Security Engineering Lead

Kisi

Stockholms kommun

On-site

SEK 760,208 - 1,086,012

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Kisi is looking for a Security Engineering Lead in Sweden to oversee their security engineering and hardening program. This role encompasses technical leadership, strategy development, and execution across various platforms including Google Workspace and GCP. The successful candidate will define security requirements, drive incident response, and manage the security roadmap. Ideal candidates will have strong hands-on experience in cloud security, IAM, incident response, and the ability to communicate risks to executives. Join Kisi to enhance their security landscape.

Qualifications

  • Broad experience in security engineering, security operations, or security leadership.
  • Hands-on technical ability; not a policy-only profile.
  • Strong understanding of IAM, MFA, SSO, SaaS security, cloud posture, CI/CD.

Responsibilities

  • Own the security roadmap and risk register.
  • Define the company’s practical security operating model.
  • Drive hardening across corporate systems and cloud infrastructure.

Skills

Security engineering
Cloud security
Incident response
Technical leadership
Risk prioritization

Tools

GitHub
Terraform
Cloudflare Zero Trust

Job description

Role Summary

The Security Engineering Lead owns Kisi’s overall security engineering and hardening program. This role is broader than a Security Operations Engineer and more technical than a pure CISO or GRC lead. The person should be able to drive both strategy and execution across Google Workspace, Rippling, GitHub, GCP, production data access, SaaS tools, incident response, and R&D security. They should be independent from R&D but credible with R&D. They should define security requirements, require remediation, elevate unresolved risk, and work with the CTO/COO on tradeoffs.

Responsibilities

The role owns the security roadmap, risk register, control catalog, exception process, security metrics, and executive reporting. They define the company’s practical security operating model: what requires approval, what needs logging, what access should be temporary, what exceptions are acceptable, and where executive risk acceptance is needed. They also drive hardening across corporate systems and cloud infrastructure, oversee phishing resilience and incident readiness, and ensure access to production data, payroll data, customer data, and critical infrastructure is governed. On the product side, they lead or coordinate reviews for areas such as authorization, tenant isolation, support tooling, audit logs, device‑to‑cloud flows, OTA, firmware signing, and credential lifecycle. External agencies may support GCP hardening, product security, embedded security, phishing simulations, or incident response readiness, but this role keeps ownership internal.

Requirements
  • Broad experience in security engineering, security operations, cloud security, product security, or security leadership
  • Hands‑on technical ability; not a policy‑only profile
  • Strong understanding of IAM, MFA, SSO, SaaS security, cloud posture, CI/CD, logs, secrets, and incident response
  • Ability to work across engineering, IT, HR, finance, support, legal, and executive leadership
  • Strong judgment around risk prioritization, exceptions, and operational tradeoffs
  • Ability to explain risk clearly to executives and turn it into concrete requirements for technical teams
Preferred Experience
  • SaaS, IoT, embedded systems, access control, identity, or physical security
  • GCP and Google Security Command Center (or similar, e.g., AWS)
  • Product security involving APIs, authorization, tenant isolation, admin tools, or customer data
  • GitHub, Terraform, Checkov, Cloudflare Zero Trust, or similar tooling (e.g., for dependency scanning)
  • SOC 2, ISO 27001, and other enterprise customer security expectations (e.g., HIPAA)
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Engineering Lead: Cloud & Product Security
Security Engineering Lead: Cloud & Product Security

Kisi • Stockholms kommun

On-site
SEK 760,000 - 1,087,000
Senior Cloud Security Engineer — Lead GCP Security
Senior Cloud Security Engineer — Lead GCP Security

Events by L • Nyköpings kommun, Stockholms kommun

Hybrid
SEK 1,000,000 - 1,500,000
30 days paid vacation
Private health insurance
Pension contributions
GCP Cloud Security Architect - Hands-On Lead
GCP Cloud Security Architect - Hands-On Lead

True Software Scandinavia AB • Stockholms kommun

On-site
SEK 900,000 - 1,200,000
Competitive compensation
30 days vacation
Private health insurance
+2
Cloud Security Engineer: GCP Foundations & Guardrails
Cloud Security Engineer: GCP Foundations & Guardrails

SEB • Solna kommun

Hybrid
SEK 900,000 - 1,300,000
SEB staff banking
Office next to Mall of Scandinavia
Hybrid workplace
Software Engineer - Platform Security
Software Engineer - Platform Security

Neo4j Inc • Malmö kommun

On-site
SEK 90,000 - 130,000
Consultant Product Cyber Security Coordinator
Consultant Product Cyber Security Coordinator

Arion Recruitment Ltd • Göteborgs kommun

On-site
SEK 650,000 - 850,000
REQ #200 Senior Security Engineer (global)
REQ #200 Senior Security Engineer (global)

WSP • Stockholms kommun

On-site
SEK 60,000 - 90,000
Cloud Security Engineer
Cloud Security Engineer

United States Digital Space LLC • Stockholms kommun

On-site
SEK 665,000 - 999,000
SecOps Engineer
SecOps Engineer

Tavana IT AB • Stockholms kommun

On-site
SEK 600,000 - 800,000
Security Operations Engineer
Security Operations Engineer

Tobii Dynavox® • Stockholms kommun

On-site
SEK 436,000 - 655,000