This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
We’re looking for a Senior Security Engineer to join our Security team in Helsinki HQ. In this role, you will work closely with product development to embed security best practices across the entire software development lifecycle and ensure security of our products. In collaboration with the cloud infrastructure team improve security of our cloud infrastructure by improving existing and implementing new security controls. Have a high level of autonomy in your daily work to improve our security posture.
Job Responsibility:
Work closely with product development to embed security best practices across the entire software development lifecycle and ensure security of our products
In collaboration with the cloud infrastructure team improve security of our cloud infrastructure by improving existing and implementing new security controls
Have a high level of autonomy in your daily work to improve our security posture
Security Engineering & Architecture: Design, implement, and maintain security controls across our SaaS platform and internal infrastructure. This includes automating vulnerability and threat detection (SAST, SCA, IAC, container image analysis), ensuring robust audit logging via SIEM, implementing and managing IAM policies, and continuously identifying and mitigating security risks
Reviews and Assessments: Do internal reviews, threat modeling and testing of new product features. Use automated tools and manual code review to find security issues in software and infrastructure
Collaboration & Communication: Collaborate closely with development and operations teams to integrate security into the Software Development Life Cycle (DevSecOps). Champion a security-first culture, embedding security principles into all aspects of our operations and product development
Security Automation: Improve our existing security tooling in CI / CD and add new tools. Implement automated threat detection and policy-as-code solutions to detect possible data breaches and insecure configurations
Requirements:
3+ years of full-time experience in information security and in total at least 5 years of full-time work experience in e.g. software development
Expertise in securing cloud infrastructure in AWS, GCP or Azure
Basic knowledge of Kubernetes and securing Kubernetes clusters and containerized applications
Software development experience, including proficiency in at least one programming language (e.g., Python, Go, PHP) and understanding of secure coding practices, is required
Experience reviewing source code is also required
Experience of modern CI / CD systems (GitLab / GitHub) and implementing automated security scanning tools (SAST, SCA etc) as part of pipelines
Knowledge of security frameworks and standards such as OWASP ASVS, OWASP SAMM, ISO 27001, and CIS Benchmarks, and applying them to product development
Keen interest in promoting security in a product development organization and working in close collaboration with software and cloud engineers to improve security of our products
Nice to have:
Expertise in securing Kubernetes clusters in complex, multi-cloud environments (a significant plus)
Familiarity with AI software development tools and AI security
Hands-on experience in configuring SIEMs, threat detection and response tooling and web application firewalls
Experience of incident response in cloud environments