Apply Edge Start your job search

Senior DevSecOps Engineer

Northbridge · Stockholm, Stockholm County, Sweden

Apply & track with Apply Edge

About the jobAs a Senior DevSecOps Engineer at Northbridge Security, you'll lead security and platform work in client engagements, from architecture to implementation. You set the direction for how security is built into the delivery flow, and you make sure the client's team can own it after you leave.Northbridge Security helps organisations in regulated industries, including life sciences, medical technology and finance, ship software quickly without compromising on security or compliance. We work across cloud, DevSecOps and AI governance, and we run the same controls we recommend to our clients.What you will doDesign DevSecOps architecture, security baselines and standards for client cloud and delivery platformsBuild CI/CD pipelines with built in controls: SAST, SCA, secrets, container and IaC scanning, and SBOM generationAutomate compliance checks and evidence collection, so audits become a byproduct of deliveryArchitect landing zones, identity and access based on Zero Trust and least privilegeLead threat modelling, security reviews and incident responseBuild developer platforms and golden paths where the secure choice is also the easy oneAdvise client technical leadership and coach their teamsWhat we are looking forAt least 10 years in DevOps, platform, infrastructure or security roles, several of them with a clear security focusExperience establishing DevSecOps practices in one or more organisationsArchitect level experience with AWS and/or Azure, plus hands on experience with Kubernetes and Infrastructure as CodeExperience integrating security tooling into pipelines, from SAST and SCA to container and IaC scanningAbility to turn frameworks such as ISO 27001, CIS Benchmarks or NIST into automated controlsComfortable in front of clients, explaining a risk to both a developer and a CISO, fluent in Swedish and EnglishNice to haveSpecific tooling such as Terraform, Pulumi, Bicep, AWS CDK, GitHub Advanced Security/CodeQL, Semgrep, Snyk, Trivy or WizExperience from regulated environments: GxP, medical device software (SaMD), HIPAA, DORA, PCI DSS or SOC 2Experience leading audits or regulatory submissionsExperience with SOC capabilities, SIEM/SOAR and observabilityCertifications such as AWS Solutions Architect or DevOps Engineer Professional, AWS Security Specialty, Azure Solutions Architect or DevOps Engineer Expert, CISSP or CCSPExperience securing AI assisted development workflowsWhy Northbridge SecuritySenior colleagues who build what they recommendA focus on architecture and principles rather than individual toolsVariety: SMB and enterprise clients at different levels of maturityBenefits and compensation model (80/20, 70/30, 70/25)How to applyThe first interview is with our Head of Business, followed by a technical interview focused on security. We review applications continuously.