Application Security Engineer
Summary
Build automated security guardrails for container platforms, AI environments, and application deployments at a global investment firm, focusing on policy-as-code, runtime visibility, and AI-specific threats like prompt injection.
EQT is looking for an Application Security Engineer to join our Cyber Security Engineering team, owning the security posture of our hosted applications and container platforms. This is a hands-on engineering role where you will build automated guardrails and real-time visibility — making the secure path the easy path across a modern, globally distributed technology landscape. Over time, this role will grow to include ownership of our AI and agentic platform security as that discipline matures at EQT.
About the Team
The Cyber Security Engineering team defines and validates security standards across EQT's technology landscape. Operating as a trusted security function, the team works closely with platform engineering, cloud infrastructure, identity, and technology assurance teams to strengthen controls while enabling innovation.
This role sits within a small, high-trust team where collaboration, curiosity, and technical depth are core to how we work. The team supports both traditional application environments and EQT's emerging AI and agentic platforms, helping the organization navigate a rapidly evolving threat landscape with practical, engineering-led security standards. You will report to the Head of Digital Employee Experience and partner closely with the CISO function.
About the Role
This role is built around strong application and container security fundamentals, with the mandate to build automated guardrails and observability at scale — not to review individual applications by hand. As you grow into the role, you'll partner with the CISO function and wider security team to extend that same automation-first approach into AI and agentic security, a space EQT is actively investing in.
- Design and deploy automated controls for container platforms and application deployments — admission controllers, policy-as-code, and pre-configured scanning — that enforce standards at the point of deployment rather than after the fact.
- Enable citizen development — making sure non-technical teams can use AI coding tools like Claude Code and CoWork without needing to come through security first, because the guardrails are already there.
- Curate internal security tooling and automation for cost, reliability, and security posture — favouring deterministic, scripted components that run fast and cheap over token-intensive approaches, and tracking cost-per-outcome across security controls as a core operating discipline.
- Own container security standards as enforceable controls: image scanning policy, runtime baselines, and registry governance across all deployment paths, including workloads outside formal pipelines.
- Manage software supply chain risk end-to-end, including dependency scanning, build-time and runtime composition analysis, and identifying high-propagation risk junctions.
- Build application security observability that goes beyond static inventories — a live picture of what is deployed, what it is composed of, and where risk is concentrated — and provide actionable dashboards for engineering leadership and the CISO function.
- Collaborate with Detection & Insider Threat Engineers on container runtime telemetry, and with Identity & Cloud Security Engineers on service identity, workload access, and secrets management.
- As you build context with the team, take on a growing slice of AI platform security — starting alongside colleagues on things like access controls for EQT's AI platforms, MCP connector risk assessment, and defences against prompt injection and data exfiltration — with the opportunity to own this scope outright as the discipline matures.
About You
You are a technically grounded security engineer who cares deeply about developer experience and approaches security friction as a design problem to solve, not a trade-off to accept. You work with clarity and ownership, communicate technical findings to senior stakeholders with confidence, and are genuinely curious about how AI and agentic systems will reshape security engineering — even if that's not where your experience lives today.
What you'll bring (must-have):
- Proven hands-on experience with container security — Kubernetes, image scanning, admission control, runtime protection, and policy-as-code.
- A track record of building automated security controls that scale, with an instinct for making the right path easy and the wrong path hard rather than relying on manual review.
- Solid application security fundamentals, including familiarity with OWASP Top 10, secure development lifecycle, and software supply chain risk, with an orientation toward enforcement over assessment.
- Experience building security visibility into running systems through instrumentation, runtime analysis, or operational dashboards — understanding the difference between knowing what was shipped and knowing what is actually executing in production.
- Active use of AI-assisted development tools in your own engineering work (such as Claude Code, GitHub Copilot, or equivalent).
- A genuine interest in AI and LLM security and a clear appetite to grow into it — this isn't required experience on day one, but it is a direction you want your career to go.
- The ability to communicate complex technical findings clearly and concisely to senior stakeholders who will translate them into policy and governance decisions.
Nice to have:
- Early exposure to AI/LLM security — prompt injection, data exfiltration, model API security, or agentic system controls.
- Familiarity with tools such as CrowdStrike, Aikido, Bold Security, Nightfall, Zscaler, or Lakera Guard.
- Experience with MCP (Model Context Protocol), agentic frameworks, or AI platform administration.
- Background working in private equity, financial services, or other environments where non-public information is a primary asset requiring protection.
- Experience measuring and optimising the operational cost of security controls.
- Comfort deploying and working with local open-source LLMs for automation use cases.
How We Think About This Role
Application security is the foundation this role is built on — that's where the depth needs to be from day one. AI security at EQT is still an emerging discipline, and rather than requiring that expertise up front, we're looking for someone who can bring rockstar AppSec engineering now and grow into AI security scope alongside the team over time, as EQT's AI platforms and the wider practice mature. That's a deliberate growth path we're offering, not a gap we're asking you to fill immediately: you'll build it together with the CISO function and the rest of the security team.
The role is also shaped by a bet on AI-augmented engineering. An engineer with good tooling, a real token budget, and the discipline to automate before they assess can cover ground that would have required a larger team not long ago. We've designed the headcount around that — not to cut corners, but because the best security engineering now looks like one person building excellent guardrails with AI, not several people reviewing things by hand.
What We Offer
At EQT, you will work in an environment that combines high impact with high trust, contributing to security challenges that matter at a global scale. You will help shape practices in areas that are rapidly evolving across the industry — application security, software supply chain security, and modern cloud-native platforms — with a clear path to grow into AI security as that practice takes shape, and direct influence on governance decisions and engineering standards along the way.
We offer meaningful and complex work with global reach, close collaboration with experienced colleagues across security, engineering, and technology, and genuine exposure to emerging AI technologies and cloud-native platforms. EQT has a culture that values curiosity, ownership, and continuous learning, with real opportunities for professional development in a fast-moving environment.
Compensation & Benefits Notice
We offer a competitive total rewards package including base salary, determined based on the role, experience, skill set, and location. Eligible employees may also receive discretionary incentive compensation, awarded in recognition of individual performance and company results. EQT provides a comprehensive benefits offering designed to support employee wellbeing, development, and work-life balance. Benefits include paid time off, parental leave, wellbeing and wellness support, flexible working arrangements, and learning and development opportunities. Benefits are effective from the first day of employment and may vary by location and role.
Inclusion at EQT
Our vision for EQT employees is to build high performing & engaged teams. Our competitive edge comes from fostering an environment where every individual feels valued, empowered, and motivated to drive business impact. Our commitment to inclusion is not just about fairness; We understand and believe that being a great place to work drives the best performance.At EQT, inclusion is a business imperative and it's embedded into our talent strategy, decision-making, and culture to ensure that every individual and team operates at their full potential. By doing so, we unlock better collaboration, stronger innovation, and superior investment outcomes.
About EQT
EQT is a purpose-driven global investment organization focused on active ownership strategies. With a Nordic heritage and a global mindset, EQT has a track record of over three decades of developing companies across multiple geographies, sectors and strategies. EQT has investment strategies covering all phases of a business’ development, from start-up to maturity. EQT has EUR 270 billion in total assets under management (EUR 141 billion in fee-generating assets under management), within two business segments – Private Capital and Real Assets.
With its roots in the Wallenberg family’s entrepreneurial mindset and philosophy of long-term ownership, EQT is guided by a set of strong values and a distinct corporate culture. EQT manages and advises funds and vehicles that invest across the world with the mission to future-proof companies, generate attractive returns and make a positive impact with everything EQT does. EQT has offices in more than 25 countries across Europe, Asia and the Americas and has more than 1,900 employees.
More info:
Follow EQT on LinkedIn, X, YouTube and Instagram
As published by greenhouse · 8 questions · 2 written answers
Basics
First Name, Last Name, Email, Phone, Resume/CV, Cover Letter, Location
Short answers (2)
- What AI-assisted development tools do you use in your own engineering work today, and how do they change what you can get done?
- LinkedIn Profile optional
Pick from a list (4)
- Will you require EQT to sponsor you to obtain, maintain or extend current or future employment/work authorization?
- Are you a current or former employee of EQT?
- Please state in which industry you are currently working
- EQT Privacy Notice
Written answers (2)
- Describe a security control you built that runs without human intervention. What does it enforce and how did you avoid making it a bottleneck for developers?
- How would you approach securing code or deployments that don't flow through a formal CI/CD pipeline — for example, business users building tools with AI assistants and deploying them directly?