Junior Security Engineer, GRC

Hoxhunt

Helsinki

Hybrid

EUR 33,000 - 45,000

Full time

7 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Extensive healthcare
Beautiful Helsinki office
Gym and swimming pool

Job summary

Hoxhunt is hiring a Junior Security Engineer, GRC to join the Product Security team. You will own security questionnaires and RFP responses, coordinate evidence across SOC 2 Type II, ISO 27001, ISO 42001, and HIPAA, and drive vulnerability management with engineers.

You will partner with Sales, Product, and external teams in a fast-growing SaaS environment, leveraging AI tools to scale compliance while actively learning. Helsinki office visits required on hybrid schedule.

Qualifications

  • Customer-facing security work (RFPs and questionnaires).
  • Excellent written English with high attention to detail.
  • Organizational and project-management skills to lead RFP execution.
  • Familiarity with security frameworks (SOC 2, ISO 27001, HIPAA) or willingness to learn.

Responsibilities

  • Quarterback RFP and security questionnaire responses, triage requests, draft high-quality responses, coordinate input from experts, and drive submission.
  • Own evidence flow across SOC 2 Type II, ISO 27001, ISO 42001 and HIPAA; validate evidence and automate where possible.
  • Run vulnerability management cadence: review dashboards, route findings, track remediation against SLAs, report status.
  • Coordinate recurring security activities: pen tests, access reviews, policy reviews, and subprocessor reviews.
  • Maintain security knowledge base and external security documentation for sales.

Skills

GRC
RFP coordination
English writing

Education

Bachelor’s or Master’s in InfoSec/IT/Business

Tools

Vanta
Drata
Loopio
Hyperproof

Job description

Our mission and why it matters

We are on a mission to make humans the strongest security layer.

Human risk remains one of the biggest vulnerabilities and traditional awareness training is not enough. We take a different approach by combining AI-driven personalization, real threat detection, and behavioral science to actively protect people and organizations.

We don't just simulate risks. We build the tools that detect and stop them.

Why this role matters

We are looking for a Junior Security Engineer, GRC to join Hoxhunt's Product Security team. In this role, you will act as a quarterback for customer trust by taking the lead on the security questionnaires and RFPs that unblock sales deals, owning each case end-to-end. You will play a key role in our compliance footprint by collecting and validating evidence across the frameworks we operate under (SOC 2 Type II, ISO 27001, ISO 42001, HIPAA). You will also run the day-to-day coordination of our vulnerability management program and our recurring security activities. This is an excellent opportunity to build a career at the intersection of information security and business within a fast-growing SaaS company, with modern tooling and automation doing the heavy lifting. This is a growth role for someone with ambition. We hire juniors we expect to grow quickly, providing real ownership from week one and experienced mentors to support you.

What you'll do
  • Quarterback RFP and security questionnaire responses: Triage requests, draft high-quality responses using our answer library and tooling (Vanta), coordinate input from technical experts, and drive it through to submission.
  • Drive continuous compliance: Own the evidence flow across SOC 2 Type II, ISO 27001, ISO 42001 and HIPAA. Validate evidence collected through Vanta, handle manual needs, and work with engineers to automate processes to stay continuously audit-ready.
  • Run the vulnerability management coordination cadence: Review dashboards and automated triage output weekly, route findings to the code owners, track remediation against CVSS-based SLAs, elevate when needed, and report on status.
  • Run our recurring security activities: Own the regular calendar including coordinating penetration testing with external partners, quarterly access reviews, annual policy reviews and approvals, and annual subprocessor reviews.
  • Maintain our security knowledge base and sales collateral: Keep the answer library comprehensive, accurate, and current, and maintain external-facing security documentation that supports the sales process.
  • Close the loop: Track security-questionnaire outcomes, collect lessons learned from each RFP cycle, and feed recurring gaps back to Product, Sales, and the security team.
  • Support compliance reporting: Help prepare quarterly compliance status reporting for the Senior Management Team and keep procedures and policies documented.
  • Assist in preparing for external audits, maintaining our AI Management System (AIMS, ISO 42001), and acting as a point of contact for external vulnerability reports.
  • Research, propose, and deliver improvements to security controls and contribute to security automation initiatives.
What success looks like
  • In your first 3 months you'll: Get up to speed with our existing security answer library and compliance tooling, take ownership of incoming security questionnaires and RFPs, and begin coordinating vulnerability management cadences and recurring security activities.

  • By month 6 you'll: Smoothly drive continuous compliance and evidence validation, actively partner with engineers to automate manual compliance tasks, independently quarterback RFPs from triage to submission, and contribute to improvements in our security controls and knowledge base.

What makes you thrive here

You have:

  • A genuine desire to work in compliance and with customers. This role is customer-facing security work at its core and requires someone who truly wants to do this work.

  • Excellent written English with rigorous attention to detail to ensure every customer-facing answer is clear, accurate, professional, and error-free.

  • Organizational and project-management ability to lead RFP execution, identify stakeholders, assign ownership, and manage multiple deadlines.

  • An understanding of compliance frameworks (SOC 2, ISO 27001, ISO 42001, HIPAA, NIST) or a strong willingness to learn them quickly.

  • An understanding of security controls and best practices, or the drive to build it fast.

  • A self-motivated, continuous learning mindset where you actively teach yourself new frameworks, tools, and techniques.

  • Currently pursuing or completed a Bachelor's or Master's degree in Information Security, IT, Business, or a related field.

  • A mindset to use modern AI tools everywhere to expand and scale your reach, acting as a force multiplier.
    You don't need to meet every qualification on day one. Three things are non-negotiable: you want to work in compliance and with customers, you use AI to accelerate everything you do, and you teach yourself what you don't know. If that's you, we'd like to hear from you even if the rest is still growing.

Bonus points if you also:

  • Bring experience with GRC or RFP automation tools like Vanta, Drata, Loopio, or Hyperproof.

  • Have previous experience in compliance, audit, security, or technical-writing roles.

  • Possess basic programming or scripting skills (Python, Shell) for automation tasks.

  • Have exposure to vulnerability management concepts like CVSS, triage, and remediation tracking.

  • Understand AI-native, cloud-native, and SaaS business models.

Who you'll work with

You will work daily with the Product Security team, whose shared job is to address any security concern a product team or customer raises. You will not start from scratch or work alone; the team behind you includes experienced colleagues who own the frameworks and engineers who build the automation you run. You will report to the Director of Product Security, collaborating closely with Sales, Product, and external partners in an environment where continuous learning and automation are the default.

What you can expect from us
  • Compensation: Monthly salary of €3,000 - €4,000 depending on your experience. You may notice varying salary ranges for roles with similar titles across Hoxhunt; this is because each range is grounded in our role leveling and reflects the seniority, scope, and impact expectations required for that specific role and team, and we operate with a low hierarchy.

  • Working ways: We work in a flexible, but hybrid work setting. You are expected to visit the Helsinki office 2-3 days a week.

  • High performance meets high humanity: We bring an incredibly driven, high-impact energy to our work, but we leave our egos at the door. You will be surrounded by wildly talented, dedicated colleagues in an environment built on extreme kindness, support, and psychological safety.

  • Authentic trust & autonomy: We hire great people and trust them to do great work. You will find a culture free of micromanagement, giving you the autonomy to take real ownership, drive impact, and shape things early on.

  • A product you can be proud of: It is incredibly rare in cybersecurity to build a product that end-users genuinely love. You will join a fast-paced, technically sophisticated team making a real, measurable impact against cybercrime.

  • The perks that matter: Alongside this amazing community, you will enjoy extensive healthcare with other benefits and our beautiful office in Helsinki (complete with a gym and swimming pool!).

Recruitment Process

We want to get to know you and how you think! Our process includes:
1. Screening call with Talent Acquisition (30 min, remote)
2. Interview with the Director of Product Security (60 min, remote)
3. Case assignment and technical panel (90 min, onsite)
4. Reference checks and final offer

About Hoxhunt

Hoxhunt was founded in 2016 by four visionaries. Today we are a global team of +270 amazing Hoxhunters advancing a truly AI-native category leader in human risk management, with key hubs in the United States, the United Kingdom, Singapore, and Finland. We are proud to be an award-winning, fast-growing software company, recognized by G2 and Gartner, named to TIME Magazine's list of the World's Top EdTech Companies, and featured for our innovation in major publications like Fast Company, TechCrunch, Forbes, and Inc.

As a multi-product company, Hoxhunt goes beyond traditional security awareness. We don't just educate employees through frequent, personalized, and behavior-changing cybersecurity training - we also actively build real threat intelligence and response tools that protect organizations against malicious cyberattacks every single day.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Software Engineer, Security
Software Engineer, Security

Hoxhunt • Helsinki

Hybrid
EUR 50,000 - 67,000
Extensive healthcare
Office in Helsinki with gym and pool
Senior Software Engineer, Security
Senior Software Engineer, Security

Hoxhunt • Helsinki

Hybrid
EUR 67,000 - 84,000
Extensive healthcare
Helsinki office with gym and swimming
Hybrid work model
Senior Software Engineer, New product, Full-stack
Senior Software Engineer, New product, Full-stack

Hoxhunt, Inc. • Helsinki

Hybrid
EUR 67,000 - 84,000
Healthcare
Office in Helsinki
Gym and swimming pool
+1
Security Engineer
Security Engineer

Hoxhunt • Helsinki

Hybrid
EUR 50,000 - 67,000
Healthcare benefits
Helsinki office
Gym access
+1
Senior Software Engineer, Gamified Phishing Training
Senior Software Engineer, Gamified Phishing Training

Hoxhunt • Helsinki

Hybrid
EUR 67,000 - 84,000
Healthcare
Helsinki office
Gym
+1
Senior Software Engineer, New product, Threat Detection, Full-stack
Senior Software Engineer, New product, Threat Detection, Full-stack

Hoxhunt • Helsinki

Hybrid
EUR 72,000 - 90,000
Healthcare
Helsinki office facilities (gym & pool
(Senior) Financial Controller
(Senior) Financial Controller

Hoxhunt • Helsinki

Hybrid
Healthcare
Hybrid work setting
Office in Helsinki
Security Engineer, SecOps
Security Engineer, SecOps

Hoxhunt • Finland

Hybrid
EUR 4,000 - 6,000
Extensive healthcare
Office gym and swimming pool
Flexible working hours
Senior Product Designer
Senior Product Designer

Hoxhunt, Inc. • Helsinki

Hybrid
EUR 61,000 - 67,000
Gym and pool
Jacuzzi
Senior Software Engineer, New product, Full-stack
Senior Software Engineer, New product, Full-stack

Hoxhunt • Helsinki

Hybrid
Extensive healthcare benefits
Gym and swimming pool access
Flexible working setting