
Carasent · Göteborg
ABOUT THE POSITION We need an experienced Head of Security who can lead the way forward in bringing our product to the next level. We have a great product (We...
We need an experienced Head of Security who can lead the way forward in bringing our product to the next level.
We have a great product (Webdoc) with many happy customers (800), a great support organization (free support for all customers), a
great product management team (lots of hands-on experience and domain knowledge), and a great development department (six teams
including infrastructure).
We need a skilled Head of Security who can guide and lead the way forward for our security work through technical knowledge,
strategic thinking, and strong collaboration with both technical and non-technical teams.
Our product helps caregivers in the private healthcare sector work efficiently with their administration, and we integrate with
many actors such as Inera, E-hälsomyndigheten, and several private actors. Experience working within healthcare, compliance, or
highly regulated environments is very valuable to us.
In this role, you will define, implement, and continuously improve the organization’s security strategy and roadmap while ensuring
that security is embedded throughout the organization.
You will work closely with engineering, infrastructure, and product teams to integrate security into development and operational
processes, while also leading the design and implementation of security architecture and controls across systems and
infrastructure.
Part of the role is being hands-on in implementing security tools, automation, and practical security solutions, while also
supporting teams with guidance and best practices. It's important that you are up to date with latest trends in AI; both how we
should meet the increased threats and how we should use AI as a tool to be more efficient in handling existing potential
vulnerabilities.
You will lead incident response processes and continuously improve readiness and routines through testing and follow-up. Risk
assessments, penetration testing, vulnerability management, and remediation strategies will be an important part of the role,
including ensuring that identified vulnerabilities are prioritized, followed up on, and resolved across systems and applications.
Another key responsibility is ensuring compliance with frameworks and regulations such as ISO27001, GDPR, SOC2, and NIS2, as well
as supporting and guiding audits and other compliance activities.
We also see you taking an active role in establishing and maintaining security policies, standards, and best practices across the
organization, while continuously evaluating and improving security processes, tools, and methodologies.
Together with the Head of Infrastructure and other stakeholders, you will help align security and infrastructure strategies and
ensure security is integrated into all parts of the organization.
You enjoy sharing knowledge and driving competence development initiatives related to security awareness and secure development
practices.
We believe you are comfortable communicating security risks, priorities, and progress clearly to both technical teams and
leadership.
You have experience working with legacy systems and modernizing environments while ensuring long-term maintainability and
security.
As a manager at Carasent, you are expected to lead the team in accordance with the Carasent Leadership Promise, hire and onboard
new employees, establish goals and development plans, and support, coach, mentor, and give feedback to team members.
We believe you have strong experience from security leadership roles and a deep understanding of application security,
infrastructure security, cloud environments, incident response, vulnerability management, and risk assessment.
You have hands-on experience with security tools, automation, and scripting, and you are comfortable balancing strategic security
work with practical implementation.
Strong verbal and written communication skills (Swedish and English) are important in this role, as you will collaborate across
teams and present security concepts to both technical and non-technical stakeholders.
We spend 2–5 days a week at the office depending on what’s needed.
We have a great benefits package.
Are you up for the challenge?
Anchored in the vision of enabling future care, Carasent provides healthcare organisations with a seamless ecosystem of integrated
solutions that significantly reduce administrative burdens and improve patient engagement and healthcare delivery.
Through its wide portfolio of products and services, such as cloud-based electronic health record systems, tools for electronic
patient communication and virtual visits, business intelligence solutions, and numerous existing partner integrations, Carasent
offers the most flexible clinical business support available in the Nordic market today.
Carasent has offices in Sweden and Norway with customers ranging from primary care to secondary care to occupational health and
rehabilitation, primarily in the private sector.
At FTMO, we believe that company growth starts with people. We are a team that pushes forward together, supports one another, and celebrates shared achievements. Our environment creates space for talents to grow – individually, as a team, and across the whole company. We are currently launching a new crypto-native product, a greenfield initiative that brings the principles we've built our reputation on (transparency, fairness, verifiable track records) into the on-chain world. You'll be one of the first engineers on a small, autonomous team building from scratch. This isn't a role where you maintain existing systems, you'll design and ship the core backend architecture for a product with real deadlines, real users, and a tight timeline. The first milestone is a working demo within 4 months. Full production launch within 10. WHAT WILL BE YOUR AGENDA? * Design and build the core backend services in Rust, real-time data processing, WebSocket infrastructure, and high-throughput event pipelines. * Architect and implement a simulation engine that operates against live market data with sub-second latency requirements. * Build risk and evaluation logic - real-time monitoring, rule-based assessment, automated decision pipelines. * Develop and deploy on-chain programs that record and verify platform activity on blockchains. * Integrate external price feeds - WebSocket order book data, oracle networks, and other liquidity sources. * Own the infrastructure - RPC nodes, CI/CD, monitoring, deployment workflows. * Design for scale from day one - the system must handle thousands of concurrent sessions with real-time data streaming. * Work directly with the Head of Crypto on architecture decisions, feature prioritization, and product direction. You'll have a seat at the table, not just a ticket queue. WHAT WILL YOU BRING TO THE TABLE? * 3+ years of professional Rust development - you think in Rust, this isn't a "learning on the job" position. * Strong backend systems background - building APIs, WebSocket services, real-time data pipelines, and event-driven architectures. * Experience designing systems for high concurrency and low latency. * Comfort with ambiguity and ownership - you'll often be the only person who knows how a subsystem works, and that's fine with you. * You ship first, polish second - we have 4 months to a private demo. You need to be comfortable with speed over perfection, then iterating. * CS degree or equivalent - we care about what you've built, not where you studied. WHAT WOULD BE NICE TO HAVE? * Experience with Solana or other EVM-based blockchains, program development, on-chain data patterns, and security considerations. * Familiarity with trading systems, simulation engines, or risk management logic. * Experience with DeFi protocols, oracle networks, or cross-chain infrastructure. * Hackathon participation or open-source contributor. * TypeScript/Node.js for tooling and integration testing. WHY JOIN THE FTMO TEAM? * We are a Czech fintech that, since 2015, has grown from an idea into a global project. 🚀 * 300+ amazing teammates. We’re a great team who learn from each other every day.🤜🤛 * How do we work? We focus on meaningful work and open communication, while only adopting processes that make our lives easier. * Prague, Národní třída. Enjoy our modern offices at the Quadrio shopping center, offering beautiful views and excellent accessibility. * What if I don’t trade? No worries. We’ll show you what our product is all about and introduce you to the basics of trading. * Free fruit, snacks, and coffee are always within reach in the office. * How do we promote strong relationships and well-being? Company cottage, team building events, and running club. * Flexible hybrid model. We prefer collaborating in person to keep the team spirit high, but we offer the flexibility you need to stay balanced. *The benefits mentioned above apply to on-site employees in our Prague office.
The AI-powered OS for beauty, wellness and self-care About Fresha Fresha is the AI-powered operating system for the global beauty, wellness and self-care industry, connecting and powering everything from salons and barbers to spas, medspas, fitness studios and health practices. Trusted by millions of consumers and businesses worldwide. Fresha is used by 140,000+ businesses and 450,000+ stylists and professionals worldwide, processing over 1 billion appointments to date. The company is headquartered in London, United Kingdom, with 15 global offices located across North America, EMEA and APAC. Fresha allows consumers to discover, book and pay for beauty and wellness appointments with local businesses via its marketplace, while beauty and wellness businesses and professionals use an all-in-one platform to manage their entire operations with an intuitive business software and financial technology solutions. Fresha’s ecosystem gives merchants everything they need to run their business seamlessly by facilitating appointment bookings, point-of-sale, customer records management, marketing automation, loyalty, beauty products inventory and team management. The consumer marketplace unlocks revenue potential for partner businesses by leveraging the power of online bookings and automated marketing through mobile apps and advanced integrations with major tech brands including Instagram, Facebook and Google.
About Us_ // At Masabi, we’re driving the fare payment revolution, powering the journeys of millions all over the world. We build fare collection platforms that allow riders to seamlessly buy and present tickets for public transport either on their mobile phones, from a ticket machine, or even by tapping their bank card to travel. Our Justride platform is used in over 250 locations globally, including some of the largest cities in the world. With our industry-first mobile ticketing SDK, we’ve partnered with large players in the transport space, including Uber, Moovit and Transit. Your own journey is important to us too. Choosing a role here means joining a network of innovators from all walks of life; a group of passionate individuals who consistently deliver. Here, you’ll find the tools you need to build the career you want. Whether you’re taking the direct route or trying a new path, we’ll support you no matter what. THE ROLE_ // At Masabi, we’re building technology that makes public transport simpler, fairer and more accessible for millions of people. That only works if our platform is secure, trusted and reliable. As our Head of Security & Compliance, you’ll step into a role that is central to how we build trust with our customers and scale as a global SaaS business. You’ll own security and compliance end to end, shaping how we approach it as a company and how it works in practice day to day. You’ll lead a small team, bringing clarity, focus and direction as you build on solid foundations and evolve this area alongside the business. In the near term, you’ll focus on understanding where we are today, strengthening our approach to key areas like audits and compliance, and helping teams move forward with confidence. You’ll work closely with Engineering, Product and Legal to turn requirements into practical, well-executed outcomes. This is a senior role where you’ll stay close to the work, especially in the early stages. Over time, you’ll shape a more structured and scalable function, helping Masabi stay ahead of evolving standards and make thoughtful decisions around risk. LOCATION_ // This role is available on a remote basis for candidates located anywhere in the UK. Candidates based in London may also work in a hybrid model, with occasional travel to the office RESPONSIBILITIES_ * Take ownership of security and compliance across Masabi, creating clarity on priorities and ways of working * Build a clear view of our current security posture and define a practical path to strengthen it over time * Define security and compliance requirements and work closely with Engineering and IT teams to ensure they are implemented effectively * Maintain existing compliance across PCI DSS, ISO27001, SOC2 and Cyber Essentials, and lead new compliance initiatives across additional standards such as ISO 27017 and ISO 27018 * Manage audits end to end, from preparation through to delivery and follow-up actions * Work closely with Engineering and Product teams to embed security practices in a way that supports delivery * Maintain a clear and actionable view of risk, helping the business prioritise what matters most * Build a more scalable approach to customer assurance, including clearer processes and reusable materials for customer and audit requests * Help guide decisions on which compliance standards we take on as we grow * Lead and support a small team, creating focus, trust and shared direction ABOUT YOU_ * You’ve worked in security and compliance within a payments, fintech or PCI-regulated environment * You have strong, hands-on experience with PCI DSS, ISO27001 and SOC2, including preparing for and delivering audits * You’ve personally owned and delivered compliance programmes, not just overseen them * You understand how security and compliance connect, and how to make them work in practice across a business * You’ve operated in a growing or scaling company, where you’ve had to bring structure and prioritise effectively * You’re comfortable driving work across teams without direct authority, and following through to completion * You bring sound judgement when balancing risk, delivery and commercial needs * You’ve supported or led a small team and know how to create clarity and accountability * You communicate clearly with both technical and non-technical audiences, helping people understand what matters and what action is needed NICE TO HAVE_ * Experience working with additional ISO standards such as ISO 27017 and ISO 27018 * Experience scaling security and compliance in a growing SaaS company, especially through periods of increased customer or regulatory demand * Relevant certifications such as CISSP, CISM, CISA or ISO27001 Lead Auditor or similar * Awareness of AI-related security and governance considerations, and how they may apply in a SaaS environment SOME OF OUR BENEFITS_ * 25 days of holiday per year plus the option to buy another 5 days pro-rated * Private Healthcare via AXA, including pre-existing conditions and mental health * Life Insurance * Menopause support * Choice of workstation * Ability to work for up to 3 months per year from any country in the world (certain limitations) * Pension scheme * Training allowance of up to £1000 per year * £200 annual allowance for any home office need or improvement * Enhanced family leave pay * Cycle to work scheme * Regular social gatherings with a monthly allowance for each employee * Fun and collaborative environment with a focus on making a difference in the world Careers at Masabi are for people going places - driven by a mission to make transit fair and accessible for all. // We are a network of innovators from all walks of life, passionate about making a difference. At Masabi, we operate with openness and trust, creating an environment where everyone feels empowered to bring their whole, authentic selves to work. Whoever you are, just be yourself. // We welcome applications from underrepresented groups, including disabled and neurodivergent people, and can make adjustments at any stage of the process. You’re also welcome to share your pronouns whenever you feel comfortable. Together, we simplify journeys, remove barriers, and improve daily life for millions. Why Join Masabi? * Driven by Purpose – We believe in journeys made simple. The work isn’t always easy, but the best things never are. * Encouraged to Accelerate – Masabi is going places and our people are in the driving seat. Whether you’re taking the direct route or exploring new paths, we support your journey. * Advancing with Empathy – We put people first and foster a culture of learning, not blame. No matter your cargo, we share the load. We’re already powering journeys - are you ready to join us?