams Securitas Alarm Monitoring Centers (SOC) Security In addition to Cluster responsibilities, you will contribute to Division-level security of Securitas Alarm Monitoring Centers (SOCs) supporting the Domain Digital Security Officer SOC and RVS, which are among the most critical environments within Securitas. This includes: Supporting and overseeing the security posture of SOC environments, including underlying infrastructure and supporting applications Ensuring implementation of enhanced technical controls (e.g. network segmentation, strong access control, privileged access management, monitoring, and secure application access) Monitoring the availability, integrity, and protection of SOC systems, applications, and data flows Supporting incident detection, response readiness, and recovery capabilities for SOC-related platforms and applications Working closely with Infrastructure, Application, SOC and other IT teams to reduce attack surface and strengthen resilience of SOC environments Ideal Candidate Profile We are looking for a candidate who combines technical understanding across infrastructure and applications, structured execution, and strong collaboration skills. Certifications (mandatory) CISSP or CISM or equivalent Experience & Knowledge 5–7 years of experience in Cyber Security, Information Security or Application Security Minimum of 2 years of experience in IT operations Good understanding of security domains (IAM, endpoint security, vulnerability management, logging/monitoring, network security, and application security) Solid understanding of application security principles, including secure development practices, common vulnerabilities (e.g. OWASP Top 10), and risks in application architecture and integrations Good understanding of ISO 27001 standard Experience with risk management, audits, or compliance activities Understanding of infrastructure environments (networks, servers, cloud platforms) and their interaction with applications Technical & Analytical Skills Ability to assess security posture across infrastructure and applications and identify control gaps Comfortable working with security metrics, reports, and risk data Understanding of incident detection and response processes, including those impacting applications Ability to translate security requirements into practical and implementable actions across infrastructure and application teams
At HiQ, every challenge is an invitation to explore new possibilities. We’re looking for someone who thrives on the thrill of discovery, who sees every system as a puzzle waiting to be solved, and who finds energy in the pursuit of safer, smarter digital solutions. As part of our Pentest team, you’ll be at the heart of our mission to build secure applications and environments for some of the most exciting organizations in the Nordics. Your days will be filled with hands-on penetration testing, creative problem-solving, and the freedom to dive deep into the latest tools and techniques. Whether you’re orchestrating a Red Team engagement or probing the intricacies of cloud security, you’ll have the autonomy to shape your own approach, while always knowing that a team of passionate experts has your back. You’ll work with Burp Suite, Nmap, Wireshark, and a host of other tools, sometimes in the cloud, sometimes on-prem, always at the cutting edge. Your experience with Active Directory and scripting will come to life as you navigate complex environments, uncover vulnerabilities, and help our clients see their systems through a new lens. If you’ve cracked hashes, explored mobile app security, or sharpened your skills in CTFs, you’ll find plenty of opportunities to push your expertise even further. WHAT YOU BRING * At least 5 years of practical experience in penetration testing or Red Team operations * Deep familiarity with industry-standard tools such as Burp Suite, Nmap, and Wireshark * Strong background in assessing and securing web applications * Proven experience performing Active Directory and broader network security assessments * Understanding of modern cloud platforms and architectures * Scripting skills that enable you to automate workflows and develop new solutions * Relevant education and/or certifications (e.g., OSCP, OSCE, AWS/Azure Security) * Excellent communication skills, with the ability to clearly document and articulate vulnerabilities and recommendations * Swedish citizenship, as HiQ carries out security-classified assignments that may require it BONUS SKILLS * Experience with hash cracking * Knowledge of mobile application security * Knowledge in cloud security * Networking know-how * Capture the Flag participation * Insights into computer forensics Here, learning is woven into the fabric of every project. Whether you’re pursuing new certifications, experimenting with the latest exploits, or sharing insights with colleagues, you’ll find endless room to grow. We celebrate curiosity and initiative, if you spot an opportunity to make something better, you’ll have the freedom and support to make it happen. You’ll be trusted to run penetration tests independently, but you’ll never be alone. Collaboration is second nature here: ideas bounce, knowledge flows, and everyone’s voice matters. You’ll document your findings with clarity, communicate risks with empathy, and help guide clients toward stronger, more resilient solutions. If you’re ready to join a team where your passion for security is matched only by your drive to learn and create, we’d love to meet you. Ready to take the next step? Apply now and let’s build something extraordinary together.
We are now looking for a Senior IT Security Architect who wants to play a key role in helping our customers build resilient, modern, and business-aligned security architectures. With us, you will work at the forefront of cybersecurity alongside some of the industry’s leading specialists — in a company with a strong expert profile, a solid culture, and international reach. This role is for someone highly senior who understands that good security architecture is not only about controls and technology, but about creating customer value: reducing risk, enabling transformation, supporting compliance, improving decision-making, and building solutions that remain effective over time. You are expected to take ownership of the bigger picture, challenge stakeholders at the right level, build trust in executive-level discussions, and at the same time possess sufficient technical depth to make sound architectural decisions. Example of responsibilities: Lead and drive security architecture initiatives in complex customer environments Develop target architectures, current-state assessments, gap analyses, and transformation roadmaps Advise customers on Zero Trust strategy and architecture, including identity-centric security, segmentation, least privilege, continuous verification, and secure access Design security architectures for hybrid environments, datacenters, networks, identity, endpoints, applications, and cloud services Support customers in architectural matters related to AWS, Azure, and GCP Ensure that security solutions support business objectives, risk management, and regulatory requirements Facilitate workshops, lead design decisions, and prepare decision-making material for both technical and business-oriented stakeholders Act as a strategic advisor to CISOs, IT leadership, architecture boards, and projects/programs Contribute to the continued development of our offerings, methodologies, and best practices within security architecture Your Profile We are looking for someone clearly senior, with many years of experience in security architecture, complex IT environments, and advisory work toward customers or larger internal organizations. You are confident in your expertise, comfortable taking ownership, and capable of connecting technology, risk, and business value. We believe you have: Extensive experience working as a Security Architect, Enterprise Architect with a security focus, or a similar senior advisory role Strong understanding of security architecture across several of the following areas: Zero Trust, IAM/PAM, network security, cloud security, hybrid architecture, endpoint security, application security, data protection, and logging/monitoring Proven experience translating security requirements and risks into concrete architectural decisions and actionable plans The ability to lead workshops, facilitate decisions, and build alignment between technical and business stakeholders Strong consultative skills and a deep understanding of how security creates customer value Experience working with strategies, target architectures, governing principles, reference architectures, and roadmap initiatives Good understanding of cloud platforms such as Azure, AWS, and/or GCP Meritorious Qualifications Certifications such as CISSP, SABSA, CISM, CCSP, TOGAF, Azure/AWS Security certifications, or similar Experience from regulated industries or critical infrastructure environments Knowledge of security frameworks and standards such as NIST CSF, ISO 27001, CIS Controls, or similar Experience with SASE/SSE, microsegmentation, identity federation, or modern access control Experience supporting customers in large-scale transformation initiatives or security programs Why Orange Cyberdefense? There are many employers within IT and security. But few are as clearly focused on cybersecurity as we are. At Orange Cyberdefense, you do not just get a new assignment — you become part of an environment where your expertise is taken seriously, continuously developed, and applied where it makes the greatest impact. With us, you will: Work in a dedicated cybersecurity company with deep specialist expertise and a strong market position Be close to some of the industry’s most complex and interesting assignments, where security is business-critical Collaborate with highly experienced colleagues in architecture, advisory, SOC, incident response, offensive security, and managed services Continuously develop through training, certifications, knowledge sharing, and professional exchange Make a real impact — both in customer engagements and in how we develop our services and ways of working Work in a Challenger culture where initiative, accountability, and ideas are encouraged Have colleagues who are passionate about cybersecurity, support each other, and generously share knowledge Contribute to something bigger: building a safer digital society
At Securitas, Digital Security (Cyber Security) is focused on protecting our systems, applications, data, and services while enabling secure and reliable business operations. All countries within our scope are either certified against ISO/IEC 27001 or actively implementing it, ensuring a consistent and structured approach to information security management across the organisation. Your Role – Cluster Digital Security Officer (Cluster North) As a Cluster Digital Security Officer, you will support the technical execution, coordination, and oversight of Digital Security across Cluster North (Sweden, Norway, Finland, Denmark, the UK, and Ireland), while also contributing to Group/ Division-level security priorities. This is a hands-on, operational role, delivered as part of a wider Digital Security organization. You will work closely with different Division/Group IT teams, Digital Security Operations, Digital Security, and Country IT teams, operating in a collaborative, multi-country and multi-layer (Cluster–Division–Group) environment. ---------------------------------------------------------------------------------------------------------------------------------- Key Responsibilities Security Coordination & Team Collaboration (Cluster & Division) * Coordinate Digital Security activities across the Cluster and support execution of the security roadmap aligned with Division priorities, including application security initiatives * Ensure consistent implementation of security controls, baselines, and services across infrastructure and applications * Work closely with GITS, Application teams, Domain and other IT teams to ensure alignment and effective execution * Contribute actively to the Digital Security community, including sharing practices related to application and platform security * Provide regular, transparent, and data-driven reporting on risk posture, control effectiveness, and remediation progress Technical Security Oversight (Infrastructure & Applications) * Monitor and assess the security posture of platforms, infrastructure, and applications (on-prem and cloud) * Oversee key control areas including vulnerability management, patching, identity and access management, endpoint security, and application security * Support secure practices across the application lifecycle (SDLC), including awareness of secure design and common vulnerabilities (e.g. OWASP Top 10) * Ensure effective logging, monitoring, and incident detection capabilities are in place across infrastructure and applications * Track and assess third-party and supplier risks, including risks related to applications and integrations Risk, Compliance & Assurance * Identify and track gaps against security policies, standards, and mandates, including application security requirements * Support/execute risk assessments, internal and external audits, and customer assurance activities across Cluster environments * Drive and follow up on risk remediation plans, ensuring clear ownership and execution across technical teams Securitas Alarm Monitoring Centers (SOC) Security In addition to Cluster responsibilities, you will contribute to Division-level security of Securitas Alarm Monitoring Centers (SOCs) supporting the Domain Digital Security Officer SOC and RVS, which are among the most critical environments within Securitas. This includes: * Supporting and overseeing the security posture of SOC environments, including underlying infrastructure and supporting applications * Ensuring implementation of enhanced technical controls (e.g. network segmentation, strong access control, privileged access management, monitoring, and secure application access) * Monitoring the availability, integrity, and protection of SOC systems, applications, and data flows * Supporting incident detection, response readiness, and recovery capabilities for SOC-related platforms and applications * Working closely with Infrastructure, Application, SOC and other IT teams to reduce attack surface and strengthen resilience of SOC environments ---------------------------------------------------------------------------------------------------------------------------------- Ideal Candidate Profile We are looking for a candidate who combines technical understanding across infrastructure and applications, structured execution, and strong collaboration skills. Certifications (mandatory) * CISSP or CISM or equivalent Experience & Knowledge * 5–7 years of experience in Cyber Security, Information Security or Application Security * Minimum of 2 years of experience in IT operations * Good understanding of security domains (IAM, endpoint security, vulnerability management, logging/monitoring, network security, and application security) * Solid understanding of application security principles, including secure development practices, common vulnerabilities (e.g. OWASP Top 10), and risks in application architecture and integrations * Good understanding of ISO 27001 standard * Experience with risk management, audits, or compliance activities * Understanding of infrastructure environments (networks, servers, cloud platforms) and their interaction with applications Technical & Analytical Skills * Ability to assess security posture across infrastructure and applications and identify control gaps * Comfortable working with security metrics, reports, and risk data * Understanding of incident detection and response processes, including those impacting applications * Ability to translate security requirements into practical and implementable actions across infrastructure and application teams
Om företaget Hos Avaron får du tryggheten i en fast anställning kombinerat med variationen av att arbeta ute hos olika kunder. Vi tillsätter specialister inom allt från teknik, IT och industri till projektledning och affärsstöd – och oavsett uppdrag har du en konsultchef som finns där för dig och din utveckling. Om rollen Du kliver in i ett avgränsat men viktigt tekniskt arbete där en verksamhetskritisk applikation behöver anpassas inför en migrering från SQL Server 2016 till en ny databasinstans. För att lösningen ska fungera smidigt vid installation och samtidigt bli säkrare behöver både paketering och autentisering ses över. Fokus ligger på att ta fram ett uppdaterat MSI-paket som automatiskt pekar applikationen mot rätt databasinstans samt att ersätta dagens hantering av inloggningsuppgifter i klartext med en säkrare anslutningslösning. Det här är en roll för dig som gillar tydliga tekniska problem, praktiska förbättringar och lösningar som ger direkt effekt i drift och förvaltning. ArbetsuppgifterDu bygger ett nytt MSI-paket för applikationen som pekar mot den nya databasinstansen. Du ser till att applikationen kan installeras eller ominstalleras utan manuell konfiguration av databasinställningar. Du analyserar nuvarande lösning där funktionskonto lagras i konfigurationsfiler och tar fram en säkrare hantering. Du implementerar en lösning där applikationen ansluter till databasen med den inloggade användarens autentiseringsuppgifter. Du bidrar i migreringen från SQL Server 2016 genom att anpassa applikationens koppling mot den nya databasinstansen. Du hjälper till att säkerställa att den färdiga lösningen fungerar stabilt vid installation och i fortsatt användning. KravDu har tidigare erfarenhet av att bygga nya MSI-paket för applikationer som pekar mot nya databasinstanser. Du har tidigare erfarenhet av att förbättra säkerhet från hårdkodade inloggningsuppgifter till anslutning via databas med autentiseringsuppgifter. Du har tidigare erfarenhet av migrering från SQL Server 2016. Du har tidigare erfarenhet av MSI-paket som automatiskt konfigurerar applikation mot databasinstans. Du kommunicerar obehindrat på svenska. Vi erbjuderFast anställning hos Avaron AB Tjänstepension Friskvårdsbidrag på 5 000 kr per år Ansökan Vi tillsätter löpande – sök gärna så snart du kan.
Secure Every Identity, from AI to Human Identity is the key to unlocking the potential of AI. Okta secures AI by building the trusted, neutral infrastructure that enables organizations to safely embrace this new era. This work requires a relentless drive to solve complex challenges with real-world stakes. We are looking for builders and owners who operate with speed and urgency and execute with excellence. This is an opportunity to do career-defining work. We're all in on this mission. If you are too, let's talk. THE ENGINEERING ARCHITECT TEAM The Architecture team is a small group of very senior engineers reporting to our VP of Engineering Excellence, working broadly across the organization in collaboration with Engineering, Product, and Security. We partner deeply with other Engineering teams for large projects, and provide direction and architectural guidance for smaller initiatives. We have a dual-pronged charter to “level up the tech stack and level up the people stack” via both technical contributions and partnerships/mentoring. In this role, you will have the opportunity to significantly contribute to Auth0’s future technology direction. Through your experience, knowledge of industry trends, and technical abilities you will provide guidance, build proof of concepts, and deliver production software implementations that help Auth0 Engineering teams move faster by using and developing standard patterns and technologies. You will also help advance the engineering culture and help uplevel other engineers. Note that while this role involves a lot of guidance, documentation, and leadership, it also requires substantial hands-on coding and development of both applications and systems. WHAT YOU’LL BE DOING * You will collaborate with Product, Security, and Engineering teams to define and continually improve Auth0’s technology stack and architecture. * Foster and lead innovation in the IAM space, with a strong focus on Agentic Identity * Lead initiatives to enhance, scale, and evolve Auth0’s product offerings. * Embed within Engineering teams across the organization for large projects, while providing guidance and lighter touch engagements for smaller initiatives. * Design, architect, and document large scale distributed systems. * Lead the development of complex, broadly-scoped functionality in a very large and deep set of services and components. * Teach by doing: coding, optimizing, and troubleshooting Node.js and Go applications in collaboration with feature development teams. * Implement features and create consistent foundations using technologies such as AWS, Azure, Node.js, Go, MongoDB, Redis, PostgreSQL, Kubernetes. * Investigate, understand, and resolve bottlenecks in our ability to scale, use resources efficiently, and maintain a 99.99% uptime SLA. * Drive technical decision making while striving to find the right balance between factors such as simplicity, flexibility, reliability, cost, and performance. * Participate in “round table” discussions and mentor team members and engineers throughout the organization to level up our people. * Participate in our Engineering Leadership Team with other architects, directors, and executives. * You will join our Incident Commander on-call rotation. Members of our team do periodic on-call rotation for high-severity incidents to help up-level our responses After spending time getting acquainted with our applications, systems, and processes, and getting training to WHAT YOU’LL BRING TO THE ROLE * Passion and thorough understanding of what it takes to build and operate secure, reliable systems at scale. * Knowledge of Identity Protocols such as OAuth, OIDC and SAML. * Industry knowledge of the Authorization and Authentication spaces. * Experience in building AI Agents, and/or MCP servers applications. * Experience with security engineering and application security. * Very strong written and verbal communication skills with a demonstrated ability to adjust your communication style to the intended audience, whether communicating with senior executives, customers, engineers, or product managers. * Mastery and deep understanding of hands-on software development building distributed systems. * Experience with API-first applications using REST and/or gRPC. * Experience with multi-cloud environments and container deployments, particularly Kubernetes in AWS/Azure. * Prior experience with application performance management, tracing, and performance testing tools. * Excellence at creating clarity and alignment for technical initiatives. * Great ability to build trust through collaboration with multiple teams and get consensus on a vision. * Knowledge of application security and cloud security best practices. * 10+ years of software development experience. * 5+ years of experience working on cloud applications. And extra credit if you have experience in any of the following! - Deep experience in Node.js (Javascript or Typescript), or Golang. #LI-Hybrid (P-3286_3209115) Below is the annual base salary range for candidates located in California (excluding San Francisco Bay Area), Colorado, Illinois, New York and Washington. Your actual base salary will depend on factors such as your skills, qualifications, experience, and work location. In addition, Okta offers equity (where applicable), bonus, and benefits, including health, dental and vision insurance, 401(k), flexible spending account, and paid leave (including PTO and parental leave) in accordance with our applicable plans and policies. To learn more about our Total Rewards program please visit: https://rewards.okta.com/us. The annual base salary range for this position for candidates located in California (excluding San Francisco Bay Area), Colorado, Illinois, New York, and Washington is between: $244,000—$330,000 USD The Okta Experience * Supporting Your Well-Being * Driving Social Impact * Developing Talent and Fostering Connection + Community We are intentional about connection. Our global community, spanning over 20 offices worldwide, is united by a drive to innovate. Your journey begins with an immersive, in-person onboarding experience designed to accelerate your impact and connect you to our mission and team from day one. Okta is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, ancestry, marital status, age, physical or mental disability, or status as a protected veteran. We also consider for employment qualified applicants with arrest and convictions records, consistent with applicable laws. If reasonable accommodation is needed to complete any part of the job application, interview process, or onboarding please use this Form to request an accommodation. Notice for New York City Applicants & Employees: Okta may use Automated Employment Decision Tools (AEDT), as defined by New York City Local Law 144, that use artificial intelligence, machine learning, or other automated processes to assist in our recruitment and hiring process. In accordance with NYC Local Law 144, if you are an applicant or employee residing in New York City, please click here to view our full NYC AEDT Notice.
RaySearch develops innovative software solutions to improve cancer care. About 1000 clinics in more than 40 countries use RaySearch software to improve treatments and quality of life for patients. RaySearch was founded in 2000 and is listed on Nasdaq Stockholm. The headquarters is located in Stockholm, with subsidiaries in the US, Europe and Asia - Pacific. Today we are more than 400 employees with a common vision of improving cancer care with innovative software. Our great staff is crucial for our success and we offer a fantastic working environment in modern offices, flexibility and good opportunities for development. We believe in equal opportunities, value diversity and work actively to prevent discrimination. We are looking for a System Developer who can blend software development expertise with a strong interest in security. In this role, you’ll contribute directly to RaySearch’s mission: advancing cancer treatment through innovative software. By ensuring that our products are designed and implemented securely, you help protect both patients and healthcare professionals and strengthen the reliability of the tools they depend on. About the role As a System Developer within cybersecurity, you will play a key role in shaping our secure development practices. You will work closely with development teams to embed security into the software development lifecycle and ensure that our products follow industry-leading standards. The role combines hands-on application security work—such as secure code reviews, threat modeling, and penetration testing—with knowledge sharing, training, and collaborative support to help teams make informed security decisions. This is an ideal role for a developer who enjoys cybersecurity and wants to contribute by guiding others, elevating security awareness, and helping teams work securely and effectively together. Your main tasks Work with development teams to implement application security best practices throughout the SDLC. Participate in threat modeling (e.g., STRIDE) and risk assessments for new and existing applications. Assist in designing and implementing cybersecurity controls in products. Ensure compliance with cybersecurity frameworks and standards. Contribute to developer security awareness training and promote secure development practices. Perform secure code reviews, static/dynamic analysis, and penetration testing. Develop and maintain secure coding guidelines and security documentation. Support the preparation of cybersecurity documentation for regulated products (including FDA-related frameworks). Your profile You are a developer with a strong interest in cybersecurity and secure design. You enjoy sharing knowledge, collaborating with others, and supporting development teams in building secure solutions. You communicate clearly, work constructively across functions, and contribute to a culture where security is a natural part of everyday development. Required skills Strong understanding of software development practices and the ability to read, analyze, and evaluate code for security and quality aspects. Strong understanding of application security principles (e.g., OWASP Top 10, secure coding). Experience with threat modeling and risk analysis. Excellent ability to produce clear, structured security and compliance documentation. It’s an advantage, but not required, if you also have experience of: Working in regulated environments (e.g., medical devices, embedded systems). Hands-on experience with security testing tools (e.g., SonarQube, Burp Suite). Familiarity with FDA cybersecurity guidelines, the IEC 8100x series, or IEC 62443 for industrial/embedded systems. Integrating security into CI/CD pipelines (Azure DevOps or GitHub Actions). Our Culture Culture at RaySearch is the driving force behind our organization, where everything we do is driven by a shared passion for innovation and the fight against cancer. Our dedication is reflected in our ability to deliver exceptional results, pay close attention to detail, and consistently go the extra mile. Our employees stand out as experts in their field, driven by a relentless focus on solving problems - no matter how complex. At RaySearch, we take pride in leading the way in cancer treatment, leveraging cutting-edge technology to develop innovative solutions that make a real difference in patient care. Our Offer At RaySearch, we offer a diverse and inclusive work environment, fostering openness, sincerity, and collaboration. Located in Hagastaden, Stockholm's Life Science Hub, our modern and creative workspace includes an in-house gym, yoga, and social activities like ping pong, table football, and regular after-work events. Our bistro serves a fantastic lunch buffet, and we offer morning- and afternoon-fika every day. Our rooftop terrace also provides a stunning 360-degree view of Stockholm, enhancing the work experience. All of this comes attached with a competitive compensation and benefits package. Application Please apply to the position through the application form below. Selection and interviews will be ongoing. We do not accept applications by e-mail.
Job Description As a Senior Software Engineer in the Price Adjustments product, you will design, build, and improve secure, scalable backend solutions that support pricing and adjustment capabilities across H&M. You will work end-to-end across the software lifecycle, from solution design and development to testing, release, maintenance, and continuous improvement. WHAT YOU'LL DO Design and develop scalable, secure, and high-performing backend systems using .NET/C#. Drive API design and system-level decisions with focus on maintainability, performance, and extensibility. Drive key technical initiatives from idea to production, ensuring quality and long-term sustainability. Apply clean code, SOLID principles, testing strategies, and engineering best practices in daily delivery. Improve system performance across application, database, and infrastructure layers. Strengthen observability through logging, monitoring, tracing, and alerting. Support secure development practices, including application security and Azure cloud security standards. Collaborate with DevOps, platform, product, and other engineering teams to improve CI/CD and release processes. Mentor and support other engineers, contributing to a strong and collaborative engineering culture. WHO YOU'LL WORK WITH You will be part of the Price Adjustments product team and collaborate closely with Product Managers, Engineering Managers, Software Engineers, Architects, DevOps and Platform teams, as well as stakeholders across Business Tech. Together, you will help build modern digital solutions that enable H&M to deliver reliable, secure, and customer-focused technology at scale. WHO YOU ARE We are looking for people with... Strong experience with .NET Framework / C# and backend development in enterprise environments. Deep hands-on experience with Microsoft Azure, cloud architecture patterns, and Azure security best practices. Strong knowledge of Entity Framework, T-SQL, and SQL Server, including schema design and performance tuning. Experience designing APIs, distributed systems, and scalable backend architectures. Good understanding of CI/CD pipelines, preferably with GitHub Actions or similar tools. Experience with debugging, performance tuning, observability, and production incident management. Solid knowledge of secure coding and application security practices. Bonus: Azure certifications, Azure Data Factory, microservices, Docker/Kubernetes, messaging systems, or large-scale distributed systems. And people who are... A strong owner who can take initiatives forward independently and deliver high-quality outcomes. Curious, analytical, and confident in solving complex technical problems. Comfortable influencing technical direction and continuously improving engineering practices. A collaborative team player who communicates openly and supports knowledge sharing. Passionate about building resilient, scalable, and secure systems that create real business value. WHO WE ARE H&M Group is a global company of strong fashion brands and ventures. Our goal is to prove that there is no compromise between exceptional design, affordable prices, and sustainable solutions. We want to liberate fashion for the many, and our customers are at the heart of every decision we make. We are made up of thousands of passionate and talented colleagues united by our shared culture and values. Together, we want to use our power, our scale, and our knowledge to push the fashion industry towards a more inclusive and sustainable future. Technology is a key enabler in this journey. At H&M, our Business Tech teams build modern digital products and platforms that support our customers, colleagues, and business globally. WHY YOU'LL LOVE WORKING HERE At H&M Group, we are proud to be a vibrant and welcoming company. We offer our employees attractive benefits with extensive development opportunities around the globe. Staff discount card: Usable on all our H&M Group brands in stores and online. H&M Incentive Program (HIP): Included in our HIP. You can read more about our H&M Incentive Program here. Competitive pensions: Collective Agreement and ITP pensions competitive to the Swedish market. Generous vacation: 30 days' vacation, health care allowance, and good work-life balance. Additional perks: Discounts from Benify. Innovative Environment: Work with cutting-edge technology and innovative solutions. Global Impact: Be part of a team that influences users worldwide. Professional Growth: Endless opportunities to learn and develop your skills. Collaborative Culture: Join a motivated team that values collaboration and excellence. JOIN US Our uniqueness comes from a combination of many things - our inclusive and collaborative culture, our strong values, and opportunities for growth. But most of all, it is our people who make us who we are. Take the next step in your career together with us. The journey starts here. *We are committed to a recruitment process that is fair, equitable, and based on competency. We therefore kindly ask you to not attach a cover letter in your application.
Professional Galaxy is an IT and technology consulting company that provides highly specialized expertise within IT, software development, SAP, purchasing, electronics and mechanical design. We collaborate with experienced senior experts and deliver strategic value-creating expertise to some of Sweden's most complex and analytically demanding projects. Our focus is always on high quality, professionalism and clear, measurable results. We are now seeking a Senior Project Manager – Information Security & AI for one of our clients. About the assignment: On behalf of our client, we are looking for an experienced Senior Project Manager with expertise in Information Security and AI. In this role, you will lead strategic security initiatives within a global organization where business, IT, and Information Security work closely together. Your focus will be on driving projects that strengthen security controls, reduce risk, and ensure that security requirements are embedded in both business processes and technical solutions. You will work in an international environment with multiple stakeholders and be responsible for delivering projects on time, within scope, and with high quality. Key Responsibilities - Lead complex Information Security projects with a focus on AI. - Plan, coordinate, and manage projects throughout the entire project lifecycle. - Coordinate cross-functional teams across Business, IT, and Information Security. - Act as the primary link between business stakeholders, project sponsors, and technical teams. - Identify, manage, and escalate project risks while ensuring delivery against agreed timelines, scope, and quality. - Facilitate project meetings and provide regular status reporting to steering committees and key stakeholders. - Support the implementation and integration of security controls into business processes and technical solutions. Qualifications We are looking for someone who has: - At least five years of experience leading complex projects within international organizations. - Proven experience managing cross-functional and geographically distributed project teams. - Experience delivering Information Security or other security-related IT projects. - Solid technical understanding of IT, such as networking or infrastructure. - General knowledge of AI and its application within Information Security. - Strong project planning, coordination, and organizational skills. - Excellent communication skills with the ability to engage both technical and non-technical stakeholders. - Fluency in English, both written and spoken. Meritorious Experience - Project Management certification such as PMP or IPMA. - Experience within Cyber Security. - Experience supporting governance initiatives, policy implementation, or audit preparation. - Experience with AI-related Information Security initiatives. - Fluency in Swedish and English Who You Are You are a confident and structured project manager who thrives in complex, international environments. You build trust quickly, communicate effectively with stakeholders at all levels, and have a collaborative, solution-oriented mindset. You are comfortable managing changing priorities while maintaining focus on successful project delivery. This is an exciting opportunity to contribute to high-impact initiatives at the intersection of Information Security, AI, and business transformation within a global organization. Are you the right person for the assignment, or do you want to recommend a strong candidate? Do not hesitate to contact us. Please apply directly through our system with: - Your updated CV in english - Availability to start the assignment In the motivation, describe why you are suitable for this assignment - refer to previous consulting assignments, employmxent, education and personal qualities. Please note: We do not accept any applications through mail. All applications have to be sent through the portal to be valid. Offer continuously: Please note that for this role we offer continuously. That means that we sometimes remove the assignments before the deadline. If you are interested, we recommend that you apply immediately.
About the role The objective of this position is to strengthen the team’s capacity to develop and apply data-driven and systems-based approaches across water, coastal and marine domains – including federated data systems, decision-support tools and geospatial analysis – while contributing to project leadership and new funding opportunities. The researcher will work across the team’s three pillars and multiple projects, bringing methodological coherence to data-intensive work and reducing dependence on the team lead for analytical coordination. About the team The Water, Coasts and Ocean Team works across three thematic pillars: Resilient Infrastructures, One Water and Blue Economy. Across these pillars, the team addresses increasingly complex challenges involving data integration, cross-sectoral cooperation and digital decision-support – from freshwater systems and coastal resilience to offshore infrastructure and critical national services. Several funded projects now require integrated capacity in data (systems, modelling and governance). Recruiting a researcher with strong expertise in data systems is a strategic priority for delivery, proposal development and analytical leadership. Key responsibilities Lead and contribute to data systems work: integration, interoperability, security and application in decision-support tools across sectors Apply and promote FAIR data principles (Findability, Accessibility, Interoperability, Reusability) and related standards in project data management Develop and implement digital and data-driven approaches for infrastructure risk assessment, resilience planning and coastal and marine management Contribute to SAFEWIN’s development of federated learning approaches for cross-sectoral data cooperation in sensitive infrastructure contexts Contribute to KRAFT’s analysis of data management challenges and cascading risks across critical infrastructure systems Engage with Swedish and international stakeholders, including public agencies, research partners and practitioners Translate complex data and modelling outputs into policy-relevant insights, project reports, publications and stakeholder-facing materials Contribute to proposal development and fundraising for new projects Support project coordination and supervision of junior researchers where relevant What we are looking for We do not expect candidates to have expertise across all areas listed. We are particularly interested in candidates with strong foundations in either data systems and digital methods or the governance and application of digital tools, combined with a demonstrated ability to work across disciplinary and sectoral boundaries. Experience in or genuine interest in water, coastal, marine or critical infrastructure contexts is valued but not required. Essential PhD in data science, environmental informatics, computer science, infrastructure systems or a related field; candidates without a PhD must demonstrate equivalent independent research experience, including a track record of securing funding Strong experience with data integration, modelling, spatial analysis or the development of digital decision-support tools Experience eliciting user requirements and translating them into analytical methods, digital tools or decision-support products Experience working with data from complex, multi-sectoral or infrastructure-related contexts Working proficiency in at least one programming or scripting language (e.g. Python, R) for data analysis or tool development Ability to lead analytical work packages within interdisciplinary research projects Familiarity with data governance, metadata standards, interoperability frameworks and data architectures supporting the sharing and use of data across organizations or sectors Experience contributing to or leading research funding proposals, with a track record of securing funds at a scale commensurate with career stage Strong publication record or equivalent output in applied research settings Excellent written and oral communication skills in English Desirable Experience with federated learning, privacy-preserving computation or cross-sectoral data governance Familiarity with GIS and geospatial data tools Background in or demonstrable familiarity with critical infrastructure systems, offshore energy, marine monitoring or defence-adjacent data environments Working proficiency in Swedish Who you are This is a cross-cutting role open to candidates at mid- or senior-researcher level. Both levels are genuinely considered; the appointment will reflect the experience and profile of the successful candidate. The ideal candidate at either level combines technical depth in data systems with the ability to engage meaningfully with governance, policy and stakeholder dimensions – and to translate between these registers. The role sits at the technical–policy interface that characterizes SEI’s comparative advantage. We are not looking for a pure engineer or a pure policy analyst, but someone who understands data systems well enough to make credible technical contributions and is intellectually curious about the institutional, political and governance dimensions of how data is managed and shared in complex settings. Mid-level researcher – A mid-level researcher will have demonstrated the ability to work independently on analytical and data-intensive tasks within research projects. They will have some experience contributing to funding proposals and may have secured smaller grants or project components, though not necessarily in a leading role. They may have worked within teams or independently without formal management responsibilities, and will have an emerging publication record or equivalent demonstrated output in applied research settings. Senior researcher – A senior researcher will have a demonstrated track record of independently mobilizing research or innovation funding, including having led funding applications, not only participated in teams led by others. They will have successfully secured funds both for their own work and to support others, and will have held leadership positions with responsibility for more junior staff. They will have built a recognized area of work, evidenced through a sustained publication record, a portfolio of funded projects or equivalent standing in applied or policy research communities.
Sida 1 av 23