Modoante
SwedenFull TimeSecurity Guards

Head of Security (533A21C)

Referment | Stockholm, Stockholm County, Sweden | Salary not specified

Source: JobsPipe

View company

Role snapshot

Work model
Hybrid
Language
Not specified
Experience
Not specified
Posted
Posted today
Application deadline
2026-10-03

What you'll do

Referment is working with a growing financial-technology SaaS business whose data and software help investor-relations and finance professionals make informed decisions. The company is hiring a Head of Security to take overall responsibility for information security and develop the structure needed to support its Swedish and international operations. This is a broad, hands-on role spanning governance, technical security and customer-facing assurance. You will build on an existing information security management system, lead the path towards SOC 2 certification and work directly with software engineers on application and infrastructure security. You will also represent security in B2B customer discussions. The position follows a hybrid model from the company’s Stockholm office. The Role

  • Own and continue developing the information security management system and the organisation’s ISO 27001 work.
  • Lead the implementation and certification programme for SOC 2.
  • Lead incident response and develop effective processes and tools for logging, monitoring and incident management, including SIEM capabilities.
  • Set security requirements and organise technical security work directly with development teams.
  • Advise colleagues on application and infrastructure security.
  • Act as the technical security expert in B2B sales processes and establish a Trust Center for customer assessments.

What We're Looking For

  • Several years of direct security experience, potentially gained through DevSecOps, penetration testing or security-focused software development.
  • A relevant engineering or technical education, or an equivalent background.
  • Fluency in both Swedish and English, spoken and written.
  • The ability to move comfortably between governance, hands-on technical work, software teams and external customer conversations.

Relevant Desirable Experience Practical work with ISO 27001 or SOC 2, modern cloud software development, CI/CD and SIEM implementation would be valuable. Experience of penetration testing, vulnerability analysis, the OWASP Top 10 or managing security assessments in a B2B SaaS environment would also be useful. This could suit a Security Lead, Information Security Manager, senior DevSecOps specialist or security-focused engineering leader who is ready to take broad ownership of a security function while remaining close to technical delivery. #Referment

Work resources

Helpful work resources for this job

Sign in to read

Application checklist

Review your application before submitting

A quick checklist to help candidates submit a clearer, more complete application.

Read resource