
Senior Application Security Engineer
- Oslo
- Fast
- Fulltid
- Energize the customer relationship: Our clients are our partners. We make their goals our own, working side by side to turn challenges into solutions.
- Success starts with me: Personal ownership fuels collective success. We each play our part and empower our teammates to do the same.
- Commit to learning: Every win is a springboard. Every hurdle is a lesson. We use each experience as an opportunity to grow.
- Dare to innovate: We challenge the status quo with creativity and innovation as our true north.
- Better together: We check our egos at the door. We work together, so we win together.
- Prevention and early detection (shift left) of vulnerabilities through developer training and awareness
- Prevention and early detection of vulnerabilities through SAST, DAST, SCA
- Solve problems together with devs, devops and cloud ops
- Handle external penetration tests
- Test for vulnerabilities (red teaming)
- Assist with advice and/or writing code for security specific functions
- Threat modeling sessions with product teams
- Develop systems for testing and reporting
- Stay up to date on attacks and vulnerabilities
- Share knowledge and promote secure coding and deployment in the organization
- Be passionate about security in all stages of a product lifecycle
- Show analytical and communication skills
- Acquiring new knowledge and turn it into actionable changes
- Show persistence in finding vulnerabilities, qualifying/prioritizing vulnerabilities, and seeing them fixed
- Take pride in what you deliver
- Ability to work independently and as part of various teams
- Be a strong team player and prefer to work with others in all phases of the development process
- Enjoy collaborating across departments and borders in an international environment
- Take responsibility, learn continuously, and lead initiatives and projects
- A degree in Computer Science, Information Security, Cryptography or similar, or professional experience in information security software development or system administration.
- Fluent in English (our working language) and Norwegian (or willing to learn).
- Web app development
- Mobile app development
- Kubernetes/containers
- Security testing
- Attack techniques
- Secure coding
- OWASP top 10, HIPAA
- Web proxies, Burp Suite, ZAP, sqlmap, other reconnaissance and vulnerability detection tools
- SAST, DAST, SCA
- OpenID connect, OAuth 2.0, SAML2
- Security headers, same origin policy, authentication tokens, certificates
- Azure
- Web servers
We require applicants to already reside in Norway with a relevant work or residency permit.Don’t meet every single requirement? Studies have shown that women and people of color are less likely to apply to jobs unless they meet every single qualification. At PG Forsta we are dedicated to building a diverse, inclusive and authentic workplace, so if you’re excited about this role but your past experience doesn’t align perfectly with every qualification in the job description, we encourage you to apply anyways. You may be just the right candidate for this or other roles.Additional Information for US based jobs:Press Ganey Associates LLC is an Equal Employment Opportunity/Affirmative Action employer and well committed to a diverse workforce. We do not discriminate against any employee or applicant for employment because of race, color, sex, age, national origin, religion, sexual orientation, gender identity, veteran status, and basis of disability or any other federal, state, or local protected class.Pay Transparency Non-Discrimination Notice – Press Ganey will not discharge or in any other manner discriminate against employees or applicants because they have inquired about, discussed, or disclosed their own pay or the pay of another employee or applicant. However, employees who have access to the compensation information of other employees or applicants as a part of their essential job functions cannot disclose the pay of other employees or applicants to individuals who do not otherwise have access to compensation information, unless the disclosure is (a) in response to a formal complaint or charge, (b) in furtherance of an investigation, proceeding, hearing, or action, including an investigation conducted by the employer, or (c) consistent with the contractor's legal duty to furnish information.All your information will be kept confidential according to EEO guidelines.Our privacy policy can be found here: