Cyber Instincts AB

Cybersecurity Specialist

Cyber Instincts AB Stockholm Municipality, Sweden

IT Services and IT Consulting · 2-10 employees

7 h ago
security Senior (5-10 yrs) Full-time Sweden
Create a free account to apply — email only, no card. You can also save this posting or score it against your profile with AI.

About the role

The specialist will act as a bridge between cybersecurity and technical development, ensuring security is integrated from the design phase through to implementation. Key tasks include managing CRA compliance, performing risk assessments, conducting security testing, and overseeing vulnerability management.

What they look for

Cybersecurity Risk assessment Security testing Threat modeling Source code review System hardening Secure development lifecycle Vulnerability management Embedded systems Firmware C C++ VHDL Assembler Real-time operating systems C#

Requirements

The ideal candidate possesses a solid foundation in cybersecurity within product development, specifically in software, system architecture, or embedded systems. Proficiency in languages like C/C++ and experience with secure development lifecycles and threat modeling are highly valued.

Full description

Are you the kind of person who builds security into products from the ground up, rather than bolting it on afterward? We're looking for a cybersecurity specialist to join an industrial product development team in Västerås.

The role in short

You'll act as the bridge between cybersecurity and the technical development organization. On a day-to-day basis, you'll work closely with software developers, system architects, and other technical profiles to make sure security is built in from the design phase onward. A particular focus of the assignment is navigating the new requirements under the EU Cyber Resilience Act (CRA) and turning them into concrete, everyday actions within the development work.

What you'll be working on

  • Mapping out where the organization currently stands on cybersecurity and charting the path toward CRA compliance
  • Risk-assessing products and making sure actions are actually implemented, not just documented
  • Owning and coordinating security work within development projects – being the person who holds the whole picture together
  • Planning and running various types of security testing
  • Mapping attack surfaces and building threat models for the products
  • Reviewing source code with a security lens
  • Contributing to system hardening, including image management for Windows environments
  • Making sure teams follow a secure development lifecycle (SDLC) and identifying ways to improve it
  • Being involved when security requirements are defined for new features
  • Developing and implementing concrete security solutions, for both embedded systems and traditional applications
  • Driving vulnerability management – from discovery to remediation
  • Writing the documentation that's needed: architecture descriptions, processes, agreement materials
  • Preparing development teams ahead of security reviews
  • Keeping an eye on emerging threats, vulnerabilities, and security updates
  • Reviewing how well suppliers live up to the security requirements set for them
  • Acting as a point of contact for both local and global security functions

Who are we looking for?

We think you have a solid foundation in cybersecurity tied to product development – ideally with roots in software development, system architecture, or embedded systems. You're comfortable stepping into development teams and giving hands-on support, not just delivering reports. Since the role involves a lot of collaboration – both locally and internationally – you need to be confident communicating with many different types of technical profiles.

It's an extra plus if you have experience with any of the following:

  • Embedded systems and firmware
  • C / C++
  • VHDL / Assembler
  • Real-time operating systems (RTOS)
  • C# / Java
  • Windows environments and Windows-based applications
  • Secure architecture and implementation
  • Vulnerability management and security testing

If you've also worked practically with CRA, IEC 62443, secure development lifecycle, threat modeling, or security architecture – great, but it's not a requirement to reach out.

The assignment

  • Location: Västerås, on-site
  • Start: October 12, 2026
  • Duration: through March 31, 2027
  • Scope: Full-time

Similar roles