Application Security Engineer
Sitoo Stockholm, Stockholm County, Sweden
Software Development · 51-200 employees
About the role
You will manage the application-level vulnerability backlog and ensure code fixes are triaged and compliant with SOC 2 SLA targets. Additionally, you will collaborate with engineering teams to maintain CI/CD security gates and support secure development practices.
What they look for
Requirements
The role requires foundational knowledge of application security, secure coding practices, and common vulnerabilities like the OWASP Top 10. Candidates must have experience with at least one programming language and a proactive approach to managing security technical debt.
Benefits
Full description
Join our highly skilled team — breaking new ground and shaping the future of retail. We dare to dream big, we have the courage to keep raising the bar, and we're committed to being a force for good in retail—helping both established and fast-growing brands meet the ever-changing expectations of their customers.
Sitoo is a fast-growing technology company exploring how far we can take innovation to deliver the world's best Unified Commerce Platform and Point of Sale. Our technology is used in more than 20 countries—a number that keeps growing thanks to our incredible team. And we have no intention of slowing down. Are you the Application Security Engineer we're looking for?
Your mission at Sitoo
As a Application Security Engineer at Sitoo, you will work closely with our CISO, Senior Security Engineer, and engineering teams to support the secure development side of our platform. You will play a vital, hands-on role in securing our application code, repositories, and dependencies. You will take direct ownership of our application-level vulnerability backlog across our GitHub repositories, ensuring code fixes are triaged, released, and compliant with our SOC 2 SLA targets. By pairing a passion for security with an eagerness to learn, you will help triage findings, maintain CI/CD security gates, and empower our developers to safely leverage AI-assisted coding tools.
What you will do
- Actively track, prioritize, and remediate application and dependency vulnerabilities (Dependabot, Aikido) across ~184 active GitHub repositories to hit strict SOC 2 SLA targets.
- Assist development teams with code-level security updates across npm, pnpm, Go, Ruby, Python, Dockerfiles, and GitHub Actions.
- Help investigate and resolve breaking dependency upgrades, CI failures, and build issues caused by security updates.
- Track merged security fixes through the release lifecycle to ensure they are successfully deployed and validated in production.
- Contribute to improving repository-level security workflows, automated scanning, and CI/CD security gates.
- Learn, help define, and monitor security guardrails for the safe use of AI-assisted development tools in product engineering.
- Collaborate closely with our Senior Cloud & Infrastructure Security Engineer to escalate complex code or architectural risks while continuously growing your technical security expertise.
What you'll bring to the table
- Foundational knowledge of application security concepts, secure coding practices, and common vulnerabilities (OWASP Top 10).
- Familiarity with at least one programming language (such as Python, Go, Ruby, or JavaScript/TypeScript) and a hands-on drive to test PRs, update libraries, and fix build breakages.
- Basic understanding of version control (GitHub), repository management, and CI/CD pipelines.
- A proactive, problem-solving mindset with a genuine enthusiasm for clearing security technical debt and learning modern AppSec practices.
- Interest in AI-assisted development and a basic awareness of AI-related code security risks (e.g., hallucinated packages, unsafe generated patterns).
- Confident, clear communication skills to collaborate effectively across development teams and foster a culture of shared security ownership.
- Professional English, both verbal and written.
Why Sitoo
We dare to dream big, we have the courage to keep raising the bar, and we’re committed to being a force for good in retail. We believe in an inclusive culture where everyone feels a sense of belonging. We support each other, we win together, we celebrate success together, and we overcome challenges together.
Today, we’re more than 120 dedicated experts with a positive and solution-oriented mindset. Most importantly, we take care of each other, and we never forget to have fun.
The Good Stuff
We care just as much about our team as we do about pushing the boundaries of retail. To make sure you have the support, balance, and energy to thrive, both in and out of the office, here is glimpse of what you get when you join us:
- 30 days vacation
- 5,000 SEK wellness benefit
- Gym membership discount
- Parental leave top-up
- Occupational pension
- Fika every Thursday
- AW on Fridays
- And more!
Similar roles
-
Application Security & IAM Engineer
Onwelo Kielce, Holy Cross Voivodeship, Poland
-
Senior Infrastructure & Network Security Engineer
Coopers Group AG Switzerland
-
Cybersecurity Business Development Manager (100 % remote) (m/f/d)
EWOR GmbH Karlsruhe, Baden-Württemberg, Germany
-
Junior Cybersecurity Architect - Categoria protetta L.68/99
BIP Consulting Rome, Lazio, Italy · €28K–€34K/yr
-
[EJV] Lead AI Safety & Security Engineer
Bosch Group Ho Chi Minh City, Ho Chi Minh, Vietnam
-
Network and Security Engineer
Skillsoft Hyderabad, Telangana, India