Назад
Company hidden
2 часа назад

Junior Security Engineer (GRC)

3 000 - 4 000
Формат работы
hybrid
Тип работы
fulltime
Грейд
junior
Английский
b2
Страна
UK/Singapore/US +1 еще
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Junior Security Engineer (GRC) (Cybersecurity/GRC): Coordinating customer security questionnaires, RFP responses, continuous compliance evidence, vulnerability management, and recurring security activities with an accent on SOC 2, ISO 27001, ISO 42001, HIPAA, and security automation. Focus on validating audit evidence, tracking CVSS-based remediation, coordinating penetration testing and access reviews, and improving security controls with AI-enabled tooling.

Location: Helsinki, Finland; hybrid work with a weekly visit to the Helsinki office

Salary: €3,000–€4,000 per month, depending on experience

Company

hirify.global is an AI-native cybersecurity software company building human risk management, threat detection, and response tools for organizations.

What you will do

  • Own customer security questionnaires and RFP responses from triage through submission, coordinating input from technical experts.
  • Drive continuous compliance evidence collection and validation across SOC 2 Type II, ISO 27001, ISO 42001, and HIPAA using Vanta.
  • Coordinate weekly vulnerability management activities, route findings to code owners, track CVSS-based remediation SLAs, and escalate issues.
  • Coordinate recurring security activities, including penetration tests, quarterly access reviews, annual policy reviews, and subprocessor reviews.
  • Maintain the security knowledge base, answer library, and customer-facing security documentation.
  • Support compliance reporting, external audits, the AI Management System, vulnerability reports, and security automation improvements.

Requirements

  • Genuine interest in compliance and customer-facing security work.
  • Excellent written English with rigorous attention to detail.
  • Strong organizational and project-management skills for coordinating stakeholders and deadlines.
  • Understanding of security controls and compliance frameworks including SOC 2, ISO 27001, ISO 42001, HIPAA, or NIST, or the ability to learn them quickly.
  • Self-motivated continuous-learning mindset and willingness to use AI tools to accelerate work.
  • Currently pursuing or having completed a Bachelor's or Master's degree in Information Security, IT, Business, or a related field.

Nice to have

  • Experience with GRC or RFP automation tools such as Vanta, Drata, Loopio, or Hyperproof.
  • Previous experience in compliance, audit, security, or technical writing.
  • Basic Python or Shell scripting skills for automation.
  • Exposure to vulnerability management, CVSS, triage, and remediation tracking.
  • Understanding of AI-native, cloud-native, and SaaS business models or agent-based software development.

Culture & Benefits

  • Flexible hybrid working environment with a Helsinki office featuring a gym and swimming pool.
  • High-performance culture focused on kindness, support, and psychological safety.
  • Autonomy, low hierarchy, and meaningful ownership without micromanagement.
  • Extensive healthcare and additional employee benefits.
  • Mentorship from experienced Product Security colleagues and collaboration with Sales, Product, Engineering, and external partners.

Hiring process

  • 30-minute remote screening call with Talent Acquisition.
  • 60-minute remote interview with the Director of Product Security.
  • 90-minute onsite case assignment and technical panel, followed by reference checks and a final offer.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →