
Master Thesis: Keeping Security Assurance in Pace with Continuous Deployment
Ericsson ABNy
Sammanfattning
This opportunity involves a master's thesis project focused on enhancing security assurance in continuous software deployment. The role is based in Linköping, Sweden, and requires mapping security assurance activities in product development, evaluating their compatibility with continuous deployment, and proposing improvements. Candidates will work on a prototype to test hypotheses derived from research and industry practices, culminating in a presentation for security and development teams.Det här erbjuder vi
Opportunity to work on innovative solutions to complex problems.Collaborative environment with a diverse team of innovators.Encouragement of diverse and inclusive practices within the organization.
Ansök senast: Öppet tillsvidare
Publicerad: 2026-10-02
Beskrivning
Join our Team
About this opportunity:
Software is increasingly released continuously, with changes reaching production in hours instead of months. Security assurance has not kept up: threat modelling, security and risk assessments remain manual, expert-driven and tied to large releases and milestone gates. As release frequency rises, they become bottlenecks, or they are quietly skipped. Speed alone is not the goal, though: a faster analysis is worthless if its result cannot be trusted or reproduced, since a missed threat costs more than a slow one.
How can security assurance be maintained when software is released continuously and incrementally? The student derives a testable hypothesis from related work, then builds and evaluates a prototype. Which approach to pursue is deliberately left open: candidates include automated threat derivation from design artefacts, incremental re-analysis of changed parts, and large language models.
What you will do:
The thesis concludes with a result presentation for the security and development teams involved.
The skills you bring:
Why join Ericsson?
At Ericsson, you'll have an outstanding opportunity. The chance to use your skills and imagination to push the boundaries of what's possible. To build solutions never seen before to some of the world's toughest problems. You'll be challenged, but you won't be alone. You'll be joining a team of diverse innovators, all driven to go beyond the status quo to craft what comes next.
What happens once you apply?
Click Here to find all you need to know about what our typical hiring process looks like.Encouraging a diverse and inclusive organization is core to our values at Ericsson, that's why we champion it in everything we do. We truly believe that by collaborating with people with different experiences we drive innovation, which is essential for our future growth. We encourage people from all backgrounds to apply and realize their full potential as part of our Ericsson team. Ericsson is proud to be an Equal Opportunity Employer. learn more.
Primary country and city: Sweden (SE) || Linköping
Req ID: 790896
About this opportunity:
Software is increasingly released continuously, with changes reaching production in hours instead of months. Security assurance has not kept up: threat modelling, security and risk assessments remain manual, expert-driven and tied to large releases and milestone gates. As release frequency rises, they become bottlenecks, or they are quietly skipped. Speed alone is not the goal, though: a faster analysis is worthless if its result cannot be trusted or reproduced, since a missed threat costs more than a slow one.
How can security assurance be maintained when software is released continuously and incrementally? The student derives a testable hypothesis from related work, then builds and evaluates a prototype. Which approach to pursue is deliberately left open: candidates include automated threat derivation from design artefacts, incremental re-analysis of changed parts, and large language models.
What you will do:
- Map the security assurance activities in a product development flow and how each scales with release frequency.
- Derive from research and industry practice what makes an assurance activity compatible with continuous deployment.
- Select one activity and one approach and state the hypothesis to be tested.
- Evaluate it against current practice on coverage, repeatability, cost and actionability.
- Propose a stepwise adoption path for the improvements that pay off.
The thesis concludes with a result presentation for the security and development teams involved.
The skills you bring:
- Master's student in computer science, software engineering, computer engineering or similar.
- An interest in software security is required; familiarity with continuous integration and delivery pipelines is preferred.
Why join Ericsson?
At Ericsson, you'll have an outstanding opportunity. The chance to use your skills and imagination to push the boundaries of what's possible. To build solutions never seen before to some of the world's toughest problems. You'll be challenged, but you won't be alone. You'll be joining a team of diverse innovators, all driven to go beyond the status quo to craft what comes next.
What happens once you apply?
Click Here to find all you need to know about what our typical hiring process looks like.Encouraging a diverse and inclusive organization is core to our values at Ericsson, that's why we champion it in everything we do. We truly believe that by collaborating with people with different experiences we drive innovation, which is essential for our future growth. We encourage people from all backgrounds to apply and realize their full potential as part of our Ericsson team. Ericsson is proud to be an Equal Opportunity Employer. learn more.
Primary country and city: Sweden (SE) || Linköping
Req ID: 790896
Ansök till tjänsten
Master Thesis: Keeping Security Assurance in Pace with Continuous Deployment
Ny
OM FÖRETAGET

Ericsson AB









