Security Engineer
Stockholm, Sweden
Product & Tech - Europe – Tech Foundation - Europe /
Full-time /
Hybrid
Trustly is leading the human-centric payments revolution. To us, this means passionately building the most convenient, intelligent and responsible way of paying for things online. Whether it’s for shopping, paying subscriptions, funding trading accounts, booking airfare, playing online games and much more – we’re all about a better way to pay. At our core, we are a tech company with industry-leading tech capabilities. But, it’s the ingenuity of our people that makes us leaders in our field. Thus, our appetite for innovation will never be anything less than fierce. Trustly is steadily growing as it connects thousands of businesses with hundreds of millions of people. And with a strong presence across Europe and the Americas, we are leading the human-centric payment revolution as a truly global team.
About the team
As part of fulfilling the objective of becoming the leading global online banking payments provider, we are strengthening our capability in the information and cyber security area. Currently, we are restructuring our internal setup within the security area allowing us to scale and grow our teams.
To get us going we are now looking for additional Security Engineers to join the Security and Compliance team focusing on our product security in Europe.
About the role
As a Security Engineer at Trustly, you will be part of a team of security professionals ensuring security lies in the core of everything we build and operate. We combine our expertise in providing security services to the organization with automating security controls wherever and whenever possible.
As our team is undergoing an expansive phase, you will have the opportunity to shape our direction and methodologies. Your contributions will be important in refining our interactions with merchants, allowing you to leave a large impact on our operational security framework.
What you’ll do
- Ensure our vulnerability management program maintains coverage of all applicable assets, by building automation that makes sure our tools are up to date and supports our teams to keep our software secure
- Perform security assessments and provide security guidance of the product we build through design reviews, code reviews as well as performing dynamic testing, working closely with the development teams
- Research and implement security controls on top of the CI/CD pipeline
- Design and execute internal penetration testing activities
- Compromise our hosts and data with exploitation of vulnerabilities to assess actual risks involved and understand what controls that failed to protect
- Proactively gather threat intelligence and build tools that enable us to identify and act on external threats efficiently and intelligently
Who you are
- You have spent a few years in the area of cyber security doing hands-on technical security work
- Detailed technical knowledge of techniques, standards and state-of-the art capabilities for authentication and authorisation, applied cryptography, security vulnerabilities and remediation
- DNS, TLS, X.509, CVEs and SOAR/SIEM systems are no strangers to you
- Experience from hands-on technical security assessments such as penetration tests, web application tests, code reviews etc.
- Passionate about working with application developers in "shifting left", introducing security controls early on in the development process
- Any security certification (e.g. OSCP, OSWE or similar)
- Bachelor/Masters/PhD degree in Computer Science or Cybersecurity is considered a plus
Kindly submit your application and CV in English.
Kindly submit your CV in English.
Are you someone who voices new ideas and acts on them? Do you value great communication with all stakeholders? We are looking to strengthen the team with dedicated, highly motivated people who thrive in working with different areas across the organisation.
If you feel that your skill set and personality compliments the criteria above, please apply now.