Stand out for this role — generate a tailored resume and cover letter in about a minute.
One Click LCA Ltd. is seeking an experienced Head of Security to lead security across our SaaS products and internal IT. This hands-on practitioner-leader role combines strategic direction with active security delivery and incident readiness.
Based in Helsinki, you will own security strategy, standards and policy, while working with DevOps, platform and support teams. The role focuses on ISO 27001, SOC 2, GDPR and secure design in a rapidly growing global SaaS business.
We are looking for an experienced security professional to serve as our Head of Security, leading security across our globally used SaaS products and internal IT environment. This is a hands‑on practitioner‑leader role, not an oversight role for an established function.
One Click LCA is the construction industry’s leading digital platform for Life Cycle Assessment for buildings, infrastructure, and manufacturing. As a fast-growing, well‑funded, and profitable B2B SaaS business, our solutions are used in over 170 countries, across +50,000 global construction projects, with +300,000 certified construction data points, and trusted by the biggest names in construction and manufacturing.
You will join a supportive, effective, and mission-oriented team in a flexible, friendly, and international work environment, with a great deal of autonomy in your role.
This full‑time, permanent position is available on a hybrid basis for candidates based in Helsinki.
Due to the nature of this role and applicable security requirements, preference will be given to candidates who are EU citizens or otherwise eligible to obtain the required security clearances.
Own security as a discipline across both product and company perspectives, setting or updating strategy, standards and policy where needed.
Own application security hands‑on: threat modelling, secure design principles and code review practices, penetration test scoping and triage.
Own incident response end‑to‑end: the plan, the tabletop exercises, and being ready for the day we need it.
Manage ISO 27001, SOC 2 and other standard renewal efforts, and support customer security reviews, questionnaires and audits.
Work with our platform, internal IT and support teams to secure our internal systems and processes. We run entirely on SaaS, with no self‑hosted servers.
Support our GDPR and data protection obligations.
Act as a manager to our security analyst who supports you in your area.
Cloud and production infrastructure security experience, working in partnership with DevOps and platform teams rather than running the infrastructure yourself.
Experience operating through influence rather than headcount, in an organisation where security doesn't own the systems it's accountable for.
Corporate and identity security depth in SSO, endpoint management, email, SaaS governance and integrations, with good judgment about where the real risk sits.
Incident command experience under real pressure, and the composure that goes with it.
Credibility in both directions: you can hold your own in a system review and be clear with an executive audience the same afternoon.
Familiarity with SOC 2, ISO 27001 and GDPR, enough to set direction without needing to run the audit yourself. CISSP, CISM or CISA are welcome but won't substitute for hands‑on depth.
A security function you define rather than inherit, including cost management, processes and tooling related to security.
The combination of SaaS product security and internal security in a global company.
Work in a growing business that helps bring about a zero‑carbon future.
Remote working is supported, though we hope you will also enjoy collaborating with colleagues in our Helsinki office.
A friendly, motivated and diverse team of experienced professionals, social events, and the chance to contribute to a zero‑carbon future.
No bureaucracy: direct communication with the CTO and executive team, and a short path from problem to decision.