Senior Application Security Engineer

Nordic Investin Group Aktiebolag

Stockholms kommun

On-site

SEK 900,000 - 1,200,000

Full time

3 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Nordic Investin is seeking a Senior Application Security Engineer to embed security in product delivery for a partner company in Sweden. You will work with developers on threat modelling, secure design, testing and remediation across modern web and API services.

As a senior colleague, you will own outcomes, recognise risk early and provide practical, drivable paths to fixes while still contributing hands-on delivery and mentoring engineers.

Qualifications

  • Strong software engineering or application security background.
  • Knowledge of web, API and identity vulnerabilities.
  • Experience with threat modelling and secure code review.
  • Ability to automate checks within CI/CD.
  • Clear understanding of risk severity and exploitability.
  • Constructive communication with product engineers.

Responsibilities

  • Facilitate threat modelling for new features and architectures.
  • Review code and designs for exploitable weaknesses.
  • Improve SAST, DAST and dependency scanning workflows.
  • Develop secure coding guidance with practical examples.
  • Support vulnerability triage and coordinated remediation.
  • Teach teams through pairing, workshops and incident lessons.

Skills

Threat modelling
Secure code review
CI/CD automation
Web/API security
Risk assessment
Communication with dev teams

Job description

On behalf of a partner company, Nordic Investin is looking for a Senior Application Security Engineer. You enjoy finding the design flaw before it becomes a production incident and helping engineers fix the pattern rather than only the instance.

The partner wants to embed application security more deeply in product delivery. You will work with developers on threat modelling, secure design, testing and remediation across modern web and API services.

Security work is expected to reduce real exposure while preserving the organisation’s ability to deliver. The strongest candidates can connect a technical weakness with a credible threat, an appropriate control and a practical path to implementation.

How you will work

You will work directly with the people who design, operate and depend on the systems being protected. Recommendations must identify the threat, the affected asset and a realistic implementation path. The partner values careful evidence, proportionate controls and clear escalation when risk cannot be removed immediately.

As a senior colleague, you will own substantial outcomes and help others make stronger decisions. You are expected to recognise risk early, communicate it without drama and move work forward with practical alternatives. The role still includes hands on delivery; seniority here means broader judgement, not distance from the work.

What you will do
  • Facilitate threat modelling for new features and architectures.

  • Review code and designs for exploitable weaknesses.

  • Improve SAST, DAST and dependency scanning workflows.

  • Develop secure coding guidance with practical examples.

  • Support vulnerability triage and coordinated remediation.

  • Teach teams through pairing, workshops and incident lessons.

What you will bring
  • Strong software engineering or application security background.

  • Knowledge of web, API and identity vulnerabilities.

  • Experience with threat modelling and secure code review.

  • Ability to automate checks within CI CD.

  • Clear understanding of risk severity and exploitability.

  • Constructive communication with product engineers.

Experience that would add value
  • Cloud native application security.

  • Mobile or embedded application security.

  • Bug bounty, penetration testing or security research.

A background that can succeed here

You may be a developer who moved into security or a security specialist who can write and review production code. The partner needs technical depth and a style that makes engineering teams more capable, not more dependent.

What makes the opportunity interesting

The role gives you direct influence over products before release and the freedom to improve the security system around delivery. Your success will be visible in better designs, faster remediation and fewer repeated weaknesses.

The exact partner, employment model, compensation, start date and working arrangement will be explained openly during the process. Nordic Investin will make sure you understand the context, expectations and decision path before you are asked to commit significant time.

The recruitment conversation

During the process, Nordic Investin will focus on concrete decisions you have made: the context you received, the alternatives you considered, the result you observed and what you would change today. You do not need every optional technology if your core experience transfers and you can explain how you would close the gap.

How to apply

Apply with your CV or LinkedIn profile and a short note describing the most relevant system, product or transformation you have helped deliver. Nordic Investin welcomes candidates with different routes into technology and assesses applicants on relevant capability, judgement and potential.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Cloud Security Engineer
Senior Cloud Security Engineer

Nordic Investin Group Aktiebolag • Stockholms kommun

On-site
SEK 700,000 - 900,000
Senior Application Security Engineer - Shape Secure Delivery
Senior Application Security Engineer - Shape Secure Delivery

Nordic Investin Group Aktiebolag • Stockholms kommun

On-site
SEK 900,000 - 1,200,000
Application Security Engineer
Application Security Engineer

Yora • Göteborgs kommun

On-site
SEK 600,000 - 900,000
Junior Security Operations Analyst
Junior Security Operations Analyst

Nordic Investin Group Aktiebolag • Gestra

On-site
SEK 320,000 - 460,000
Identity and Access Management Engineer
Identity and Access Management Engineer

Nordic Investin Group Aktiebolag • Malmö kommun

On-site
SEK 550,000 - 850,000
Identity and Access Management Engineer
Identity and Access Management Engineer

Nordic Investin Group Aktiebolag • Malmö

On-site
SEK 550,000 - 750,000
Application Security engineer
Application Security engineer

Schibsted • Stockholms kommun

On-site
SEK 700,000 - 900,000
Senior Azure NET Engineer
Senior Azure NET Engineer

Nordic Investin Group Aktiebolag • Stockholms kommun

On-site
SEK 900,000 - 1,200,000
Senior Java Platform Engineer
Senior Java Platform Engineer

Nordic Investin Group Aktiebolag • Göteborgs kommun

On-site
SEK 900,000 - 1,200,000
Senior AWS Platform Engineer
Senior AWS Platform Engineer

Nordic Investin Group Aktiebolag • Göteborgs kommun

On-site
SEK 900,000 - 1,150,000