Oh My JobFind Jobs
Company
  • About Us
  • Blog
  • Contact
Tools
  • Paycheck Calculator
Legal
  • Terms of Service
  • Privacy Policy
  • California Privacy Rights
For Employers
Post a Job

Security Engineer, SecOps

Hoxhunt
Hoxhunt
Helsinki, Finland
Jul 2, 2026
€4.5K – €6K per month
FullTime

Job Description

About the Role

Hoxhunt is seeking a Security Engineer, SecOps to join the Product Security team in Helsinki. You'll build and mature our security monitoring into an automation-driven capability, moving from manual processes to detection-as-code and infrastructure-as-code approaches. This is a hands-on engineering role where you'll own security detections, observability, vulnerability management, and cloud security architecture while supporting compliance requirements and customer security questionnaires.

Responsibilities

  • Build and improve security monitoring end-to-end: develop detections and alerting, tune and maintain them, and contribute to SIEM build-out and automation-based security operations (not a staffed SOC).
  • Own security observability including audit logging, security telemetry, and dashboards that engineering teams rely on.
  • Coordinate vulnerability management across the engineering organization: triage, prioritize by CVSS and exploitability, and drive remediation in partnership with product teams.
  • Strengthen cloud security architecture on GCP: implement network segmentation, egress controls, IAM and least-privilege access, secrets management, and infrastructure-as-code in collaboration with SRE and Platform teams.
  • Support the secure development lifecycle: implement SAST, DAST, SCA, and secrets scanning across deployment pipelines.
  • Write production-quality software and automation to streamline security processes, automate response, and reduce manual work.
  • Treat detections as code: peer-review, unit-test, and backtest against historical logs; validate with attack simulation where appropriate; measure effectiveness (MTTD, false-positive rates) to drive data-driven decisions.
  • Help connect customer security and compliance requirements to product features and policy proposals, turning customer asks into concrete roadmap items.
  • Contribute to customer security questionnaires and RFPs (10–30% of time depending on deal flow): review and update existing security answers and research new ones, drawing on SOC 2, ISO 27001, ISO 42001, and HIPAA knowledge.
  • Support GRC: automate compliance evidence collection and help implement security controls.
  • Participate in threat modeling, security reviews, and guidance for external penetration-testing partners on major product use cases.

Requirements

  • Solid working knowledge of GCP and/or AWS and containers/Kubernetes.
  • Hands-on experience building security monitoring through automation: logging, telemetry, detections, alerting, and response automation with a detection-as-code and infrastructure-as-code mindset.
  • Experience with vulnerability management and coordinated remediation across teams.
  • Broad working knowledge of SOC 2, ISO 27001, ISO 42001, and HIPAA frameworks; able to answer customer security questions confidently and support audits; awareness of NIST CSF, CIS, and NIS2.
  • Clear written and verbal communication; ability to collaborate across teams.
  • Proficiency writing production-quality software in at least one programming language (JavaScript, Python, or Go) for cloud deployment.
  • Self-motivated with a commitment to continuous learning; comfortable with modern AI tools to expand impact and scale effectiveness.

Preferred Qualifications

  • Detection engineering and/or SIEM build-out experience.
  • Front-line SOC or incident-response background: hands-on detection and response work with a desire to automate and scale.
  • Familiarity with secure-development tooling (SAST, DAST, SCA, secrets scanning) and concepts such as OWASP and threat modeling.
  • Hands-on experience implementing controls, running audits, or automating compliance evidence (e.g., with GRC platforms like Vanta).
  • Distributed or large-scale systems experience.
  • Bug-bounty experience or open-source/security community contributions (CVEs, talks).
  • Understanding of SaaS and cloud-native business models.

Benefits

  • Monthly salary: €4,500–€6,000 depending on experience.
  • Flexible hybrid work with weekly Helsinki office visits expected.
  • Comprehensive healthcare and additional benefits.
  • Access to a modern Helsinki office with gym and swimming pool.
  • Work with a driven, high-impact team in a culture emphasizing psychological safety, support, and autonomy.
  • Opportunity to shape security architecture and practices in a fast-growing, award-winning organization.
Apply now
Share: