Get more replies from employers
Send a job-specific resume in minutes.
Hoxhunt in Helsinki is looking for a Security Engineer, SecOps to mature our security monitoring into an automation-first operations capability. You will own detections, observability, and response, and translate customer requirements into features and policy proposals with the help of our existing tooling (Vanta) and security answers.
You’ll collaborate with engineering and SRE teams to implement SAST/DAST/SCA, manage vulnerabilities end-to-end, and drive secure development practices.
We are on a mission to make humans the strongest security layer. Human risk remains one of the biggest vulnerabilities and traditional awareness training is not enough. We take a different approach by combining AI-driven personalization, real threat detection, and behavioral science to actively protect people and organizations. We don't just simulate risks. We build the tools that detect and stop them.
We're looking for a Security Engineer, SecOps to join Hoxhunt's Product Security team. Your core mission is to help mature our security monitoring into a stronger, automation-based security operations capability. We already have the foundations in place, and we want you to build on them with detection, observability and response delivered through tools and automation rather than a staffed SOC. You'll also coordinate vulnerability management across our engineering teams and write the production code and automation that makes security scale.
You’ll also help keep our customer security answers accurate, working with the team on the security questionnaires and RFPs that unblock deals. This is a real and recurring part of the job, roughly 10-30% of your time depending on deal flow: reviewing and updating our existing security answers, and researching new ones where none exist yet, drawing on broad SOC 2, ISO and HIPAA knowledge, with the occasional customer call when a deal needs technical depth.
Beyond supporting deals, you'll also help turn customers' security and compliance requirements into product features and policy proposals, helping close the loop between what customers ask for and what we build. You won't start from scratch or do it alone: there's an existing library of security answers and compliance tooling (Vanta) behind you, and the team shares the load. The team's job is simple to state: address any security concern a product team or customer raises, and you'll be part of that.
This is an engineering role, not an analyst or shift-based one. You'll bring real, hands-on instinct for incident response and case management, and the job is to turn that instinct into systems: codifying it into automation, playbooks and tooling so detection and response scale without scaling headcount. Product Security is a small, high-leverage team: we work through discovery, planning and influence, and most implementation happens across the wider Technology organisation. You'll add the delivery muscle and the automation-first mindset to keep maturing our security roadmap (security observability, SIEM build-out, vulnerability management). We expect you to use modern AI tools throughout your work to expand and scale your reach.
You’ll own security capabilities that help us detect, respond, and scale security through engineering.
You have:
You don't need to meet every qualification on day one. If you're a strong engineer with the right instincts and you're excited to grow into the rest, we'd still like to hear from you.
This is a rare opportunity to combine building, breaking, and operating in a broad security engineering role. You’ll write production code, design how we detect and respond through automation, and act as a force multiplier for security across the engineering organization. You’ll report to the Director of Product Security and work closely with experienced colleagues across Product Security, SRE, and the product teams, with plenty of opportunity to shape how we build, operate, and scale security.
Hoxhunt was founded in 2016 by four visionaries. Today we are a global team of +270 amazing Hoxhunters advancing a truly AI-native category leader in human risk management, with key hubs in the United States, the United Kingdom, Singapore, and Finland. We are proud to be an award-winning, fast-growing software company, recognized by G2 and Gartner, named to TIME Magazine's list of the World's Top EdTech Companies, and featured for our innovation in major publications like Fast Company, TechCrunch, Forbes, and Inc.
As a multi-product company, Hoxhunt goes beyond traditional security awareness. We don't just educate employees through frequent, personalized, and behavior-changing cybersecurity training - we also actively build real threat intelligence and response tools that protect organizations against malicious cyberattacks every single day.
Solid working knowledge of a major cloud (GCP and/or AWS), Knowledge of containers and Kubernetes, Hands-on experience building security monitoring through automation (logging, telemetry, detections, alerting), Experience with vulnerability management and coordinated remediation, Broad working knowledge of security compliance frameworks (SOC 2, ISO 27001, ISO 42001, HIPAA), Ability to write production-quality software in JavaScript, Python, or Go, Clear written and verbal communication skills, Comfortable using modern AI tools to scale effectiveness