Enterprise Security Services Lead
Indexed description
The role also covers application and third-party security, working with internal teams and external service providers to strengthen secure development practices, manage security testing and remediation, and ensure suppliers and integrations meet our security requirements. This is a highly cross-functional role where you will coordinate security activities across multiple stakeholders and drive improvements in processes, tooling, and security maturity.
Job Responsibilities:
Enterprise Vulnerabilities
- Own and develop our enterprise vulnerability management capabilities, including vulnerability tooling, scanning, data integrations, reporting, and integration with SDLC, DevSecOps, and CI/CD processes.
- Work with Risk and technical teams to identify and prioritise vulnerabilities, define remediation plans, track key risk and performance indicators, and coordinate remediation across the organisation.
- Lead third-party and supply chain security, including supplier risk assessments, security due diligence and continuous monitoring, as well as software supply chain practices such as SBOM governance and open-source risk management.
- Lead penetration testing and Red Team activities, ensuring testing reflects business risks and relevant threats, and coordinate remediation and retesting of identified vulnerabilities.
- Support code-signing services and governance, ensuring secure certificate and key management, software integrity, and trusted release processes across development teams.
- 10+ years of cybersecurity experience, including 5+ years in a senior or leading role within application security, vulnerability management, or security assurance.
- Strong experience with enterprise vulnerability management and application security, including penetration testing and third-party/supplier security.
- Hands-on experience implementing DevSecOps and secure software development practices, including security integration within CI/CD environments.
- Good understanding of relevant security frameworks, testing methodologies, and technologies, such as OWASP, NIST, SAST/DAST/SCA, API and cloud security, software supply chain security, and PKI/code signing.
- Experience working with cloud environments such as Azure, AWS, or GCP. Relevant certifications such as CISSP, CSSLP, OSCP, or GIAC are an advantage.
- A Collaborative & Inclusive Culture where we celebrate and value everyone’s contributions, encouraging diverse perspectives in decision-making.
- Work-Life Balance & Well-being: prioritizing your mental and physical well-being.
- A Creative and Safe Workplace by joining a company experiencing rapid growth, with the stability of being Norway’s first unicorn listed on the Oslo Stock Exchange.
- International and Supportive Environment within a Norwegian multinational that values collaboration and innovation with a structured onboarding plan and career opportunities within the company
AutoStore does not accept agency resumes or assistance for this role. Please do not forward resumes to our job's alias or AutoStore employees. AutoStore is not responsible for any fees related to unsolicited resumes. This policy should be respected.
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search