JobBobsTyöpaikat reaaliajassa, maailmanlaajuisestiLive

Security Engineer, SecOps

Hoxhunt · Helsinki, Finland · 2026-07-02

FullTimeexecutiveEtätyö
Hae työnantajan sivuilla

Tietoa tehtävästä

OUR MISSION AND WHY IT MATTERS

We are on a mission to make humans the strongest security layer.

Human risk remains one of the biggest vulnerabilities and traditional awareness training is not enough. We take a different approach by combining AI-driven personalization, real threat detection, and behavioral science to actively protect people and organizations.

We don't just simulate risks. We build the tools that detect and stop them.

WHY THIS ROLE MATTERS

We're looking for a Security Engineer, SecOps to join Hoxhunt's Product Security team. Your core mission is to help mature our security monitoring into a stronger, automation-based security operations capability. We already have the foundations in place, and we want you to build on them with detection, observability and response delivered through tools and automation rather than a staffed SOC. You'll also coordinate vulnerability management across our engineering teams and write the production code and automation that makes security scale.

You'll also help keep our customer security answers accurate, working with the team on the security questionnaires and RFPs that unblock deals. This is a real and recurring part of the job, roughly 10–30% of your time depending on deal flow: reviewing and updating our existing security answers, and researching new ones where none exist yet, drawing on broad SOC 2, ISO and HIPAA knowledge, with the occasional customer call when a deal needs technical depth.

Beyond supporting deals, you'll also help turn customers' security and compliance requirements into product features and policy proposals, helping close the loop between what customers ask for and what we build. You won't start from scratch or do it alone: there's an existing library of security answers and compliance tooling (Vanta) behind you, and the team shares the load. The team's job is simple to state: address any security concern a product team or customer raises, and you'll be part of that.

This is an engineering role, not an analyst or shift-based one. You'll bring real, hands-on instinct for incident response and case management, and the job is to turn that instinct into systems: codifying it into automation, playbooks and tooling so detection and response scale without scaling headcount. Product Security is a small, high-leverage team: we work through discovery, planning and influence, and most implementation happens across the wider Technology organisation. You'll add the delivery muscle and the automation-first mindset to keep maturing our security roadmap (security observability, SIEM build-out, vulnerability management). We expect you to use modern AI tools throughout your work to expand and scale your reach.

WHAT YOU'LL OWN AND DRIVE

You’ll own security capabilities that help us detect, respond, and scale security through engineering.

Primary Responsibilities

- Build and improve our security monitoring: own detections and alerting end-to-end (build, tune, maintain) and contribute to maturing our wider automation-based capability and SIEM build-out, with detection and response running through tools and code, not a manned SOC.

- Build and operate our security observability: audit logging, security telemetry, and the dashboards/signals the rest of engineering relies on.

- Coordinate vulnerability management end-to-end: triage, prioritise (CVSS plus exploitability and context), and drive remediation in partnership with the teams that own the code.

- Strengthen our cloud security architecture: implement and help shape network segmentation and egress controls, IAM and least-privilege, secrets management and infrastructure-as-code on GCP, partnering with SRE/Platform.

- Help connect customer requirements to what we build: turn security and compliance requirements from customers and frameworks into concrete feature and policy proposals, surfacing gaps to the team and roadmap.

- Strengthen the secure development lifecycle: SAST, DAST, SCA, and secrets scanning across our pipelines.

- Measure and test what we build: treat detections as code that is peer-reviewed, unit-tested and backtested against historical logs (and, where useful, validated with attack simulation), and track effectiveness quantitatively and qualitatively (MTTD, false-positive rate) to make data-driven decisions.

- Write production-quality software and automation to streamline security processes, automate response, and reduce manual work.

Secondary Responsibilities

- Help keep our security answers accurate: a key contributor to customer security questionnaires and RFPs, reviewing and updating existing answers and researching new ones where none exist, drawing on broad SOC 2, ISO and HIPAA knowledge and our existing answer library and tooling. You provide technical input, not the sales process.

- Support GRC: automate compliance evidence collection and help implement security controls.

- Contribute to threat modelling and security reviews alongside the rest of the team.

- Help guide our external penetration-testing partners on major product use cases.

- Support secure engineering practices and developer security awareness.

WHAT MAKES YOU THRIVE HERE

You have:

- Solid working knowledge of a major cloud (GCP and/or AWS) and of containers / Kubernetes.

- Hands-on experience building security monitoring through automation: logging and telemetry, detections, alerting, and automating response (a detection-as-code / infrastructure-as-code mindset).

- Experience with vulnerability management and coordinated remediation.

- Broad working knowledge of the security compliance frameworks Hoxhunt operates under (SOC 2, ISO 27001, ISO 42001 and HIPAA), enough to answer customer security questions confidently and support audits, plus awareness of the wider control-framework and regulatory landscape (NIST CSF, CIS, NIS2).

- Clear written and verbal communication; able to work across teams.

- Comfortable using modern AI tools…

Vaadittu osaaminen

Samankaltaiset työpaikat

Hae työnantajan sivuilla

Seuraava työpaikkasi on jo täällä.

Selaa tuhansien työnantajien avoimia paikkoja, tallenna kiinnostavat ja anna JobBobin pitää silmällä loput.