3 дня назад
Head of Security for a Sustainability SaaS
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Head of Security for a Sustainability SaaS (Application Security/Cloud Security): Defining security across globally used SaaS products and internal IT systems with an accent on threat modelling, incident response, identity security, and compliance. Focus on building the security function, leading penetration test scoping and triage, managing ISO 27001 and SOC 2 renewals, and coordinating security responses under pressure.
Location: Hybrid position for candidates based in Helsinki, Finland. Remote work is supported, with collaboration expected in the Helsinki office. Preference is given to EU citizens or candidates eligible to obtain the required security clearances.
Company
is a Helsinki-based B2B SaaS company providing life-cycle assessment and decarbonization software for buildings, infrastructure, manufacturing, and construction projects.
What you will do
- Define and maintain security strategy, standards, policies, processes, tooling, and cost management across the product and company.
- Lead application security through threat modelling, secure design, code review practices, and penetration test scoping and triage.
- Own incident response planning, tabletop exercises, and end-to-end incident command.
- Manage ISO 27001, SOC 2, and other security standard renewal efforts, while supporting customer security reviews, questionnaires, and audits.
- Partner with platform, internal IT, and support teams to secure cloud infrastructure, SaaS systems, integrations, and internal processes.
- Support GDPR and data protection obligations and manage the security analyst.
Requirements
- Hands-on experience with cloud and production infrastructure security in partnership with DevOps and platform teams.
- Experience influencing security outcomes in an organization where security does not directly own the accountable systems.
- Strong corporate and identity security knowledge covering SSO, endpoint management, email, SaaS governance, and integrations.
- Incident command experience under real pressure and the ability to communicate with both technical and executive audiences.
- Working familiarity with SOC 2, ISO 27001, GDPR, and data protection requirements.
- Based in Helsinki and preferably an EU citizen or eligible to obtain the required security clearances.
Nice to have
- CISSP, CISM, or CISA certification.
Culture & Benefits
- Hybrid work with remote working support and collaboration in the Helsinki office.
- High autonomy, flexible working, and a low-hierarchy environment.
- Direct communication with the CTO and executive team.
- International, diverse, and supportive team representing more than 40 nationalities.
- Work focused on decarbonizing construction and manufacturing and supporting a zero-carbon future.
Hiring process
- Applications are reviewed upon receipt.
- Applications are accepted until 20 September 2026.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
4 дня назад
Senior ICT Specialist, Security (Cybersecurity)
8 дней назад
AI Security Consultant
4 дня назад
Junior Security Engineer (GRC)
3 000 - 4 000€
8 дней назад
Managing Consultant - FS - Digital Trust and Cyber Security
4 дня назад
Lead Security Engineer (Cybersecurity)
8 дней назад