As a Senior DevSecOps Engineer at Northbridge Security, you'll lead security and platform work in client engagements, from architecture to implementation. You set the direction for how security is built into the delivery flow, and you make sure the client's team can own it after you leave.
Northbridge Security helps organisations in regulated industries, including life sciences, medical technology and finance, ship software quickly without compromising on security or compliance. We work across cloud, DevSecOps and AI governance, and we run the same controls we recommend to our clients.
What you will do
- Design DevSecOps architecture, security baselines and standards for client cloud and delivery platforms
- Build CI/CD pipelines with built in controls: SAST, SCA, secrets, container and IaC scanning, and SBOM generation
- Automate compliance checks and evidence collection, so audits become a byproduct of delivery
- Architect landing zones, identity and access based on Zero Trust and least privilege
- Lead threat modelling, security reviews and incident response
- Build developer platforms and golden paths where the secure choice is also the easy one
- Advise client technical leadership and coach their teams
What we are looking for
- At least 10 years in DevOps, platform, infrastructure or security roles, several of them with a clear security focus
- Experience establishing DevSecOps practices in one or more organisations
- Architect level experience with AWS and/or Azure, plus hands on experience with Kubernetes and Infrastructure as Code
- Experience integrating security tooling into pipelines, from SAST and SCA to container and IaC scanning
- Ability to turn frameworks such as ISO 27001, CIS Benchmarks or NIST into automated controls
- Comfortable in front of clients, explaining a risk to both a developer and a CISO, fluent in Swedish and English
Nice to have
- Specific tooling such as Terraform, Pulumi, Bicep, AWS CDK, GitHub Advanced Security/CodeQL, Semgrep, Snyk, Trivy or Wiz
- Experience from regulated environments: GxP, medical device software (SaMD), HIPAA, DORA, PCI DSS or SOC 2
- Experience leading audits or regulatory submissions
- Experience with SOC capabilities, SIEM/SOAR and observability
- Certifications such as AWS Solutions Architect or DevOps Engineer Professional, AWS Security Specialty, Azure Solutions Architect or DevOps Engineer Expert, CISSP or CCSP
- Experience securing AI assisted development workflows
Why Northbridge Security
- Senior colleagues who build what they recommend
- A focus on architecture and principles rather than individual tools
- Variety: SMB and enterprise clients at different levels of maturity
- Benefits and compensation model (80/20, 70/30, 70/25)