Security Engineer, SecOps

Hoxhunt

Finland

On-site

EUR 54,000 - 72,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Extensive healthcare
Office gym and swimming pool
Flexible working hours

Job summary

Hoxhunt in Finland is seeking a Security Engineer, SecOps to help mature their security operations. The role focuses on building automation for security monitoring while coordinating with product teams to ensure customer requirements are met.

You'll be involved in managing vulnerabilities, writing production-quality software, and shaping security policies, contributing to a strong and scalable security framework. The position offers a hybrid work environment with a competitive salary between €4,500 and €6,000/month.

Qualifications

  • Solid understanding of security monitoring practices and tooling.
  • Experience in building and operating security automation.
  • Familiarity with SOC 2, ISO 27001, and HIPAA compliance frameworks.

Responsibilities

  • Build and improve security monitoring through automation.
  • Coordinate vulnerability management processes across teams.
  • Turn customer security requirements into action plans.

Skills

Security monitoring
Automation
Incident response
Vulnerability management
GCP/AWS

Tools

JavaScript
Python
Go

Job description

Our mission and why it matters

We are on a mission to make humans the strongest security layer.

Human risk remains one of the biggest vulnerabilities and traditional awareness training is not enough. We take a different approach by combining AI-driven personalization, real threat detection, and behavioral science to actively protect people and organizations.

We don't just simulate risks. We build the tools that detect and stop them.

Why this role matters

We're looking for a Security Engineer, SecOps to join Hoxhunt's Product Security team. Your core mission is to help mature our security monitoring into a stronger, automation-based security operations capability. We already have the foundations in place, and we want you to build on them with detection, observability and response delivered through tools and automation rather than a staffed SOC. You'll also coordinate vulnerability management across our engineering teams and write the production code and automation that makes security scale.

You'll also help keep our customer security answers accurate, working with the team on the security questionnaires and RFPs that unblock deals. This is a real and recurring part of the job, roughly 10-30% of your time depending on deal flow: reviewing and updating our existing security answers, and researching new ones where none exist yet, drawing on broad SOC 2, ISO and HIPAA knowledge, with the occasional customer call when a deal needs technical depth.

Beyond supporting deals, you'll also help turn customers' security and compliance requirements into product features and policy proposals, helping close the loop between what customers ask for and what we build. You won't start from scratch or do it alone: there's an existing library of security answers and compliance tooling (Vanta) behind you, and the team shares the load. The team's job is simple to state: address any security concern a product team or customer raises, and you'll be part of that.

This is an engineering role, not an analyst or shift-based one. You'll bring real, hands‑on instinct for incident response and case management, and the job is to turn that instinct into systems: codifying it into automation, playbooks and tooling so detection and response scale without scaling headcount. Product Security is a small, high‑leverage team: we work through discovery, planning and influence, and most implementation happens across the wider Technology organisation. You'll add the delivery muscle and the automation‑first mindset to keep maturing our security roadmap (security observability, SIEM build‑out, vulnerability management). We expect you to use modern AI tools throughout your work to expand and scale your reach.

What you'll own and drive

You will own security capabilities that help us detect, respond, and scale security through engineering.

Primary Responsibilities
  • Build and improve our security monitoring: own detections and alerting end-to-end (build, tune, maintain) and contribute to maturing our wider automation‑based capability and SIEM build‑out, with detection and response running through tools and code, not a manned SOC.
  • Build and operate our security observability: audit logging, security telemetry, and the dashboards/signals the rest of engineering relies on.
  • Coordinate vulnerability management end-to-end: triage, prioritise (CVSS plus exploitability and context), and drive remediation in partnership with the teams that own the code.
  • Strengthen our cloud security architecture: implement and help shape network segmentation and egress controls, IAM and least‑privilege, secrets management and infrastructure‑as‑code on GCP, partnering with SRE/Platform.
  • Help connect customer requirements to what we build: turn security and compliance requirements from customers and frameworks into concrete feature and policy proposals, surfacing gaps to the team and roadmap.
  • Strengthen the secure development lifecycle: SAST, DAST, SCA, and secrets scanning across our pipelines.
  • Measure and test what we build: treat detections as code that is peer‑reviewed, unit‑tested and backtested against historical logs (and, where useful, validated with attack simulation), and track effectiveness quantitatively and qualitatively (MTTD, false‑positive rate) to make data‑driven decisions.
  • Write production‑quality software and automation to streamline security processes, automate response, and reduce manual work.
Secondary Responsibilities
  • Help keep our security answers accurate: a key contributor to customer security questionnaires and RFPs, reviewing and updating existing answers and researching new ones where none exist, drawing on broad SOC 2, ISO and HIPAA knowledge and our existing answer library and tooling. You provide technical input, not the sales process.
  • Support GRC: automate compliance evidence collection and help implement security controls.
  • Contribute to threat modelling and security reviews alongside the rest of the team.
  • Help guide our external penetration‑testing partners on major product use cases.
  • Support secure engineering practices and developer security awareness.
What makes you thrive here
  • Solid working knowledge of a major cloud (GCP and/or AWS) and of containers / Kubernetes.
  • Hands‑on experience building security monitoring through automation: logging and telemetry, detections, alerting, and automating response (a detection‑as‑code / infrastructure‑as‑code mindset).
  • Experience with vulnerability management and coordinated remediation.
  • Broad working knowledge of the security compliance frameworks Hoxhunt operates under (SOC 2, ISO 27001, ISO 42001 and HIPAA), enough to answer customer security questions confidently and support audits, plus awareness of the wider control‑framework and regulatory landscape (NIST CSF, CIS, NIS2).
  • Clear written and verbal communication; able to work across teams.
  • Comfortable using modern AI tools to expand your impact, automate repetitive work, and scale your effectiveness.
  • Self‑motivated, continuous learning is a must: you actively teach yourself new tools, threats and techniques and keep your skills current.
  • Ability to write production‑quality software as part of a team in at least one real programming language (JavaScript, Python or Go) for cloud deployment.
Bonus points if you also
  • Detection engineering and/or SIEM build‑out experience.
  • A front‑line SOC or incident‑response background is a plus: you've done hands‑on detection and response and now want to automate and scale it rather than do manual triage.
  • Familiarity with secure‑development tooling (SAST, DAST, SCA, secrets scanning) and core concepts such as OWASP and threat modelling.
  • Hands‑on experience implementing controls or running audits, and automating compliance evidence (e.g. with a GRC platform such as Vanta).
  • Distributed / large‑scale systems experience.
  • Bug‑bounty experience; contributions to the open‑source or security community (CVEs, talks).
  • Understanding of SaaS and cloud‑native business models.
What makes this role unique

This is a rare opportunity to combine building, breaking, and operating in a broad security engineering role. You'll write production code, design how we detect and respond through automation, and act as a force multiplier for security across the engineering organization. You'll report to the Director of Product Security and work closely with experienced colleagues across Product Security, SRE, and the product teams, with plenty of opportunity to shape how we build, operate, and scale security.

What you can expect from us
  • Compensation: Monthly salary of €4,500-€6,000 per month depending on your experience.
  • Working ways: We work in a flexible, hybrid work setting. You are expected to visit the Helsinki office weekly.
  • High performance meets high humanity: We bring an incredibly driven, high‑impact energy to our work, but we leave our egos at the door. You will be surrounded by wildly talented, dedicated colleagues in an environment built on extreme kindness, support, and psychological safety.
  • Authentic trust & autonomy: We hire great people and trust them to do great work. You will find a culture free of micromanagement, giving you the autonomy to take real ownership, drive impact, and shape things early on.
  • A product you can be proud of: It is incredibly rare in cybersecurity to build a product that end‑users genuinely love. You will join a fast‑paced, technically sophisticated team making a real, measurable impact against cybercrime.
  • The perks that matter: Alongside this amazing community, you will enjoy extensive healthcare with other benefits and our beautiful office in Helsinki (complete with a gym and swimming pool!).
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Engineer
Security Engineer

Hoxhunt • Helsinki

Hybrid
EUR 50,000 - 67,000
Healthcare benefits
Helsinki office
Gym access
+1
Senior Software Engineer, New product, Full-stack
Senior Software Engineer, New product, Full-stack

Hoxhunt • Helsinki

Hybrid
Extensive healthcare benefits
Gym and swimming pool access
Flexible working setting
(Senior) Financial Controller
(Senior) Financial Controller

Hoxhunt • Helsinki

Hybrid
Healthcare
Hybrid work setting
Office in Helsinki
Product Marketing Manager
Product Marketing Manager

Hoxhunt • Helsinki

Hybrid
EUR 50,000 - 67,000
Healthcare
Helsinki office with gym & pool
Staff Security Engineer
Staff Security Engineer

Supermetrics • Helsinki

On-site
EUR 90,000 - 130,000
Equity
Home office allowance
Annual personal learning budget
+1
Senior Product Analyst
Senior Product Analyst

Hoxhunt • Helsinki

Hybrid
EUR 100,000 - 130,000
Healthcare
Office Helsinki gym & pool
Senior Product Analyst, Team Lead
Senior Product Analyst, Team Lead

Hoxhunt • Helsinki

Hybrid
EUR 65,000 - 85,000
Extensive healthcare
Gym and swimming pool in office
Account Executive
Account Executive

Hoxhunt • Helsinki

Hybrid
EUR 42,000 - 50,000
Extensive healthcare
Office in Helsinki
Gym and swimming pool
+1
Lead Security Engineer
Lead Security Engineer

Sineeng • Tampere

On-site
EUR 120,000 - 180,000
Paid Time Off
Health & Wellness Package
Lunch Benefit
+14
Lead Security Engineer, Product & Platform Security
Lead Security Engineer, Product & Platform Security

Sine Engineering • Tampere

On-site
EUR 120,000 - 190,000
Paid time off
Health & wellbeing package
High-end equipment
+3