Get more replies from employers
Send a job-specific resume in minutes.
Laerdal Medical AS is seeking a Security Vulnerability Lead to drive software vulnerability management across products and infrastructure. You will work closely with development teams to embed security into daily workflows and report to the Head of Digital Product Security.
You will coordinate scans, manage the SCA platform, and coordinate with external SecOps teams to strengthen incident response and remediation SLAs.
Make a difference with Laerdal where immersive technology transforms healthcare quality and education across the globe. With over 2,200 colleagues, join a team where collaboration and engagement are prioritized in helping save one million more lives, every year, by 2030.
Laerdal Medical is a global, family-owned company headquartered in Stavanger, Norway. With the vision “Helping Save Lives”, Laerdal develops products and solutions in medical simulation, training, and therapy. The company has approximately 1,600 employees in more than 20 countries, serving healthcare institutions, educational institutions, and emergency services worldwide.
As Security Vulnerability Lead at Laerdal Medical, you will be the security team’s operational driving force in software composition analysis. You will ensure that the organization detects, assesses, and manages vulnerabilities across its products and product infrastructure, and is prepared to handle security incidents within the same scope. You will be reporting to the Head of Digital Product Security. Developer know-how is a key trait for success in this role, as you will work closely with development teams to integrate security into their daily workflows.
Help development teams standardize how vulnerabilities are assessed, prioritized, reported, and handled, in line with L2DP’s triage process and remediation SLAs
Own and operate Laerdal’s software composition analysis (SCA) and vulnerability tracking platform (OWASP
Dependency Track) and help development teams integrate it into their workflows
Coordinate vulnerability scans and penetration tests, including work by the external SecOps-teams
Build and maintain incident response procedures and playbooks
Experience with vulnerability management and security assessments of systems and applications
Understanding of cyber threats, attack techniques, and risk assessment methodologies
Familiarity with and understanding of CVEs and CVSS
Familiar with architectural risk analysis/threat modeling
Ability to collect, analyze, and correlate threat intelligence
Experience working with application architecture and development
Strong communication skills and the ability to advise development teams on security risk
Ability to work effectively under pressure
Experience working in a global organization
Competence in digital forensics and evidence collection
Experience with automation of vulnerability management and security operations (SOAR)
Familiarity with the frameworks such as MITRE ATT&CK, CWE and CAPEC
Knowledge of cloud security (Azure, AWS, GCP)
Understanding of security challenges in development environments (npm/yarn supply chain, C++ memory safety, ML pipeline integrity)
Familiarity with industry-specific requirements for medical devices (MDR, IEC 62443)
Knowledge of SBOM standards and tools (CycloneDX, SPDX)
Relevant higher education in information technology, cybersecurity, information security, or equivalent
Minimum 3-6 years of experience in information security, with documented experience in vulnerability management and/or incident response
Relevant certifications are an advantage, e.g., GCIH, GCFA, GPEN, CEH, OSCP, ISO 27001 Lead Auditor
by 6 September.
For questions regarding this role, please contact goran.breivik@laerdal.com.
Laerdal Medical is an inclusive employer that values diversity. We encourage all qualified candidates to apply, regardless of gender, age, ethnic background, disability, sexual orientation, or beliefs. Please note that we use Semac background checks in our recruitment process.