About the role
You'll be VaultSpeed's first dedicated security engineer, working alongside a three-person Platform team. The security foundations and policies are already in place. Your job is to turn them into everyday practice: implement controls, automate processes, set standards for the team and report on risk.
Expect a mix of roughly half compliance, a quarter hands-on security engineering, and a quarter automation and improvement work. You'll have a lot of freedom to decide how things get done.
What you'll do
• Own ISO 27001 compliance day to day: maintain controls and evidence, coordinate access reviews, support risk assessments and audits, and automate as much of it as possible
• Roll out and manage device management (MDM) for company laptops: enrolment, security baselines, encryption, patching and secure offboarding
• Build and maintain automated security scanning in CI/CD pipelines, covering code, dependencies, secrets, container images and infrastructure as code, and help developers fix what it finds
• Set security standards and guardrails for engineering, and write clear policies that explain why they matter
• Track vulnerabilities, assess their impact and report risks in plain terms to the team and management
• Automate manual security and IT processes
• Work with Platform on cloud, identity and container security, and take part in incident response
Requirements
– Mid-to-senior experience in security, DevOps, system administration or development, with real security responsibility
– Hands-on involvement in ISO 27001 audit or certification preparation
– Experience implementing or administering an MDM solution
– Working knowledge of Docker and containers
– Scripting skills for automation (Python, PowerShell or similar)
– Experience with security scanning, vulnerability management and reporting
– Comfortable using AI tools in your daily work
– A proactive approach: you take ownership and see things through
– Proficient English
Nice to have
– Kubernetes
– Azure (AWS or GCP experience is fine if you’re open to switching)
– Experience with a compliance automation platform
– Having led an ISO 27001 audit or certification
Company offers
– The chance to shape security as the company’s first dedicated hire
– Remote-first work, with hybrid possible
– Private health insurance
– Company events
– A relaxed, supportive team with real freedom to propose ideas and make decisions
Nepraleiskite savo galimybės ir kandidatuokite dabar.
Jūs galite pateikti klausimą darbdaviui. Klausimas atsiras skelbime iškart, kai tik darbdavys atsakys į jį. Lanktytojai negalės matyti jūsų el. pašto adreso.
Persiųsti
Nuoroda į skelbimą bus pridėta automatiškai žinutės pabaigoje.