Still hiring?
14 checks1 red flag
Browse
All Tech JobsThe whole board, newest first.Roles That Fit MeAnswer a few questions, see your matches.Early WindowFound before the big boards.Direct ApplyStraight to the manager, past the ATS.By specialty
Your materials
CV AnalyzerWhat an ATS sees, and what to fix.Tailor CVBrought in line with one posting.Cover LetterWritten from your CV and the role.You and the process
Hey, I’m Wayjo. I find roles before the big boards.
Free to browse. An account unlocks the rest.
Jobs
All Tech JobsThe whole board, newest first.Roles That Fit MeAnswer a few questions, see your matches.Early WindowFound before the big boards.Direct ApplyStraight to the manager, past the ATS.€72,000 - 90,000/ year
The whole posting in a few lines. Sign up to read it here and on every role you open.
Sign Up to ReadOur mission and why it matters
We are on a mission to make humans the strongest security layer.
Human risk remains one of the biggest vulnerabilities and traditional awareness training is not enough. We take a different approach by combining AI-driven personalization, real threat detection, and behavioral science to actively protect people and organizations.
We don't just simulate risks. We build the tools that detect and stop them.
Why this role matters
We're growing fast, over 50% year over year, and our security has to scale with the product: through tooling and code, not headcount. There is no manned SOC here and no plans for one.
You will build our security observability: the pipeline that collects, processes and routes security events and logs across our Google Cloud platform, and the detections, alerting and dashboards on top of it. You won't start from zero. Dashboards, audit logging, alerting and a SIEM build-out are underway, and you inherit working security automation: an automated vulnerability triager covering our npm, Maven, Go and Python ecosystems, remediation nudging with CI tests, and the scanning-stack integrations around them. Your job is to take all of it from working to excellent.
What you'll own and drive
Own the architecture and outcomes of our security event and log pipeline on GCP, and the detections, alerting and dashboards on top of it, engineered as code: reviewed, tested, deployed through CI/CD.
Own and extend our security automation: the vulnerability triager, the remediation nudging automation, and our scanning-stack integrations (GitHub Advanced Security, dependency ownership, issue sync).
Build and improve the tooling our GRC function relies on every day.
Turn recurring manual security work into code, for example automating our churned-customer data-removal monitoring end to end.
Harden our cloud security architecture together with SRE/Platform: trust boundaries, IAM and least privilege, network egress, secrets, infrastructure-as-code.
Drive technical decisions and mentor through code review: act as a multiplier who raises the bar on how security software gets built here.
Contribute to our agentic security tooling (AI-assisted PR review and security review) alongside the team.
What makes you thrive here
You'll probably have at least five years of experience building production software, but we care less about how long you've been active and more about what you've built, how it was built, and why it worked. You are comfortable owning outcomes at system scale, turning ambiguous problems into shipped systems, and influencing how adjacent teams build securely.
Part of the week in the office
Hoxhunt
Office in Helsinki, Finland
Also hiring in Minneapolis, United States
Worth a look before you spend an evening tailoring a CV for it.
Still hiring?
14 checks1 red flag
How crowded?
7 checks1 red flag
How well does this role fit you?
Answer a few questions or drop your CV, and every role gets a fit score with the reasons, this one first.
Something wrong with this vacancy?