Security Vulnerability Lead
- Søknadsfrist Snarest
- Arbeidsspråk Engelsk
- Sektor Privat
Make an impact with Laerdal!
Make a difference with Laerdal where immersive technology transforms healthcare quality and education across the globe. With over 2,200 colleagues, join a team where collaboration and engagement are prioritized in helping save one million more lives, every year, by 2030.
Laerdal Medical is a global, family-owned company headquartered in Stavanger, Norway. With the vision “Helping Save Lives”, Laerdal develops products and solutions in medical simulation, training, and therapy. The company has approximately 1,600 employees in more than 20 countries, serving healthcare institutions, educational institutions, and emergency services worldwide.
About the role
As Security Vulnerability Lead at Laerdal Medical, you will be the security team’s operational driving force in software composition analysis. You will ensure that the organization detects, assesses, and manages vulnerabilities across its products and product infrastructure, and is prepared to handle security incidents within the same scope. You will be reporting to the Head of Digital Product Security. Developer know-how is a key trait for success in this role, as you will work closely with development teams to integrate security into their daily workflows.
Key Responsibilities
Help development teams standardize how vulnerabilities are assessed, prioritized, reported, and handled, in line with L2DP’s triage process and remediation SLAs
Own and operate Laerdal’s software composition analysis (SCA) and vulnerability tracking platform (OWASP
Dependency Track) and help development teams integrate it into their workflows
Coordinate vulnerability scans and penetration tests, including work by the external SecOps-teams
Build and maintain incident response procedures and playbooks
Required Qualifications
Experience with vulnerability management and security assessments of systems and applications
Understanding of cyber threats, attack techniques, and risk assessment methodologies
Familiarity with and understanding of CVEs and CVSS
Familiar with architectural risk analysis/threat modeling
Ability to collect, analyze, and correlate threat intelligence
Experience working with application architecture and development
Strong communication skills and the ability to advise development teams on security risk
Ability to work effectively under pressure
Preferred Qualifications
Experience working in a global organization
Competence in digital forensics and evidence collection
Experience with automation of vulnerability management and security operations (SOAR)
Familiarity with the frameworks such as MITRE ATT&CK, CWE and CAPEC
Knowledge of cloud security (Azure, AWS, GCP)
Understanding of security challenges in development environments (npm/yarn supply chain, C++ memory safety, ML pipeline integrity)
Familiarity with industry-specific requirements for medical devices (MDR, IEC 62443)
Knowledge of SBOM standards and tools (CycloneDX, SPDX)
Education and Experience
Relevant higher education in information technology, cybersecurity, information security, or equivalent
Minimum 3–6 years of experience in information security, with documented experience in vulnerability management and/or incident response
Relevant certifications are an advantage, e.g., GCIH, GCFA, GPEN, CEH, OSCP, ISO 27001 Lead Auditor
What we offer
Interesting and meaningful work contributing to our mission
Opportunities for personal and professional growth
A great, diverse, inclusive, and international work environment
Innovative and forward-thinking technology
Competitive compensation and benefits package
Flexible work arrangements, an extensive wellbeing program with social, cultural and sports activities and benefits such as discounted public transport, wardrobe with towel service, company cabins, and more.
Ready to apply?
Please submit your CV and application letter by 6 September. We review applications on an ongoing basis and encourage you to apply as soon as possible.
For questions regarding this role, please contact goran.breivik@laerdal.com.
Laerdal Medical is an inclusive employer that values diversity. We encourage all qualified candidates to apply, regardless of gender, age, ethnic background, disability, sexual orientation, or beliefs.
Please note that we use Semac background checks in our recruitment process.
Ferdigheter
- Cybersikkerhet
- Håndtering av sikkerhetssårbarhet
- Informasjonssikkerhet
- Sårbarhetsanalyse
- Software security
- Trusseletterretning
JobbMatch
Er du en god match for denne stillingen?
JobbMatch ser på erfaringen og egenskapene dine – og sjekker hvor godt du passer.
- Sted: Seehusensgate 1, 4025 Stavanger
- Bransje: IT - programvare, Medisinsk utstyr og rekvisita
- Stillingsfunksjon: IT-sikkerhet, Sikkerhetsanalytiker
Nøkkelord
sårbarhetsstyring, it-sikkerhet, cybersikkerhet, risikovurdering
Firmaets beliggenhet
Seehusensgate 1, 4025 Stavanger
Annonseinformasjon
- FINN-kode: 474534415
- Sist endret:
- Org.nr.: 979484488Se på Brønnøysundregistrene(åpnes i ny fane)


