At Trustly, we're passionate about simplifying the way people transfer, pay, and get refunded online. Our payment solutions serve merchants in various industries. This includes E-com, Financial Services, Gaming and Travel - linking the world's top brands with millions of consumers who expect security and convenience.
Our people are from all corners of the globe, and this we're proud of. We strongly believe that diversity is what helps us create solutions that are more inclusive. Making sure that we're constantly innovating. Our fast-growing team is headquartered in Stockholm, Sweden with additional offices across Europe and the Americas. Together, we are modernizing payments and the work you'll do here will make a lasting impact.
About the team
As part of fulfilling the objective of becoming the leading global online banking payments provider, we are strengthening our capability in the information and cyber security area. Currently, we are restructuring our internal setup within the security area allowing us to scale and grow our teams. To get us going we are now looking for additional Security Engineers to join the team focusing on our product security in Europe.
About the role
As a Security Engineer at Trustly, you will be part of a team of security professionals ensuring security lies in the core of everything we build and operate. We combine our expertise in providing security services to the organization with automating security controls wherever and whenever possible. As our team is undergoing an expansive phase, you will have the opportunity to shape our direction and methodologies. Your contributions will be important in refining our interactions with merchants, allowing you to leave a large impact on our operational security framework.
What you'll do
Ensure our vulnerability management program maintains coverage of all applicable assets, by building automation that makes sure our tools are up to date and supports our teams to keep our software securePerform security assessments and provide security guidance of the product we build through design reviews, code reviews as well as performing dynamic testing, working closely with the development teamsResearch and implement security controls on top of the CI/CD pipelineDesign and execute internal penetration testing activitiesCompromise our hosts and data with exploitation of vulnerabilities to assess actual risks involved and understand what controls that failed to protectProactively gather threat intelligence and build tools that enable us to identify and act on external threats efficiently and intelligently
Who you are
You have spent a few years in the area of cyber security doing hands-on technical security workDetailed technical knowledge of techniques, standards and state-of-the art capabilities for authentication and authorisation, applied cryptography, security vulnerabilities and remediationDNS, TLS, X.509, CVEs and SOAR/SIEM systems are no strangers to youExperience from hands-on technical security assessments such as penetration tests, web application tests, code reviews etc.Passionate about working with application developers in "shifting left", introducing security controls early on in the development processAny security certification (e.g. OSCP, OSWE or similar), Bachelor/Masters/PhD degree in Computer Science or Cybersecurity is considered a plus
We are looking for someone who is not afraid of voicing and acting on new ideas and values good communication with internal and/or external stakeholders. If you are passionate about working with different areas across the organization, then this would be an interesting role for you.
Apply now, we would love to talk to you!