Senior Application Security Engineer

Nordic Investin GroupStockholm, ME

About The Position

On behalf of a partner company, Nordic Investin is looking for a Senior Application Security Engineer. You enjoy finding the design flaw before it becomes a production incident and helping engineers fix the pattern rather than only the instance. The partner wants to embed application security more deeply in product delivery. You will work with developers on threat modelling, secure design, testing and remediation across modern web and API services. Security work is expected to reduce real exposure while preserving the organisation’s ability to deliver. The strongest candidates can connect a technical weakness with a credible threat, an appropriate control and a practical path to implementation. How you will work You will work directly with the people who design, operate and depend on the systems being protected. Recommendations must identify the threat, the affected asset and a realistic implementation path. The partner values careful evidence, proportionate controls and clear escalation when risk cannot be removed immediately. As a senior colleague, you will own substantial outcomes and help others make stronger decisions. You are expected to recognise risk early, communicate it without drama and move work forward with practical alternatives. The role still includes hands on delivery; seniority here means broader judgement, not distance from the work. What makes the opportunity interesting The role gives you direct influence over products before release and the freedom to improve the security system around delivery. Your success will be visible in better designs, faster remediation and fewer repeated weaknesses.

Requirements

  • Strong software engineering or application security background.
  • Knowledge of web, API and identity vulnerabilities.
  • Experience with threat modelling and secure code review.
  • Ability to automate checks within CI CD.
  • Clear understanding of risk severity and exploitability.
  • Constructive communication with product engineers.

Nice To Haves

  • Cloud native application security.
  • Mobile or embedded application security.
  • Bug bounty, penetration testing or security research.

Responsibilities

  • Facilitate threat modelling for new features and architectures.
  • Review code and designs for exploitable weaknesses.
  • Improve SAST, DAST and dependency scanning workflows.
  • Develop secure coding guidance with practical examples.
  • Support vulnerability triage and coordinated remediation.
  • Teach teams through pairing, workshops and incident lessons.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service