Senior Application Security Engineer
Nordic Investin Group Stockholm, Maine, United States
IT Services and IT Consulting · 201-500 employees
About the role
Facilitate threat modelling for new features and architectures while reviewing code and designs for exploitable weaknesses. Improve security scanning workflows and support vulnerability triage and remediation across web and API services.
What they look for
Requirements
Requires a strong background in software engineering or application security with knowledge of web, API, and identity vulnerabilities. Candidates must demonstrate the ability to automate security checks within CI/CD pipelines and communicate effectively with product engineers.
Full description
On behalf of a partner company, Nordic Investin is looking for a Senior Application Security Engineer. You enjoy finding the design flaw before it becomes a production incident and helping engineers fix the pattern rather than only the instance.
The partner wants to embed application security more deeply in product delivery. You will work with developers on threat modelling, secure design, testing and remediation across modern web and API services.
Security work is expected to reduce real exposure while preserving the organisation’s ability to deliver. The strongest candidates can connect a technical weakness with a credible threat, an appropriate control and a practical path to implementation.
How you will work
You will work directly with the people who design, operate and depend on the systems being protected. Recommendations must identify the threat, the affected asset and a realistic implementation path. The partner values careful evidence, proportionate controls and clear escalation when risk cannot be removed immediately.
As a senior colleague, you will own substantial outcomes and help others make stronger decisions. You are expected to recognise risk early, communicate it without drama and move work forward with practical alternatives. The role still includes hands on delivery; seniority here means broader judgement, not distance from the work.
What you will do
- Facilitate threat modelling for new features and architectures.
- Review code and designs for exploitable weaknesses.
- Improve SAST, DAST and dependency scanning workflows.
- Develop secure coding guidance with practical examples.
- Support vulnerability triage and coordinated remediation.
- Teach teams through pairing, workshops and incident lessons.
What you will bring
- Strong software engineering or application security background.
- Knowledge of web, API and identity vulnerabilities.
- Experience with threat modelling and secure code review.
- Ability to automate checks within CI CD.
- Clear understanding of risk severity and exploitability.
- Constructive communication with product engineers.
Experience that would add value
- Cloud native application security.
- Mobile or embedded application security.
- Bug bounty, penetration testing or security research.
A background that can succeed here
You may be a developer who moved into security or a security specialist who can write and review production code. The partner needs technical depth and a style that makes engineering teams more capable, not more dependent.
What makes the opportunity interesting
The role gives you direct influence over products before release and the freedom to improve the security system around delivery. Your success will be visible in better designs, faster remediation and fewer repeated weaknesses.
The exact partner, employment model, compensation, start date and working arrangement will be explained openly during the process. Nordic Investin will make sure you understand the context, expectations and decision path before you are asked to commit significant time.
The recruitment conversation
During the process, Nordic Investin will focus on concrete decisions you have made: the context you received, the alternatives you considered, the result you observed and what you would change today. You do not need every optional technology if your core experience transfers and you can explain how you would close the gap.
How to apply
Apply with your CV or LinkedIn profile and a short note describing the most relevant system, product or transformation you have helped deliver. Nordic Investin welcomes candidates with different routes into technology and assesses applicants on relevant capability, judgement and potential.
Similar roles
-
DevSecOps/AppSec | Cybersecurity
Insside Ciberseguridad Buenos Aires, Argentina
-
OT/ICS Cybersecurity Consultant
Insside Ciberseguridad Buenos Aires, Argentina
-
Power BI Analyst | Cybersecurity Analytics
Insside Ciberseguridad Buenos Aires, Argentina
-
Enterprise Sales Account Manager – Cybersecurity Required at Delhi - ( Job ID - 24213)
EducoHire Delhi, India · ₹1M/yr
-
Lead Network Security Engineer
Unisys Bangalore, Karnataka, India
-
Senior Data Security Engineer - (Hybrid)
Allstate Belfast, Northern Ireland, United Kingdom