An application made for this job — a tailored resume and cover letter that speak straight to the posting.
Vend seeks a Security Engineer to own application security end to end: bug bounty triage, code scanning, vulnerability management, and incidents. AI agents are central to scaling this work, and you will help build and use them.
You will join our Product Security Team in the Nordics, with locations in Stockholm, Oslo, or Aarhus, and a flexible arrangement to work 3 days per week remotely. The role emphasizes practical security impact across production systems and collaboration with developers.
THE OPPORTUNITY IN A NUTSHELL
You? Empathetic with the people you work with, proactive about the work itself, and creative about how you solve it. Your passion is squashing bug classes at scale and helping developers without blocking them
Role? As a Security Engineer, you will own application security work end to end: bug bounty triage, code scanning, vulnerability management, and incidents. AI agents are a big part of how we scale that work. You will use them every day and help build new ones.
Tech stack? Our marketplaces run on Java/Kotlin, JavaScript/TypeScript, C# and Go, and some teams even use Haskell. We run on AWS and GCP, and most apps deploy to Kubernetes. We build our agents with whichever models fit the job best
Location? Join us in our Stockholm, Oslo, or Aarhus office with the flexibility to work 3 days per week remotely.
Company? Vend, home of FINN, Blocket, Tori, Oikotie, DBA and Bilbasen. Around 500 developers deploy code to production several thousand times a week.
Why us? Most security teams are still deciding what to do with LLMs. We have spent a year running agents on production security work and measuring what actually helps. You will join while we are still working out the methods, and help shape them.
Sounds like your cup of tea?
We used to automate with code. Now we automate with reasoning. Security scanners find patterns, but confirming a real risk takes investigation: tracing a request across services, finding who owns them, checking how they are exposed, reading logs, and testing whether an attack works. We are teaching agents to do more of that investigation, so you can spend your time on the findings that matter.
We are seven people spread across the Nordics, and we meet up regularly to work together. We are part of the Delivery Platforms area in Vend. Core Delivery Platforms helps Vend create real value by turning delivery into a trusted, measurable flow. We build composable, self-serve platform capabilities and provide services that reduce friction and power the flow that connects build, data, and AI, so ideas become outcomes faster.
If you want to learn more about Emil and the team, you can follow this Link here: vend.com/news/inside-vends-product-security-team-a-year-of-ai-agents-on-our-production-systems
QUESTIONS?
Emil Vaagland, Head of Product Security, is happy to provide information about the daily work and answer any questions you may have about the role, you can reach out via email: emil.vaagland@vend.com. For the recruitment process and other topics, you can reach out to Clayton Don Corda, Senior TA Partner, via clayton.don.corda@vend.com