- Location
- Oslo, Norway · Nedre Vats, Norway · Switzerland - Remote · Stavanger, Norway
- Workplace
- Remote
- Type
- Full-time
- Department
- Security
- Seniority
- Lead
- Closing date
- Today
- Source
- Workday
Description
We are looking for an Enterprise Security Services Lead to oversee and coordinate security across our enterprise infrastructure, applications, and third-party ecosystem. You will drive vulnerability management across servers, endpoints, networks, and applications, while ensuring our technology environment meets AutoStore security standards and follows security best practices.
The role also covers application and third-party security, working with internal teams and external service providers to strengthen secure development practices, manage security testing and remediation, and ensure suppliers and integrations meet our security requirements. This is a highly cross-functional role where you will coordinate security activities across multiple stakeholders and drive improvements in processes, tooling, and security maturity.
Job Responsibilities:
Enterprise Vulnerabilities
Own and develop our enterprise vulnerability management capabilities, including vulnerability tooling, scanning, data integrations, reporting, and integration with SDLC, DevSecOps, and CI/CD processes.
Work with Risk and technical teams to identify and prioritise vulnerabilities, define remediation plans, track key risk and performance indicators, and coordinate remediation across the organisation.
Third-Party Security & Supply Chain Security
Lead third-party and supply chain security, including supplier risk assessments, security due diligence and continuous monitoring, as well as software supply chain practices such as SBOM governance and open-source risk management.
Penetration Testing & Red Team Services
Lead penetration testing and Red Team activities, ensuring testing reflects business risks and relevant threats, and coordinate remediation and retesting of identified vulnerabilities.
Code Signing Services:
Support code-signing services and governance, ensuring secure certificate and key management, software integrity, and trusted release processes across development teams.
Qualifications:
10+ years of cybersecurity experience, including 5+ years in a senior or leading role within application security, vulnerability management, or security assurance.
Strong experience with enterprise vulnerability management and application security, including penetration testing and third-party/supplier security.
Hands-on experience implementing DevSecOps and secure software development practices, including security integration within CI/CD environments.
Good understanding of relevant security frameworks, testing methodologies, and technologies, such as OWASP, NIST, SAST/DAST/SCA, API and cloud security, software supply chain security, and PKI/code signing.
Experience working with cloud environments such as Azure, AWS, or GCP. Relevant certifications such as CISSP, CSSLP, OSCP, or GIAC are an advantage.
We offer:
A Collaborative & Inclusive Culture where we celebrate and value everyone’s contributions, encouraging diverse perspectives in decision-making.
Work-Life Balance & Well-being: prioritizing your mental and physical well-being.
A Creative and Safe Workplace by joining a company experiencing rapid growth, with the stability of being Norway’s first unicorn listed on the Oslo Stock Exchange.
International and Supportive Environment within a Norwegian multinational that values collaboration and innovation with a structured onboarding plan and career opportunities within the company
This role can be based in Norway, at our offices in Oslo (Lysaker), Stavanger, or Vindafjord (Nedre Vats), or remotely from Switzerland.
Application deadline: September 6th. Please note that we review applications continuously —if this opportunity excites you, we encourage you to apply as early as possible! All inquiries are treated confidentially.
AutoStore does not accept agency resumes or assistance for this role. Please do not forward resumes to our job's alias or AutoStore employees. AutoStore is not responsible for any fees related to unsolicited resumes. This policy should be respected.