We're looking for a Senior Security Engineer to join our Security team in Helsinki HQ.
In this role, you will... Work closely with product development to embed security best practices across the entire software development lifecycle and ensure security of our products.
In collaboration with the cloud infrastructure team improve security of our cloud infrastructure by improving existing and implementing new security controls.
Have a high level of autonomy in your daily work to improve our security posture.
Your day-to-day work and responsibilities include...
Security Engineering & Architecture: Design, implement, and maintain security controls across our SaaS platform and internal infrastructure. This includes automating vulnerability and threat detection (SAST, SCA, IAC, container image analysis), ensuring robust audit logging via SIEM, implementing and managing IAM policies, and continuously identifying and mitigating security risks.Reviews and Assessments: Do internal reviews, threat modeling and testing of new product features. Use automated tools and manual code review to find security issues in software and infrastructure.
Collaboration & Communication: Collaborate closely with development and operations teams to integrate security into the Software Development Life Cycle (DevSecOps). Champion a security-first culture, embedding security principles into all aspects of our operations and product development.
Security Automation: Improve our existing security tooling in CI / CD and add new tools. Implement automated threat detection and policy-as-code solutions to detect possible data breaches and insecure configurations.
This position is for you if you have at least...3+ years of full-time experience in information security and in total at least 5 years of full-time work experience in e.g. software development.
Expertise in securing cloud infrastructure in AWS, GCP or Azure.
Basic knowledge of Kubernetes and securing Kubernetes clusters and containerized