4 months ago
Copenhagen, DenmarkSenior
Responsibilities
- Build SDLC security checks for unsafe queries, secrets in code, credential handling, dependencies, static analysis, and pipeline identity.
- Establish secure data-access, browser-side credential-handling, and memory-safe handling patterns.
- Create automated drift detection for previously secured product surfaces and provide actionable signals to owning teams.
- Build intake and tracking systems for penetration-test findings, including classification and SLA tracking.
- Develop documentation, self-service tooling, secure-by-default patterns, threat-modeling practices, and security-review processes.
- Automate product-security control evidence for GRC and collaborate with Platform, Product, IT, Firmware, and GRC teams.
Requirements
- Several years of production software engineering experience with full SDLC understanding.
- Practical experience identifying and fixing SQL injection, unsafe query patterns, secrets in code, and unsafe browser credential handling.
- Generalist experience across backend, frontend, and their integration points.
- Experience contributing to internal tooling used by engineering teams and measuring its developer-productivity impact.
- Familiarity with adding security feedback to build and deployment pipelines without unnecessary friction.
- Strong collaboration, documentation, problem-solving, and communication skills.
- Experience with SAST or DAST tooling, dependency scanning, supply-chain security, SLSA, signing, or security reviews for cloud-native applications is preferred.
Benefits
- Copenhagen-based role with access to an office featuring an indoor ball court, rooftop terrace, and equipped gym.
- Collaborative work with a Security Enablement Team and teams across the organization.
- The team builds shared tooling and golden paths and does not operate a SOC or carry a security pager.
