Enable job alerts via email!

Senior Security Engineer

Epidemic Sound AB

Stockholms kommun

On-site

SEK 800 000 - 1 000 000

Full time

Today
Be an early applicant

Job summary

A leading audio content company in Stockholm is seeking a Senior Security Engineer specializing in Application or Product Security. This role involves enhancing the Secure Software Development Lifecycle and collaborating with engineering teams to protect against threats. Candidates should have experience in application security, familiarity with tools like BurpSuite, and programming skills in Python or similar languages. Join a global team to strengthen security practices.

Qualifications

  • Experience securing products and applications.
  • Familiarity with cloud security features, preferably GCP.
  • At least one programming or scripting language experience.

Responsibilities

  • Identify and fix vulnerabilities in applications.
  • Expand and implement the Secure Software Development Lifecycle.
  • Deliver internal tech talks and security training.

Skills

Application Security
Product Security
Static Code Analysis
Penetration Testing
Docker
Kubernetes
Python

Tools

BurpSuite
Git
Terraform
Github Actions
Job description

We are looking for a Senior Security Engineer, specializing in Application or Product Security, who will form a key part of the Security Division here at Epidemic Sound. You, along with your team, will help ensure our customers and services are protected from a wide range of online threats. Although we are a global company, this position will be based in our Stockholm office.

The role

You'll help to design and increase the maturity of our Secure Software Development Lifecycle (SSDLC) to remain resilient to ever changing attack vectors. Balance working closely with a small team of security experts with embedding regularly with product development teams to understand our product needs, build relationships, and translate security knowledge and best practices to best suit the needs of our product teams through in person interactions as well as code libraries and written documentation.

Your key responsibilities include:

  • Working closely with software engineering teams and individuals to identify, track and fix vulnerabilities/risks in our applications and products.
  • Expanding, architecting, implementing and evangelizing our SSDLC.
  • Sharing your knowledge through solid documentation, secure coding libraries, secure code reviews, delivering internal tech talks and security awareness training to technical staff.
  • Embedding within development teams to build secure awareness and accurately gauge risk profiles throughout our product environment.
  • Promoting secure ways of working across all areas of the organization.
  • Helping to identify and evaluate new security tools and services, and integrate existing tools and services into central dashboarding tools.
  • Assisting with security incidents (including on-call), breaches and training exercises around them, including creating security patches.
  • Working on a wide range of projects and new initiatives in the team.
  • Responding to product security-related requests from across the organization.
  • Mentoring other security engineers.
  • Writing solid documentation that can be used by a wide range of different viewers.

Requirements:

  • Experience securing products and applications, familiarity with BurpSuite Enterprise, Snyk and Burpsuite Professional especially appreciated.
  • Security features of the big public cloud providers (preferably GCP)
  • At least one programming or scripting language (Python, Go, Kotlin, Node.js, and Bash experience preferred)
  • Kubernetes, Docker or any other containerization architecture
  • Experience with Git, Github Actions and Terraform
  • Identifying vulnerabilities in software, systems and processes
  • Static code analysis
  • Writing test cases for existing code
  • Penetration Testing
  • Good understanding or working knowledge of common security frameworks (ISO 27001, SOC2, PCI-DSS, NIST, etc), compliance and regulatory requirements.
Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.