JobRaahGet matched free

Jobs

Application Security Engineer

EQT Group · Stockholm, Stockholm, Sweden · On-site

Posted Jul 4, 2026

Apply with JobRaah

Sign up free: we match you to jobs like this, tailor your application and fill the form. 2 free applications every day.

EQT is looking for an Application Security Engineer to join our Cyber Security Engineering team, owning the security posture of our hosted applications and container platforms. This is a hands-on engineering role where you will build automated guardrails and real-time visibility — making the secure path the easy path across a modern, globally distributed technology landscape. Over time, this role will grow to include ownership of our AI and agentic platform security as that discipline matures at EQT. About the Team The Cyber Security Engineering team defines and validates security standards across EQT's technology landscape. Operating as a trusted security function, the team works closely with platform engineering, cloud infrastructure, identity, and technology assurance teams to strengthen controls while enabling innovation. This role sits within a small, high-trust team where collaboration, curiosity, and technical depth are core to how we work. The team supports both traditional application environments and EQT's emerging AI and agentic platforms, helping the organization navigate a rapidly evolving threat landscape with practical, engineering-led security standards. You will report to the Head of Digital Employee Experience and partner closely with the CISO function. About the Role This role is built around strong application and container security fundamentals, with the mandate to build automated guardrails and observability at scale — not to review individual applications by hand. As you grow into the role, you'll partner with the CISO function and wider security team to extend that same automation-first approach into AI and agentic security, a space EQT is actively investing in. Design and deploy automated controls for container platforms and application deployments — admission controllers, policy-as-code, and pre-configured scanning — that enforce standards at the point of deployment rather than after the fact. Enable citizen development — making sure non-technical teams can use AI coding tools like Claude Code and CoWork without needing to come through security first, because the guardrails are already there. Curate internal security tooling and automation for cost, reliability, and security posture — favouring deterministic, scripted components that run fast and cheap over token-intensive approaches, and tracking cost-per-outcome across security controls as a core operating discipline. Own container security standards as enforceable controls: image scanning policy, runtime baselines, and registry governance across all deployment paths, including workloads outside formal pipelines. Manage software supply chain risk end-to-end, including dependency scanning, build-time and runtime composition analysis, and identifying high-propagation risk junctions. Build application security observability that goes beyond static inventories — a live picture of what is deployed, what it is composed of, and where risk is…