Security Operations Engineer (Europe - Remote)

SpotMe

Poland

On-site

PLN 180,000 - 260,000

Full time

18 hours ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

SpotMe is seeking a Security Operations Engineer to set and run the security configuration of the company across our tools, reporting to the Chief Security and Trust Officer. In this role you will own identity and access management, endpoint protection across macOS fleet, and security controls inside our dozen SaaS apps, plus build internal tooling with Claude Code.

This position emphasizes proactive risk reduction and active incident response, with a practical, hands-on approach suited for an

Qualifications

  • Experience configuring identity and access management across SaaS tools.
  • Experience with endpoint management and securing macOS fleet.
  • Ability to design roles and permissions in SaaS apps.
  • Experience with threat intelligence and security logging.
  • Ability to run onboarding/offboarding and access requests independently.

Responsibilities

  • Own security configuration across tools.
  • Manage identity, device management and internal telemetry.
  • Design roles and permission structures inside SaaS apps.
  • Build internal tooling and detection layer (Claude Code).
  • Lead incident response participation when needed.

Skills

Identity management
Endpoint security
SaaS tool configuration
Security logging and monitoring
Threat intelligence
Access reviews

Tools

Google Workspace
Claude Code

Job description

Mission - Why we exist, what we do, and why we need you

SpotMe is a leading B2B event platform that helps enterprises increase the impact of their events by delivering CRM-connected, high-quality experiences across in-person, virtual, hybrid events, and webinars. With a strong focus on life sciences, SpotMe powers Onomi: an HCP engagement product that enables medical and commercial teams to run impactful congresses, symposia, advisory boards, and webinars. Together, SpotMe and Onomi turn events into a company's most effective engagement channel.

This role sets and runs the security configuration of the company across different tools we use.

This position is the ideal role for someone who wants to raise the level of IT security in an environment where it carries real weight. Our customers are enterprises, and more than half a million healthcare professionals engage on Onomi every month. How our own accounts, laptops and tools are secured is part of that picture rather than a back-office concern. This is not about one access request or one control, it is about lifting the IT layer that everything else sits on.

As a Security Operations Engineer, you will be reporting to the Chief Security and Trust Officer and you will spend roughly:

  • 35% Identity, access and lifecycle. Joiners, movers and leavers, access requests and approvals, associate access, security hygiene across our SaaS tools, access reviews. Google Workspace is our identity layer.
  • 20% Endpoint management and protection. Implementing both across our macOS fleet, then keeping the fleet in a known state and triaging what the tooling reports once it is live.
  • 30% Security controls and access models inside our tools. Around a dozen SaaS applications, each with its own permission model, its own security controls, its own limits on what can actually be enforced, and its own logging capability. You will manage how each should be configured, design the role and permission structures inside them, work out what a given plan tier does and does not allow, and know where a tool is blind so we can compensate elsewhere. This also covers the alerts and logs from the tools we already have, including threat intelligence.
  • 15% Building internal tooling. Access reporting, cross-tool investigation, and a small, deliberately tuned detection layer. Built primarily with Claude Code, jointly with the CSTO, against a written specification that already exists.

This is an IT security role covering identity, device management and internal telemetry, with a real build component. It sits in security rather than IT because the work is judged on risk rather than on service.

The role is both preventive and reactive. Most of it is preventive: closing gaps before anyone else finds them, and building the visibility that shows you where they are. But when a security event happens, you are part of the response, and security events do not keep office hours. This is not a shift pattern or a formal on-call rotation, and it is not frequent.

Objectives - The problems you will solve

In your first 1 month:

  • You have a complete inventory of our tools and of how access to each one is granted and removed.
  • You know which accounts exist across those tools and which of them map to a real person.
  • You run onboarding, offboarding and access requests independently, without escalation.
  • You have given us your first read on the environment: the three or four things you would fix first, why each one matters, and what it would take.

After 3 months:

  • You have a view of the security settings in each cloud/SaaS tool we use, what each is capable of enforcing, and what it currently enforces.
  • You have recommended the changes worth making in priority order, and the first of them are already applied.
  • You have produced the plan and the recommendation for the new endpoint management and protection: the options, the obstacles we will hit, and how you would get past them.

After 6 months:

  • New endpoint management and protection are running across the fleet and you can report coverage.
  • There is one place that shows who has access to what across all tools, and access reviews run from it and produce the evidence export.
  • The new Security Dashboard is built to the point where a real investigation can be done in it.
What you need to be great at:
  • Working across multiple areas of security rather than specialising in one, in combination with "standard IT activities". Identity, endpoints, tool configuration and logging all sit in this role, and none of them get a dedicated person.
  • Judging the balance between security that limits people and what the business actually needs to get done. Knowing which control is worth the friction and which one will simply be worked around.
  • Because of our business, users often need immediate action. Some tickets can wait a week and some arrive as a Slack message because a customer event is happening now. Judging which is which, without treating everything as urgent or making people escape to get attention, is a daily call.
  • Google Workspace as an identity platform, including SSO and SAML app integration, groups and org units, admin roles and delegation, context-aware access, the security and admin audit logs and the alerts built on them.
  • Understanding the usage of APIs, minimally knowledge around REST and HTTP methods status codes, authentication via API keys, OAuth 2.0.
What we are most curious about:
  • How you decide between buying and building, what you base it on, and how the decision survives in real life.
  • Where you think the effort really belongs when it comes to security settings and capabilities, and which attack vectors matter most for a company like ours.
  • Your process for choosing security tools, what you rule out early, and what you insist on testing before anything gets signed.
  • How you adapt your views and actions based on publicly known security incidents and breaches.
  • How you handle the human pressure to override security requirements.
  • A detection or an alert you switched off, and what convinced you.

SpotMe recruits, compensates, and promotes regardless of race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability, age, parental status, or veteran status.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security & Compliance Engineer
Security & Compliance Engineer

Nomagic • Warszawa

Hybrid
PLN 180,000 - 260,000
Equity
Relocation package
Hybrid work in Warsaw
IT & Security Engineer
IT & Security Engineer

Nomagic, Inc. • Warszawa

Hybrid
PLN 180,000 - 240,000
Equity for every employee
Relocation package
Hybrid work from Warsaw
Product Security Engineer
Product Security Engineer

StackAI • Poland

On-site
PLN 235,000 - 322,000
Senior Application Security Engineer
Senior Application Security Engineer

PepsiCo • Warszawa

On-site
PLN 162,000 - 198,000
Senior Manager, Endpoint Protections
Senior Manager, Endpoint Protections

Elastic • Poland

On-site
PLN 598,000 - 946,000
Health coverage
Flexible locations
Generous vacation days
+3
Lead Security Operations Engineer
Lead Security Operations Engineer

Jobtailor • Wrocław

On-site
PLN 180,000 - 240,000
Software Engineer and Security Researcher
Software Engineer and Security Researcher

Commit • Warszawa

Hybrid
PLN 190,000 - 270,000
Security Engineer (DevSecOps)
Security Engineer (DevSecOps)

co.brick • Gliwice

Hybrid
PLN 180,000 - 260,000
Application Security Engineer | Senior
Application Security Engineer | Senior

Nord Security • Poland

On-site
Private health insurance
Flexible work arrangements
Physical well-being programs
+3
AppSec Expert
AppSec Expert

IDEMIA Group • Łódź

On-site