Security Vulnerability Lead

Laerdal Medical AS

Stavanger

On-site

NOK 900,000 - 1,300,000

Full time

10 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Meaningful work
Growth opportunities
Diverse international team
Flexible work arrangements
Wellbeing program

Job summary

Laerdal Medical AS is seeking a Security Vulnerability Lead to drive software vulnerability management across products and infrastructure. You will work closely with development teams to embed security into daily workflows and report to the Head of Digital Product Security.

You will coordinate scans, manage the SCA platform, and coordinate with external SecOps teams to strengthen incident response and remediation SLAs.

Qualifications

  • Experience with vulnerability management and security assessments of systems and applications.
  • Understanding of cyber threats, attack techniques, and risk assessment methodologies.
  • Familiarity with CVEs and CVSS.
  • Familiar with architectural risk analysis and threat modeling.
  • Ability to collect, analyze, and correlate threat intelligence.
  • Experience with application architecture and development.

Responsibilities

  • Coordinate vulnerability scans and penetration tests, including external SecOps teams.
  • Own and operate SCA and vulnerability tracking platform.
  • Help development teams standardize vulnerability assessment and remediation processes.
  • Build and maintain incident response procedures and playbooks.

Skills

Vulnerability management
Security assessments
Threat modeling
CVEs & CVSS
Security risk advisory
Development collaboration
Incident response
Communication skills

Education

Information security degree
3–6 years experience

Tools

OWASP Dependency-Track
SOAR automation

Job description

Make a difference with Laerdal where immersive technology transforms healthcare quality and education across the globe. With over 2,200 colleagues, join a team where collaboration and engagement are prioritized in helping save one million more lives, every year, by 2030.

Laerdal Medical is a global, family-owned company headquartered in Stavanger, Norway. With the vision “Helping Save Lives”, Laerdal develops products and solutions in medical simulation, training, and therapy. The company has approximately 1,600 employees in more than 20 countries, serving healthcare institutions, educational institutions, and emergency services worldwide.

About the role

As Security Vulnerability Lead at Laerdal Medical, you will be the security team’s operational driving force in software composition analysis. You will ensure that the organization detects, assesses, and manages vulnerabilities across its products and product infrastructure, and is prepared to handle security incidents within the same scope. You will be reporting to the Head of Digital Product Security. Developer know-how is a key trait for success in this role, as you will work closely with development teams to integrate security into their daily workflows.

Key Responsibilities

Help development teams standardize how vulnerabilities are assessed, prioritized, reported, and handled, in line with L2DP’s triage process and remediation SLAs

Own and operate Laerdal’s software composition analysis (SCA) and vulnerability tracking platform (OWASP

Dependency Track) and help development teams integrate it into their workflows

Coordinate vulnerability scans and penetration tests, including work by the external SecOps-teams

Build and maintain incident response procedures and playbooks

Required Qualifications

Experience with vulnerability management and security assessments of systems and applications

Understanding of cyber threats, attack techniques, and risk assessment methodologies

Familiarity with and understanding of CVEs and CVSS

Familiar with architectural risk analysis/threat modeling

Ability to collect, analyze, and correlate threat intelligence

Experience working with application architecture and development

Strong communication skills and the ability to advise development teams on security risk

Ability to work effectively under pressure

Preferred Qualifications

Experience working in a global organization

Competence in digital forensics and evidence collection

Experience with automation of vulnerability management and security operations (SOAR)

Familiarity with the frameworks such as MITRE ATT&CK, CWE and CAPEC

Knowledge of cloud security (Azure, AWS, GCP)

Understanding of security challenges in development environments (npm/yarn supply chain, C++ memory safety, ML pipeline integrity)

Familiarity with industry-specific requirements for medical devices (MDR, IEC 62443)

Knowledge of SBOM standards and tools (CycloneDX, SPDX)

Education and Experience

Relevant higher education in information technology, cybersecurity, information security, or equivalent

Minimum 3-6 years of experience in information security, with documented experience in vulnerability management and/or incident response

Relevant certifications are an advantage, e.g., GCIH, GCFA, GPEN, CEH, OSCP, ISO 27001 Lead Auditor

What we offer
  • Interesting and meaningful work contributing to our mission
  • Opportunities for personal and professional growth
  • A great, diverse, inclusive, and international work environment
  • Innovative and forward-thinking technology
  • Competitive compensation and benefits package
  • Flexible work arrangements, an extensive wellbeing program with social, cultural and sports activities and benefits such as discounted public transport, wardrobe with towel service, company cabins, and more.

by 6 September.

For questions regarding this role, please contact goran.breivik@laerdal.com.

Laerdal Medical is an inclusive employer that values diversity. We encourage all qualified candidates to apply, regardless of gender, age, ethnic background, disability, sexual orientation, or beliefs. Please note that we use Semac background checks in our recruitment process.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Vulnerability Lead: SCA & Incident Response
Security Vulnerability Lead: SCA & Incident Response

Laerdal Medical AS • Stavanger

On-site
NOK 900,000 - 1,300,000
Meaningful work
Growth opportunities
Diverse international team
+2
Senior Software Developer
Senior Software Developer

Laerdal Medical • Norway

On-site
NOK 900,000 - 1,200,000
Competitive compensation
Flexible work arrangements
Wellbeing program
+3
Senior Software Developer
Senior Software Developer

Laerdal Medical AS • Stavanger

On-site
NOK 900,000 - 1,200,000
Meaningful work
Growth opportunities
Inclusive, diverse environment
+2
Enterprise Security Services Lead
Enterprise Security Services Lead

AutoStore™ • Oslo

Hybrid
NOK 1,000,000 - 1,500,000
Portfolio Manager, HCP Team Response
Portfolio Manager, HCP Team Response

Laerdal Medical AS • Stavanger

On-site
NOK 1,000,000 - 1,400,000
Portfolio Manager, Healthcare Provider Teams
Portfolio Manager, Healthcare Provider Teams

Laerdal Medical AS • Stavanger

On-site
NOK 900,000 - 1,300,000
Application Security engineer
Application Security engineer

Schibsted • Oslo

On-site
NOK 850,000 - 1,100,000
Senior Full-Stack Engineer — Build Cloud-Native Platforms
Senior Full-Stack Engineer — Build Cloud-Native Platforms

Laerdal Medical AS • Stavanger

On-site
NOK 900,000 - 1,200,000
Meaningful work
Growth opportunities
Inclusive, diverse environment
+2
DevSecOps Engineer
DevSecOps Engineer

Accenture Nordics • Oslo

On-site
NOK 900,000 - 1,200,000
Technical Safety/Senior Engineer – Bergen
Technical Safety/Senior Engineer – Bergen

Dovre Solutions • Bergen

On-site
NOK 700,000 - 1,000,000
Equal opportunity employer