Axpo Group
Application Security Engineer (f/m/d)
Full details on LinkedIn
The complete job description, requirements, and application details are available on the original posting.
About Axpo Group
Axpo Group is Switzerland's largest energy company, specializing in the production of electricity from renewable sources. Headquartered in Baden, Aargau, it operates in around 30 countries across Europe, North America, and Asia. Established in 2001, Axpo is fully owned by cantons and their utilities in Northeastern Switzerland and employs approximately 5,000 to 7,000 people. The company focuses on producing, distributing, trading, and marketing electricity and natural gas, with a strong emphasis on renewable energy. In Switzerland, Axpo supplies electricity to about 3 million people and thousands of businesses, including nearly 200,000 private customers through its subsidiary CKW. Internationally, it serves around 400,000 electricity delivery points and 45,000 gas points in countries like Italy, Spain, Portugal, and Poland. Axpo is a leader in energy trading and offers a range of services, including risk management, renewable solutions, and energy services tailored to meet the needs of various consumers and businesses.
Security at Axpo Group
Compiled from public job postings, careers pages, and company materials. Data may not reflect current state — verify during interviews.
Security Philosophy
- Axpo emphasizes cybersecurity as a decision-shaping discipline with a focus on collaboration and remediation.
- The philosophy centers on developer enablement through vulnerability remediation support and secure coding practice implementation.
- The approach combines extensive expertise in cyber security with operational excellence, prioritizing targeted application security awareness and training.
Security Team
- The AppSec team at Axpo is led by Jacopo Fumagalli (Chief Information Security Officer) and Ilaria Bevilacqua (Head of Information Security - Trading & Sales).
- The team comprises approximately 5-10 professionals specifically in security engineering roles.
- Reporting lines between AppSec engineering and the CISO are not explicitly detailed in public documents.
Key Initiatives
- Axpo operates a comprehensive AppSec program including: (1) Shift-left practices through integration of SAST, DAST, and SCA tools into CI/CD pipelines.
- (2) Continuous monitoring and protection via a Security Operation Centre (SOC).
- (3) Vulnerability management with collaborative remediation workflows between AppSec and development teams.
- (4) Regulatory compliance enforcement through security quality gates aligned with SOX, MAR, and REMIT standards. No Security Champions program is publicly documented.
Preparing for an AppSec interview?
Get the weekly briefing 2,000+ security pros trust.