
Coretura AB · Sweden
THE VISION We build a production-grade platform running in commercial vehicles on public roads, delivering hardware, middleware, connectivity, OTA update capab...
We build a production-grade platform running in commercial vehicles on public roads, delivering hardware, middleware,
connectivity, OTA update capabilities, and an AI first development experience that must work flawlessly every day, in the office
and in the field, at scale, for years after production. Security is not a feature here. It is a foundational property of
everything we build.
This is a senior security leadership role reporting to the CDO, with genuine breadth across cloud, product, and enterprise
security. You will build and lead the Security Hub, a cross-functional centre of excellence that anchors cybersecurity across the
domains Coretura operates in. You will lead off-board and enterprise security directly and coordinate closely with the onboard
vehicle cybersecurity organisation to ensure a coherent, end-to-end security posture.
that connect vehicles to the outside world
You coordinate with the onboard vehicle cybersecurity organisation on:
safety-critical ASIL partitions to the external connectivity boundary
You also establish and lead a Security Community of Practice, the connective tissue that spreads security thinking across vehicle,
cloud, and enterprise domains.
Coretura is a product company, not a systems integrator or project house. That distinction matters enormously for security. Our
platform ships to multiple global OEMs and runs in the field for years. Every security decision we make, or fail to make, has
consequences at scale, long after delivery. The Security Hub exists to ensure that security is designed in from day one, that
compliance is traceable without drowning engineers in process, and that our platform becomes a competitive differentiator rather
than a liability.
You will own our ISMS and CSMS, govern our Asset → Threat → Control → Implementation → Evidence model, and ensure security tooling
integrates directly into how engineers already work, using the same Sphinx-needs toolchain as our product documentation. Security
here must be lean, auditable, and real.
Converging regulations, GDPR, ISO 26262, and many more apply simultaneously. Our policy with everything as code is a blessing but
also adds friction.
Cross-domain attack surface. Cloud and vehicle security are inseparable, requires technical depth and cross-team alignment.
Supply chain risk. Keep curation policies sharp: block malicious packages, flag CVEs, monitor aged dependencies.
OEM demands. Negotiate Cybersecurity Interface Agreements and turn security architecture into hardware procurement requirements.
Incident response. Our security incident response team and system must meet UN R155 timelines and OEM contracts, ready before an
incident.
A security generalist with depth in at least two of the domains above. You can read a cloud architecture diagram and a TARA and
have a view on both. You understand that compliance without engineering is theatre, and engineering without compliance is
liability.
Experience with ISO/SAE 21434, UN R155/R156, and ISO 27001 in a product company context is essential. Automotive background is a
strong advantage. Comfort with AWS/Azure, DevSecOps, and software supply chain security is expected.
Most importantly: you are motivated by the mission. Safe, secure vehicles on the road. That is what this work is for.
It is completely understandable if you want to know more before putting yourself out there. Generate and apply with your
anonymized resume and hidden mail here. This means we will review your profile without knowing your identity, and keep the initial
dialogue to an untraceable mail address.
Tech Innovation at Apotea Apotea is Sweden’s largest online pharmacy, committed to making healthcare products accessible and efficient for everyone. Our Tech department aims to redefine how AI and automation drive modern businesses — not by forcing AI into traditional workflows, but by creating AI-driven systems that give humans control, insight, and the ability to apply their expertise where it matters most. The Core Technology team builds the architectural foundation supporting e-commerce, logistics, data, AI/ML, and customer experience. We ensure all development aligns with our long-term vision and contributes to Apotea’s growth. We are now looking for a Lead Security Engineer to take full ownership of Apotea’s security strategy, ensure compliance, and enable teams to build and innovate securely at scale. The Role As Lead Security Engineer, you will define, implement, and evolve security practices across AWS (serverless-first), e-commerce, logistics, and data platforms. The role combines strategic leadership with hands-on engineering — you will implement security yourself while empowering others to do so. You will act as the first-line technical security lead, defining guardrails, monitoring risks, and leading incident response. You will develop secure practices for coding with AI assistants, ensuring generated code meets security standards, avoids data leakage, and aligns with regulations. You will also communicate complex security concepts clearly across the organization. Location: Sveavägen 168, Stockholm, Sweden (On-site) Key Responsibilities Security Leadership * Own and evolve Apotea’s security strategy across cloud, applications, and infrastructure. * Translate business and regulatory requirements into sustainable security practices. * Define guardrails, best practices, and reference implementations for teams. Hands-On Security Engineering * Design and implement secure AWS serverless and data-driven systems. * Lead IAM practices, enforcing least-privilege and zero-trust. * Oversee vulnerability management, penetration testing, and patching. * Ensure secure DevSecOps pipelines and IaC security. Monitoring & Incident Response * Build and operate monitoring, detection, and alerting systems (SIEM, EDR, GuardDuty, Security Hub). * Lead incident response: investigate, contain, and recover from security events. * Maintain and test playbooks for emerging threats. Governance & Compliance * Ensure GDPR, healthcare regulations, and industry standards compliance. * Embed security and privacy by design across development. * Partner with legal, compliance, and business units for regulatory readiness. * Provide training and frameworks for safe AI usage without compromising security. Collaboration & Culture * Work closely with engineers, architects, and product teams to integrate security early. * Mentor engineers in secure coding and infrastructure practices. * Advocate for a strong security culture. Qualifications * Extensive experience as a security engineer and organization’s main security expert. * Proven expertise in securing AWS (IAM, networking, serverless, encryption, monitoring). * Strong background in designing secure, scalable, cloud-native systems. * Hands-on experience with SIEM, EDR, vulnerability scanners, secrets management. * Deep knowledge in DevSecOps and IaC (CDK, Terraform, CloudFormation). * Programming/scripting skills: Go, TypeScript, .NET, Python, or similar. Nice to Have: experience in regulated industries, compliance frameworks (ISO 27001, NIST, PCI-DSS), or red/blue team operations. Why Join Apotea? * Stable company with a meaningful mission: improving healthcare accessibility. * Work on cutting-edge AI, ML, and automation impacting millions of customers. * Modern cloud-native technologies (serverless, AI, event-driven). * Flat, agile organization with minimal bureaucracy. * Career growth through training, mentorship, and conferences. * End-to-end project ownership from concept to deployment. * Culture of experimentation, collaboration, and innovation. About Apotea Apotea.se is Sweden’s largest online pharmacy, with the country’s broadest range of over 32,000 non-prescription items and nearly 19,000 prescription drugs for humans and animals. Recognized as Sweden’s most sustainable e-commerce company (Sustainable Brand Index 2021), we simplify everyday life for our customers with fast deliveries and expert advice. In 2024, Apotea reached a turnover of SEK 6.5 billion and currently employs about 1,000 people across Stockholm, Lidingö, and Morgongåva. Apotea is an inclusive employer that values diversity. We welcome all applicants and strive to create a work environment where people, regardless of background, gender, age, religion, or disability, can thrive and grow. Recruitment Process 1. Apply 2. Interview: Screening 3. Interview: Technical Capabilities 4. Interview: Culture Fit 5. Background Check: As a pharmacy, we always conduct a background check. 6. Offer Presented Application Do not hesitate to send in your application already today. For more information or questions, visit our career page or contact us at jobb@apotea.se. We do not accept applications via email. LinkedIn Instagram Join Us and Make a Difference - We hope you want to be a part of our team! Submit your application today—interviews are conducted on an ongoing basis, and the position may be filled immediately. Start date by agreement. Welcome to Apotea – where technology meets health and creates magic!
The Company Cubic³ provides advanced software-defined vehicle solutions to over 200 countries around the world. Our powerfully smart connectivity enables leading automotive, agriculture, and transportation OEMs to deliver innovative new services and fully compliant in-vehicle experiences that customers desire, regardless of local market requirements. We believe in leadership that supports empowerment and responsibility, while recognising and developing leadership qualities across Our Team. Together we bring out the best in each other. So, whether you’re interested in joining us as an individual contributor, manager, senior leader – or someone who aspires to growing into a leadership role – we look for people who are results focused, empathetic, visionary, empowering, and who ‘champion’ our cultures and values. Role Overview Responsible for leading the design, implementation, and continuous improvement of security engineering practices across cloud, on-premise, and hybrid environments. This role drives security-by-design principles, DevSecOps integration, Cloud and platform hardening, while providing technical leadership across the organisation. Key Responsibilities * Define and implement security-by-design principles across cloud, on-premise, endpoint, and network environments * Embed security into CI/CD pipelines (DevSecOps) in collaboration with engineering and DevOps teams * Conduct and lead security risk assessments, ensuring mitigation strategies are implemented across new applications, platforms, and third-party tools * Own and enhance cloud, platform, and endpoint security posture, including monitoring for configuration drift and vulnerabilities * Develop and enforce hardening standards across endpoints (Windows/macOS), servers, and compute environments * Support and partner with teams across IAM, GRC, DLP, SOC, and Vulnerability Management to strengthen overall security capability * Own and manage security tools related to the role and discipline e.g. SAST Tooling * Drive automation, AI usage and tooling improvements to increase efficiency and reduce risk * Provide support to the business as it relates to solution design, project and change management security. * Provide technical leadership and incident response support during security events * Collaborate with IT, DevOps, Software, Networks and Infra teams to embed security practices * Stay current on emerging threats, vulnerabilities, and security technologies Required Qualifications * Bachelor’s degree in computer science, Cybersecurity, or related field * 8+ years of experience in cybersecurity or information security roles. * Experience designing and implementing enterprise scale security principles * Proven ability to influence and work with cross-functional teams and departments * Hands on experience with end user and cloud security (Azure, AWS, Windows and MAC O/S) * Strong technical knowledge of software development (CI/CD pipeline), cloud and security by design ways of working. * Experience with security frameworks (NIST, ISO/IEC 27001, NIS2 TISAX) Key Skills Required * Security architecture & Zero Trust principles * Cloud security (Azure & AWS) * DevSecOps and CI/CD security integration (SDLC) * Security frameworks & compliance (ISO 27001, NIST, NIS2, TISAX) * Workflow Automation & AI adoption * Stakeholder management & technical leadership Tool Experience * Microsoft Azure (E5 Toolset) - Defender for Cloud, Defender for Endpoint, Defender for Identity, Microsoft Purview * AWS Security Hub (CSPM), Amazon Guard Duty, AWS Inspector, AWS Identity Analyser, AWS Config * SonarCloud (SAST Tooling) * Atlassian Cloud (Confluence / Jira) * Vanta (GRC) * Strong Microsoft Office 365 knowledge Certifications (Desired) * ISC2 - CISSP/CCSP/CSSLP * AWS Certified Security - Specialty * Microsoft Azure Security Engineer Associate (AZ-500) * Microsoft Cybersecurity Architect Expert (SC-100) * GIAC GSSP/ GCSA New hires at Cubic³ are required to work onsite five days a week during their six-month probation period to get to know the company, their team, and our ways of working. After probation, we offer a flexible arrangement of up to eight work-from-home days per month, provided it aligns with business needs and performance standards. This arrangement is not a given for all roles. Cubic³ is an equal opportunities employer and committed to fostering a diverse and inclusive workplace.
About Abound We’re redefining consumer lending in the UK, and beyond. Using advanced AI and Open Banking data, we make fair, affordable personal finance available to more people. While traditional lenders rely almost entirely on credit scores, we look at the full financial picture - how much you spend, and what you can afford to repay to build a deeper, more accurate understanding of each customer's unique financial situation. And we've shown it works at scale. We’ve issued over £1.3bn in loans directly to customers while delivering market-leading credit performance - for every 10 defaults the industry expects, we see only 3. We also reached profitability just 2.5 years after launch. Backed by £2bn+ of funding from top-tier investors including Citi, GSR Ventures, and Deutsche Bank, we’re recognised as one of Europe’s fastest-growing fintechs (Sifted, CNBC). Now, we’re expanding into new markets and product lines - and we’re looking for ambitious people who want to learn fast, take ownership, and grow with us. About the role: You won't be sitting in an ivory tower throwing policies over the fence. You will be embedded directly within our Platform team in a true DevSecOps capacity. Operating as a highly technical individual contributor, you will bridge the gap between product-led engineering and Corporate IT. You will play a hands-on role in challenging the security architecture of production and corporate IT infrastructure. In your first 6–12 months, you will design and implement our next-generation cloud security architecture across AWS and GCP, while helping to build and mature our internal SOC capabilities, including detection and response. You will take ownership of Microsoft Sentinel, enhancing our SIEM/SOAR capabilities, and strengthen identity and access management through improved and automated RBAC across AWS, Microsoft Entra, and internal systems. You will also drive a shift-left approach to security by embedding controls into GitLab CI/CD pipelines, including scanning, IaC reviews, and automated policy enforcement across the SDLC. Our technology stack: Cloud & Compute: AWS, ECS Fargate, Aurora, Lambda, GCP Data Lake: S3, DMS, Glue Cloud Security Tooling: GuardDuty, Security Hub, Inspector, Security Command Center Code & IaC: Python, Java, GitLab, AWS CDK, Terraform/CDK-TF Observability & Incident Management: AMP, Incident.io Who you are: * You are a security professional by trade, but a hacker by design. You have a strong track record in DevSecOps and cloud security engineering, with hands-on experience elevating the security posture of other organisations. * You are a strong Python developer. You know how to script automation, interact with APIs, and build security tooling from scratch. * You possess a rock-solid understanding of network security fundamentals and how they apply to modern, distributed cloud architectures. * You are comfortable owning both the build and run aspects of security—designing systems and responding to incidents. * You thrive in the dynamic, ambiguous, and fast-paced environment of a high-growth startup. You know how to balance rigorous security with engineering velocity. What you'll be doing: * Actively contribute infrastructure-as-Code (AWS CDK, Terraform) for security risks prior to deployment * Implement best practice network security across AWS and GCP (IAM, VPCs, encryption, logging, monitoring) * Embed zero-trust policies across the estate * Actively challenge the security standards of production applications and infrastructure * Embed security controls into CI/CD pipelines (SAST, dependency scanning, container security) * Partner with engineering teams on secure architecture and deployment patterns * Support secure SDLC practices and pre-deployment security reviews What we offer * Everyone owns a piece of the company - equity * Hybrid with 3 days a week in the office * 25 days’ holiday a year, plus 8 bank holidays * 2 paid volunteering days per year * One month paid sabbatical after 4 years * Employee loan * Free gym membership * Team wellness budget to be active together - set up a yoga class, a tennis lesson or go bouldering