
DevSecOps Engineer
- Stockholm
- Permanent
- Heltid
- Own and Operate Security Tooling: Deploy, configure, and maintain security tools and platforms (e.g. vulnerability scanners, email protection, endpoint protection, SSO, SAST/DAST tools, secrets managers, container security platforms)
- Automate Security Operations: Build automation around security workflows, alert triage, and tool integrations using Python, Bash, Terraform, or similar tools
- Vulnerability Management: Manage vulnerability detection tools, run or facilitate penetration tests, test impact from real exploits, support remediation workflows, and help teams prioritize risks based on real-world impact
- Secure the Infrastructure: Collaborate with platform and cloud engineering teams to ensure secure configurations across AWS/GCP/Azure environments, including networking, IAM, logging, and encryption
- Monitoring and Threat Detection: Support detection engineering efforts by ensuring telemetry from cloud services, containers, and endpoints flows reliably into monitoring platforms
- Access & Secrets Management: Help design and maintain secure identity and access practices, including secrets management solutions
- 2–4+ years of experience in a security engineering, DevSecOps, or infrastructure security role, ideally within cloud-native environments
- Strong knowledge of cloud platforms (AWS, Azure, or GCP), including security services (IAM, KMS, VPC security, CloudTrail, etc.) and best practices for securing workloads
- Hands-on experience managing security tools Strong scripting and automation skills in Python, Bash, or Go to build integrations, automate tasks, and customize tooling
- Understanding of core security principles, including least privilege, zero trust, defense in depth, and threat modeling
- Great communication and collaboration skills — you’ll work closely with local engineers as well as game developers at the studios.
- Relevant Certifications such as AWS Certified Security – Specialty, GIAC (e.g., GSEC, GCSA), or more general security certification such as Security+, OSCP or CISSP, etc.
- Contributions to open-source security projects or active participation in the security community (e.g., blog posts, talks, GitHub contributions)
- Experience in threat detection or detection engineering, including writing custom detection rules or working with MITRE ATT&CK framework
- Ability to assess and prioritize risk, translate technical issues into business impact, and make pragmatic security decisions.