Application Security engineer

Schibsted

Oslo

On-site

NOK 850,000 - 1,100,000

Full time

9 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Schibsted is expanding its cybersecurity team to support journalists and the free press. We are looking for an Application Security Engineer to fortify applications and products against threats across the software development lifecycle.

You will work with developers, architects and system engineers to implement security controls, conduct assessments and ensure resilience of our digital assets. You will also contribute to security training, documentation and continuous improvement of our security

Qualifications

  • Background in software development, pentest of web applications, infrastructure and network.
  • Good knowledge of OWASP Top 10 and mitigation techniques.
  • Experience with security assessment tools Burp Suite, OWASP ZAP, Metasploit.

Responsibilities

  • Support the different teams in remediating security issues or vulnerabilities in accordance with the best practices.
  • Contribute to the development of security training and education programs.
  • Collaborate with cross-functional teams to integrate security into the software development lifecycle.
  • Assist in the development and maintenance of security documentation, policies, and procedures to ensure compliance with regulatory requirements and industry standards.
  • Stay updated on emerging threats and industry trends, making recommendations for continuous improvement of our security posture.
  • Implement and manage security tools and technologies to enhance application security.
  • Act as a key contributor to building a robust cybersecurity culture within the organisation.

Skills

Background in software development
Pentest of web applications
Infrastructure and network

Tools

Burp Suite
OWASP ZAP
Metasploit

Job description

We are looking to extend our cybersecurity team to support Schibsted Media and the journalists along their journey for free and independent press. Located in Norway and Sweden, the team is responsible for providing, supporting and maintaining cybersecurity tools for the company as well as providing safe products and services to our customers and journalists. We are part of the tech department, the cybersecurity team collaborates with the other part of the organisation: journalists, editors, it-infrastructure, network, user devices, collaboration software…

What will you do in this role?

As an application security engineer, where you will be instrumental in fortifying our applications and products against potential threats and vulnerabilities. You will work closely with software developers, architects, and system engineers to integrate security measures throughout the software development lifecycle. Your expertise will be crucial in conducting security assessments, implementing best practices, and ensuring the integrity and resilience of our digital assets.

Your main responsibilities will be to:
  • Support the different teams in remediating security issues or vulnerabilities in accordance with the best practices.
  • Contribute to the development of security training and education programs.
  • Collaborate with cross-functional teams to integrate security into the software development lifecycle.
  • Assist in the development and maintenance of security documentation, policies, and procedures to ensure compliance with regulatory requirements and industry standards.
  • Stay updated on emerging threats and industry trends, making recommendations for continuous improvement of our security posture.
  • Implement and manage security tools and technologies to enhance application security.
  • Act as a key contributor to building a robust cybersecurity culture within the organisation.
Key competencies:
  • Background in software development, pentest of web applications, infrastructure and network.
  • Good knowledge of common application security vulnerabilities (e.g., OWASP Top 10) and mitigation techniques.
  • Experience with security assessment tools such as Burp Suite, OWASP ZAP, and Metasploit.
  • Proficiency in programming languages commonly used in web development such as Java, Python, along with familiarity with web technologies like JavaScript, HTML, and CSS.
  • Excellent analytical and problem-solving skills, with the ability to prioritise and manage multiple tasks effectively.
  • Strong communication and interpersonal skills, with the ability to collaborate effectively with both technical and non-technical stakeholders.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

IT security engineer
IT security engineer

Schibsted • Oslo

On-site
NOK 600,000 - 800,000
Application Security Engineer: Fortify Apps & SDLC
Application Security Engineer: Fortify Apps & SDLC

Schibsted • Oslo

On-site
NOK 850,000 - 1,100,000
Security Vulnerability Lead
Security Vulnerability Lead

Laerdal Medical AS • Stavanger

On-site
NOK 900,000 - 1,300,000
Meaningful work
Growth opportunities
Diverse international team
+2
Information Security Analyst
Information Security Analyst

CoreStruct Solutions • Bergen

Hybrid
NOK 124,000 - 168,000
Enterprise Security Services Lead
Enterprise Security Services Lead

AutoStore™ • Oslo

Hybrid
NOK 1,000,000 - 1,500,000
DevSecOps Engineer
DevSecOps Engineer

Accenture Nordics • Oslo

On-site
NOK 900,000 - 1,200,000
Security Platform Engineer
Security Platform Engineer

Assessit • Stavanger

On-site
NOK 900,000 - 1,200,000
Information Security Analyst
Information Security Analyst

BlueDynamics • Bergen

On-site
NOK 106,000 - 128,000
Security Engineer for Media Tech – Protecting Journalists
Security Engineer for Media Tech – Protecting Journalists

Schibsted • Oslo

On-site
NOK 600,000 - 800,000
Information Security Analyst
Information Security Analyst

QuantumIT Solutions • Oslo

On-site