About the role
You'll be VaultSpeed's first dedicated security engineer, working alongside a three-person Platform team. The security foundations and policies are already in place. Your job is to turn them into everyday practice: implement controls, automate processes, set standards for the team and report on risk.
Expect a mix of roughly half compliance, a quarter hands-on security engineering, and a quarter automation and improvement work. You'll have a lot of freedom to decide how things get done.
What you'll do
• Own ISO 27001 compliance day to day: maintain controls and evidence, coordinate access reviews, support risk assessments and audits, and automate as much of it as possible
• Roll out and manage device management (MDM) for company laptops: enrolment, security baselines, encryption, patching and secure offboarding
• Build and maintain automated security scanning in CI/CD pipelines, covering code, dependencies, secrets, container images and infrastructure as code, and help developers fix what it finds
• Set security standards and guardrails for engineering, and write clear policies that explain why they matter
• Track vulnerabilities, assess their impact and report risks in plain terms to the team and management
• Automate manual security and IT processes
• Work with Platform on cloud, identity and container security, and take part in incident response
Requirements
– Mid-to-senior experience in security, DevOps, system administration or development, with real security responsibility
– Hands-on involvement in ISO 27001 audit or certification preparation
– Experience implementing or administering an MDM solution
– Working knowledge of Docker and containers
– Scripting skills for automation (Python, PowerShell or similar)
– Experience with security scanning, vulnerability management and reporting
– Comfortable using AI tools in your daily work
– A proactive approach: you take ownership and see things through
– Proficient English
Nice to have
– Kubernetes
– Azure (AWS or GCP experience is fine if you’re open to switching)
– Experience with a compliance automation platform
– Having led an ISO 27001 audit or certification
Company offers
– The chance to shape security as the company’s first dedicated hire
– Remote-first work, with hybrid possible
– Private health insurance
– Company events
– A relaxed, supportive team with real freedom to propose ideas and make decisions
Don't miss this opportunity! Let the employer know that You are interested.
Job ads are inserted by Employers. They are not edited or corrected.
You can enter your question here. The question will appear on the job ad as soon as employer has answered it. Your e-mail will be hidden for visitors then. NB! This is public forum. Questions and answers are visible for all users.
Send to Friend
A link to an ad will be added automatically at the end of the message.
Please fill out all the fields marked with asterisk!