Profile

Security fails most often not because a control was missing but because it was bolted on late, and everyone routed around it. We work the other way: security embedded through the delivery lifecycle, designed so the secure path is also the convenient one.

That means threat modelling while a design is still cheap to change, controls chosen for the system they are protecting rather than from a checklist, and the practice work - DevSecOps, review habits, the training that makes a team able to do this without us.

It also means the overlap with telemetry. Security operations and engineering want much the same data for different reasons, and the teams who get that right build one data fabric rather than two.

This is an open application. You are not applying for a named position - you are telling us that this is the part of Volition you want to work in.

What you would work on

  • Threat modelling and security architecture, early enough that the answers still change the design
  • Security assessments that end in something a team can act on rather than a document
  • Building security into pipelines - dependency and secret scanning, policy as code, controls that fail loudly and early
  • DevSecOps practice: helping teams own security rather than hand it off
  • Working with the telemetry side so security operations and engineering share one data fabric
  • Working directly with client teams, and leaving them able to run it themselves

Who tends to fit

Experience that lands well

  • Fluent Swedish and English
  • Hands-on security work in software delivery rather than only in audit or policy
  • Familiarity with a recognised framework - threat modelling methods, OWASP, NIST, CIS, or their equivalents
  • Cloud platforms (AWS, Azure, or GCP) and how their security models actually behave
  • A language you are comfortable solving problems in, and enough development background to talk to engineers as a peer
  • Some exposure to SIEM or detection work, or an interest in it

We are not counting years. Someone who has properly secured one delivery pipeline and can explain every decision in it is more interesting than someone who has been near a dozen.

Nice to have

  • Certifications in the platforms or frameworks you work with
  • Incident response experience
  • Writing or speaking about this work in public

Personal qualities

  • Problem solver: you like diagnosing complex issues and building elegant solutions
  • Communicator: you can explain technical concepts to diverse audiences
  • Teacher: you enjoy mentoring and helping others grow
  • Curious: you stay current with emerging technologies and practices
  • Collaborative: you thrive in team environments and value diverse perspectives

What we offer you

We offer you a dedicated management team, with a solid engineering and software development background. We are all part of the delivery and still active as consultants. This means that we have a better understanding of both our customer’s unique situation and your situation as an employed consultant. Basically, we are a company by knowledge workers for knowledge workers, built on a foundation of knowledge, empathy, sharing, and fun.

We expect all employees to be part of this culture.

  • Willing to always learn something new and set knowledge into practice
  • Participation in our competence jam sessions, conferences, and trips
  • Willing to share, and spread positive energy

How an open application works

We recruit by expertise rather than by vacancy. Open applications go to the people who lead this area, they are read properly, and we come back to you - whether or not there is something to talk about immediately.

Tell us what you have built, what you would want to build here, and anything that shows how you think. A CV helps, but what you write matters more.

Sounds like a good match?

Interested in this area?