AutoStore AS

AutoStore AS

Enterprise Security Services Lead

OsloPosted 7 days ago
Full TimeSeniorNO

See how this job matches your profile

Sign in for an AI-powered fit score, breakdown, and a tailored resume.

Sign in

Job Description

We are looking for an Enterprise Security Services Lead to oversee and coordinate security across our enterprise infrastructure, applications, and third-party ecosystem. You will drive vulnerability m

Key Highlights

  • Own and develop our enterprise vulnerability management capabilities, including vulnerability tooling, scanning, data integrations, reporting, and integration with SDLC, DevSecOps, and CI/CD processes.
  • Work with Risk and technical teams to identify and prioritise vulnerabilities, define remediation plans, track key risk and performance indicators, and coordinate remediation across the organisation.
  • Lead third-party and supply chain security, including supplier risk assessments, security due diligence and continuous monitoring, as well as software supply chain practices such as SBOM governance and open-source risk management.
  • Lead penetration testing and Red Team activities, ensuring testing reflects business risks and relevant threats, and coordinate remediation and retesting of identified vulnerabilities.
  • Support code-signing services and governance, ensuring secure certificate and key management, software integrity, and trusted release processes across development teams.

Qualifications

Required Qualifications

  • 10+ years of cybersecurity experience, including 5+ years in a senior or leading role within application security, vulnerability management, or security assurance.
  • Strong experience with enterprise vulnerability management and application security, including penetration testing and third-party/supplier security.
  • Hands-on experience implementing DevSecOps and secure software development practices, including security integration within CI/CD environments.
  • Good understanding of relevant security frameworks, testing methodologies, and technologies, such as OWASP, NIST, SAST/DAST/SCA, API and cloud security, software supply chain security, and PKI/code signing.
  • Experience working with cloud environments such as Azure, AWS, or GCP. Relevant certifications such as CISSP, CSSLP, OSCP, or GIAC are an advantage.

Skills & Technologies

CI/CDAzureAWSGCP

Interested in this role?

Sign in or create a free account to see how this job matches your skills, apply with one click, and let our AI tailor your resume.

Sign in to apply
AI-powered resume optimization
Save and track your applications

Job Details

Employment Type

Full Time

Experience Level

Senior

Location

Oslo

Posted

7 days ago

Country

NO