7 часов назад
Enterprise Security Services Lead (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Enterprise Security Services Lead (Cybersecurity): Leading enterprise vulnerability management, application security, third-party risk, penetration testing, and secure software supply chain practices with an accent on DevSecOps, CI/CD integration, and code-signing governance. Focus on coordinating remediation, red-team activities, supplier security assessments, and security maturity improvements across infrastructure, applications, and external providers.
Location: Based in Norway at the Oslo (Lysaker), Stavanger, or Vindafjord (Nedre Vats) offices, or remote from Switzerland
Company
is a Norwegian multinational experiencing rapid growth and listed on the Oslo Stock Exchange.
What you will do
- Own and develop enterprise vulnerability management capabilities across servers, endpoints, networks, and applications.
- Integrate vulnerability management with tooling, scanning, reporting, SDLC, DevSecOps, and CI/CD processes.
- Lead third-party and supply chain security, including supplier assessments, due diligence, continuous monitoring, SBOM governance, and open-source risk management.
- Coordinate penetration testing and Red Team activities, remediation, and retesting.
- Support code-signing services, certificate and key management, software integrity, and trusted release processes.
- Work with Risk, technical teams, internal stakeholders, and external providers to improve security maturity and track risk indicators.
Requirements
- 10+ years of cybersecurity experience, including 5+ years in a senior or leading role in application security, vulnerability management, or security assurance.
- Strong experience with enterprise vulnerability management, application security, penetration testing, and third-party or supplier security.
- Hands-on experience implementing DevSecOps and secure software development practices in CI/CD environments.
- Understanding of security frameworks, testing methodologies, OWASP, NIST, SAST, DAST, SCA, API security, cloud security, software supply chain security, and PKI or code signing.
- Experience with cloud environments such as Azure, AWS, or GCP.
Nice to have
- CISSP, CSSLP, OSCP, or GIAC certification.
Culture & Benefits
- Collaborative and inclusive culture that values diverse perspectives.
- Focus on mental and physical well-being and work-life balance.
- Creative and safe workplace within a rapidly growing company.
- International and supportive environment within a Norwegian multinational.
- Structured onboarding and career opportunities within the company.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →