
Veritaz AB · Sweden
Vi söker en erfaren Application Security Coordinator som ska leda och samordna åtgärdandet av säkerhetssårbarheter samt driva processer för efterlevnad och riskminimering inom applikationssäkerhet.
Vi söker en erfaren Application Security Coordinator som ska leda och samordna åtgärdandet av säkerhetssårbarheter samt driva processer för efterlevnad och riskminimering inom applikationssäkerhet.
Veritaz is a leading IT staffing solutions provider in Sweden, committed to advancing individual careers and aiding employers in ensuring the perfect talent fit. With a proven track record of successful partnerships with top companies, we have rapidly grown our presence in the USA, Europe, and Sweden as a dependable and trusted resource within the IT industry.
Assignment Description
We are looking for an experienced Senior Application Security Coordinator
What You Will Work On
Coordinate remediation of findings from penetration tests and vulnerability assessments
Manage and track security findings through their complete lifecycle
Assess and prioritize vulnerabilities based on business risk
Coordinate remediation activities across business and technical teams
Work closely with application owners, infrastructure teams, and security stakeholders
Establish and maintain governance, reporting, and remediation processes
Monitor progress and ensure timely resolution of identified vulnerabilities
Facilitate communication between multiple stakeholders
Improve visibility and control of the organization's vulnerability landscape
Support compliance with internal security standards and external regulatory requirements
Drive continuous improvements in vulnerability management processes
Ensure effective collaboration across cross-functional teams
What You Bring
Experience working with Jira
Experience coordinating remediation of security findings
Strong ability to assess risks and prioritize remediation activities
Experience driving structured remediation and follow-up processes
Good understanding of application security and infrastructure security
Experience handling results from vulnerability scanning and penetration testing
Knowledge of CVE, CWE, and CVSS
Strong stakeholder management and communication skills
Experience coordinating work across multiple technical and business teams
Strong organizational and planning skills
Experience with security governance and reporting
Ability to work independently in complex environments
Analytical, structured, and proactive approach to problem-solving
Veritaz is a leading IT staffing solutions provider in Sweden, committed to advancing individual careers and aiding employers in ensuring the perfect talent fit. With a proven track record of successful partnerships with top companies, we have rapidly grown our presence in the USA, Europe, and Sweden as a dependable and trusted resource within the IT industry. Assignment Description We are looking for an experienced Application Manager – Payment Solutions What You Will Work On Manage and continuously improve existing Payment Solutions Take ownership of an existing payment platform and ensure stable operations Ensure continuity of previously implemented payment solutions Monitor and manage risks related to payment processing and PCI DSS compliance Act as the primary contact between business users, restaurants, and technology vendors Support application management for POS systems and payment infrastructure Drive continuous improvements within payment and checkout solutions Coordinate incident management and improve operational transparency Ensure proactive application management and service delivery Document processes, procedures, operational routines, and decisions Collaborate closely with application owners and external partners Support compliance, governance, and quality assurance activities What You Bring Experience managing Payment Solutions or payment platforms Strong knowledge of PCI DSS and payment card security regulations Good understanding of POS (Point of Sale) systems and payment infrastructure Experience from Restaurant, Retail, Commerce, or similar industries is highly desirable Ability to quickly understand and manage existing system implementations Experience working with multiple vendors and external partners Strong stakeholder management and communication skills Experience with application management and service management Ability to identify risks and drive proactive improvements Strong analytical and problem-solving skills Experience with incident management and operational governance Experience with drive-through systems, retail technology, or franchise environments is an advantage Understanding of franchise operating models is considered a plus Structured, proactive, and self-driven working style Fluent communication skills in business and technical environments
About the Team The Senior Manager of Application Security leads a global team responsible for embedding security into Miro’s Software Development Lifecycle (SDLC)—from concept to code to customer impact. This team partners closely with product and engineering to proactively mitigate risk while accelerating developer velocity and innovation.The role focuses on enabling secure-by-default development through secure design support, automated tooling, vulnerability management, offensive testing, and developer engagement. It also plays a critical role in integrating security into Miro’s Discover, Define, Deliver product lifecycle and aligning with our AMPED Ways of Working (Analytics, Marketing, Product, Engineering, Design) and AMPED Operating Model. As Miro embraces AI-supported software development and explores Agentic AI workflows that empower engineers, product teams, and security teams alike, this role will contribute to adapting and securing those evolving working methods—ensuring that innovation and trust go hand in hand. About the Role As Senior Manager of Application Security, you will define and operationalize Miro’s application security strategy in alignment with our industry-leading software development lifecycle and AMPED framework. You will lead a multidisciplinary team of application security engineers and offensive security specialists who work directly with developers, product teams, and platform engineering across multiple regions. You will embed security into all phases of the product lifecycle—from early discovery and architecture threat modeling, to design reviews and secure delivery pipelines, and ongoing monitoring and testing post-release. Your team will also support Miro’s AI-driven development tooling and guide secure adoption of Agentic AI workflows, which enable both developers and security teams to collaborate more efficiently and proactively. The role requires a pragmatic, hands-on leader who thrives in fast-moving environments and has a deep understanding of both software engineering and security, as well as a passion for empowering teams to build securely and autonomously. What you’ll do * Lead and mentor a globally distributed team of security engineers focused on application security, offensive testing, secure architecture, and vulnerability remediation. * Lead and coordinate the team's initiatives and help provide project management leadership to the team members. * Coordinate cross function and cross stream initiatives and projects. * Drive integration of security into Miro’s Discover, Define, Deliver lifecycle through the lens of the AMPED Ways of Working and Operating Model. * Collaborate with Product, Engineering, and Design to ensure security is considered at the earliest stages of ideation—via threat modeling, risk reviews, and abuse-case analysis.Shape and evolve Miro’s Secure SDLC practices, integrating security seamlessly into CI/CD pipelines, infrastructure-as-code, and developer tooling. * Oversee execution of bug bounty and third-party testing programs, ensuring vulnerabilities are triaged, communicated, and remediated effectively. * Build and scale Miro’s Security Champions program to embed security ownership within each engineering team. * Guide secure adoption of AI-augmented software development tools, including LLMs used for code generation, reviews, or architectural assistance. * Help envision and safely operationalize Agentic AI-driven developer and security workflows, including policy-driven autonomous agents supporting security automation and decision-making. * Provide structured guidance, patterns, and reference architectures that support developers in implementing secure, scalable, and privacy-respecting features. * Define and report on KPIs and success metrics for secure development adoption, vulnerability resolution, and developer engagement. * Collaborate with Privacy, Legal, and Compliance teams to ensure alignment with regulatory requirements (ISO 27001, SOC 2, GDPR, and emerging AI regulations). * Foster a strong team culture based on collaboration, learning, and continuous improvement. What you’ll need * 10+ years of experience in software, application, or product security, including significant experience in secure software development. * 3+ years of technical leadership or management experience in a security-focused role. * Extensive experience with threat modeling methodologies (e.g., STRIDE, PASTA) and risk assessment, particularly within a SaaS or product-centric organization. * Deep expertise in Secure Software Development Lifecycles (SSDLC), including integrating security into agile and custom development frameworks. * Demonstrated experience running Security Champions programs and scaling developer engagement. * Experience leading offensive security programs (penetration testing, red teaming, bug bounty). * Practical understanding of governance and assurance frameworks such as ISO 27001, SOC 2, and OWASP SAMM. * Familiarity with AI/LLM tooling (e.g., Cursor, GitHub Copilot, custom LLM integrations) and the associated security and governance considerations. * Experience working with AWS and securing API-driven, microservice-based architectures. * Ability to manage distributed teams and communicate effectively across technical and business stakeholders. Who You Are (Skills & Attributes) * Developer-Aligned: You understand the pace and pressure of modern software development and are committed to reducing friction while improving security posture. * An Exceptional Communicator: You can articulate complex technical risks to non-technical stakeholders and translate business goals into security strategy for your team. * A Natural Collaborator: You excel at building strong relationships and influencing cross-functional teams without direct authority. * A Pragmatic Problem-Solver: You are skilled at identifying scalable, risk-based solutions and are comfortable navigating ambiguity in a fast-paced environment. * Data-Driven: You use metrics and KPIs to measure the effectiveness of your programs and drive continuous improvement. * A Passionate Mentor: You are dedicated to developing talent and empowering engineers and product managers to be security champions. Why Join Miro’s Security Team? As a member of Miro’s security leadership, you’ll help define how innovation and trust scale together. You’ll work across the AMPED operating model, empower developers through secure tooling, and support cutting-edge AI-driven and agentic workflows that redefine how software and teams are built. If you thrive on technical depth, cross-functional collaboration, and advancing the next era of secure software development, this role is for you. What's in it for you We want you to feel supported, connected, and ready to grow. Our global benefits package generally includes equity, a wellbeing benefit, a WFH equipment allowance, and an annual Learning & Development stipend. Join a diverse team where you can do your best work. Full benefits may differ per location. If you would like to learn more about location-specific benefits, please refer to our Global Miro benefits board.
WHY WE NEED YOU The Security Engineering Manager owns Maltego’s operational security function and leads the team that protects our infrastructure, product, and corporate environment. This is a hands-on technical role combined with people leadership You will run detection and incident response, harden our multi-cloud and endpoint estate, embed security into engineering workflows, and build the practices and team that scale with the company. You act as the technical authority for operational security while partnering closely with Engineering, Corporate IT, and our Governance, Risk & Compliance (GRC) function. Reporting initially to the Head of Infrastructure & Operations, you set operational security direction independently and translate risk into concrete, prioritized action. Success in the first phase means a well-instrumented and measurable security posture, reliable incident response, and a team operating to clearly defined technical standards. WHAT TO EXPECT Key Responsibilities: * Own detection, triage, and resolution of security incidents across cloud, product, and corporate environments – ensuring fast, reliable response and continuously improving incident response playbooks and tooling (Microsoft Sentinel, Microsoft Defender). * Own operational security monitoring across the multi-cloud estate (Azure as primary, plus AWS and GCP), tuning detections, alerting, and response workflows for fast and reliable threat handling. * Drive vulnerability management end-to-end – coordinating scanning, prioritization, and remediation tracking with Nessus and Snyk in partnership with Engineering. * Define security baselines and secure-by-default standards, and embed them into the software development lifecycle and infrastructure, integrating tooling such as Snyk into engineering workflows. * Manage endpoint and identity security across Windows and macOS fleets using Microsoft Intune, Defender, and Purview, ensuring consistent hardening and data protection. * Build and lead the operational security team – line-managing and mentoring engineers, contractors, and working students toward clear technical and delivery standards. * Plan and deliver security awareness and enablement across the organization, including onboarding content and phishing simulations, translating risk into plain language for non-technical audiences. * Partner with the AI transformation team to engineer security guardrails and monitoring for the responsible use of AI across the organization. YOUR PROFILE IN SHORT Required Qualifications (Must Have) * 5+ years in security operations or security engineering, preferably in a SaaS or B2B software environment. * Experience owning security outcomes or domains end-to-end (not only contributing to them). * Hands-on incident detection and response experience, including SIEM (Microsoft Sentinel), EDR/XDR (Microsoft Defender), and cloud security monitoring. * Strong technical fluency across multi-cloud infrastructure (Azure primary; AWS and GCP) and endpoint/identity management (Microsoft Intune, Windows, macOS). * Experience with vulnerability management and developer security tooling such as Nessus and Snyk, including coordinating remediation with engineering teams. * Proven ability to define and embed security baselines and secure-default standards into engineering and infrastructure. * Proven people leadership experience, including setting expectations, developing engineers, and holding teams accountable for delivery and technical quality. * Clear communicator able to translate security risk into plain language for engineers and non-technical stakeholders. * Comfortable acting as the primary operational security practitioner, setting technical direction independently while collaborating with a separate GRC function. * Professional proficiency in English. Preferred Qualifications (Nice to Have) * Experience producing audit evidence for ISO 27001 / SOC 2 control operation and working with compliance automation platforms such as Vanta. * Experience with Microsoft Purview for data security, DLP, or information protection. * Relevant certifications such as CISSP, CISM, or Azure security certifications (e.g., AZ-500 / SC-200, SC-900), GIAC certification (GCIH, GCIA). * Experience in engineering security guardrails or monitoring for AI / LLM usage. * Experience in a scale-up or growth-stage company where security functions are being built rather than inherited. * Professional proficiency in German ABOUT THIS OPENING Team & Leadership This is a people-management position. You will begin by coordinating external contractors and working students, and are expected to lead a dedicated operational security team as Maltego scales – owning hiring, development, and performance for your direct reports while remaining hands-on technically. Current Environment (you will shape and evolve this) Cloud: Azure (primary), AWS, GCP. Detection & response: Microsoft Sentinel (SIEM), Microsoft Defender (EDR/XDR). Data & endpoint: Microsoft Purview, Microsoft Intune, Windows and macOS. Application & vulnerability security: Snyk, Nessus. Compliance automation: Vanta. WHY YOU WILL LOVE MALTEGO Here are some of the reasons why you will love Maltego: * Insights into the daily operations of a fast-growing tech scale-up. * Competitive compensation with a bonus/commission structure based on pipeline creation. * Inclusive, diverse culture, where your voice and contributions matter. * Supported language courses * Mental health support via .nilo (psychologists & digital tools) At Maltego, we are committed to supporting diversity and inclusion in our organization. We are an equal opportunity employer. We welcome applications from all individuals regardless of race, religion, color, nationality, gender, sexual orientation, age, or disability. LOCATION Our Munich office REQUIRED DOCUMENTS / INFORMATION Please submit a CV and cover letter detailing your experience and motivation for joining Maltego!