Point your AI agent at freehire and let it find you a job.

Get the CLI →

emagine

NewBe an early applicant

Senior Security Engineer

Posted 1 view
Discussion

Summary

Own and improve the security posture of a cloud-native platform: hardening cloud (ideally AWS) and Kubernetes infrastructure, embedding secure SDLC practices like threat modelling and code/container scanning, and turning ISO 27001, NIS2 and NIST CSF compliance into automated technical controls. Also covers corporate IT security and technical incident response.

Start: ASAP or in 1 months time

Duration: ongoing contract 30 days mutual notice period

Location. Hybrid setup from Stockholm - 2/3 days per week in the office

What you'll do

Secure the platform.
Own the security posture of our cloud infrastructure and Kubernetes platform: identity and access, network segmentation, secrets management, encryption, workload hardening and logging, alerting and detection. You will build guardrails so secure is the default path for our engineers.

Embed security in how we build products.
Partner with product teams on threat modelling, secure design reviews and a pragmatic secure SDLC. Run and tune code, dependency and container scanning, triage what matters, and coordinate external penetration tests and bug reports through to remediation.

Turn compliance into engineering.
Implement and evidence the technical controls behind our ISO/IEC 27001, NIS2 and NIST CSF work. Automate evidence collection where possible, support audits with facts from our systems, and translate requirements into backlog items engineers can act on.

Raise the bar on corporate IT security.
Work with our IT function to strengthen the security configuration of our identity provider, endpoint management, SaaS integrations and office networks, so the corporate environment is as well defended as the production one.

Own incident response for the technical estate.
Maintain and exercise our incident response runbooks, lead technical investigation and containment when something happens, and drive learnings back into the platform.

Run security risk assessments of new systems, integrations and vendors, and give clear, proportionate recommendations that balance risk against speed.

Make the whole company better at security.
Share knowledge, run workshops and champion a culture where security is everyone's concern and never a blocker for its own sake.

This is you

  • You have several years of hands-on security engineering experience in a modern, cloud-native software company, and you have seen what scale and growth do to a security posture.

  • You are deeply comfortable in at least one major cloud (preferably AWS) and with Kubernetes, infrastructure as code and CI/CD pipelines. You can read and write code, and you would rather automate a control than document a manual one.

  • You know the practical toolset around identity federation and SSO, secrets and key management, logging and monitoring, vulnerability management, backups and disaster recovery, and you understand the trade-offs between options.

  • You have translated frameworks like ISO 27001, NIS2 or SOC 2 into concrete technical controls and audit evidence, and you can explain to an auditor why a control works and to an engineer why it matters.

  • You have run threat modelling sessions or security assessments with product teams and know how to get to a shared decision without slowing the team down.

  • You communicate clearly with legal, engineering and leadership alike, and you are as comfortable hosting a workshop as debugging an IAM policy.

  • You work with a high degree of autonomy, drive initiatives end to end, and proactively improve how security is done rather than waiting to be asked.

  • You are curious, keep up with the threat landscape and industry trends, and enjoy helping others level up.

Nice to have

  • Experience with security in an energy, IoT or hardware-connected environment (devices in homes, real-time data, grid-facing systems).

  • Familiarity with the EU AI Act, GDPR engineering requirements or physical security for offices and network equipment across multiple locations.

  • Experience with detection engineering or running a lightweight SOC-style capability.

  • Relevant certifications (for example CISSP, CCSP, OSCP, AWS/GCP security specialties) are a plus but not required; we care about what you have built.

Skills

See also

Security jobs by country — openings, pay and top skills →

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available