660,302open jobs
38,440companies
97,349added this week
Browse all
Salary
$42k – $55k per year
Location
Remote/Hybrid (Helsinki, Finland)
Seniority
Junior
Employment
Full-Time
Overview
Company
Impact
Profile match
Hoxhunt is a human risk management platform that automates adaptive phishing training, security awareness training, and email incident response to measurably reduce employee cyber risk across the enterprise.

Our mission and why it matters

We are on a mission to make humans the strongest security layer.

Human risk remains one of the biggest vulnerabilities and traditional awareness training is not enough. We take a different approach by combining AI-driven personalization, real threat detection, and behavioral science to actively protect people and organizations.

We don't just simulate risks. We build the tools that detect and stop them.

Why this role matters

We are looking for a Junior Security Engineer, GRC to join Hoxhunt's Product Security team. In this role, you will act as a quarterback to support customer trust by helping with the security questionnaires and RFPs that unblock sales deals, seeing each case through with guidance from senior teammates. You will also play a key role in our compliance footprint by helping collect and validate evidence across the frameworks we operate under (SOC 2 Type II, ISO 27001, ISO 42001, HIPAA), and you will learn to run the day-to-day coordination of our vulnerability management program and our recurring security activities. This is an excellent opportunity to build a career at the intersection of information security and business within a fast-growing SaaS company, with modern tooling and automation doing the heavy lifting. This is a growth role for someone with ambition. We hire juniors we expect to grow quickly, and we invest in making that happen by providing real ownership from week one and experienced mentors to support you.

What you'll do

  • Quarterback RFP and security questionnaire responses: See each case you take through, end-to-end, with guidance from senior teammates. Triage the request, draft high-quality responses using our answer library and tooling, coordinate input from technical experts when needed, and drive it through to submission.

  • Support continuous compliance: Help manage the evidence flow across SOC 2 Type II, ISO 27001, ISO 42001 and HIPAA. Validate evidence collected continuously through Vanta, handle manual needs, and work with engineers to automate processes to stay continuously audit-ready.

  • Learn to run the vulnerability management coordination cadence: Review dashboards and automated triage output weekly, route findings to the code owners, track remediation against our CVSS-based SLAs, escalate when needed, and report on status.

  • Coordinate our recurring security activities: Help manage the regular calendar including coordinating penetration testing with external partners, access and policy review cycles, and subprocessor reviews.

  • Maintain our security knowledge base and sales collateral: Keep the answer library comprehensive, accurate, and current, and maintain external-facing security documentation that supports the sales process.

  • Close the loop: Track security-questionnaire outcomes, collect lessons learned from each RFP cycle, and feed recurring gaps back to Product, Sales, and the security team.

  • Support compliance reporting and external audits: Help prepare quarterly compliance status reporting for the Senior Management Team, keep procedures and policies documented, organize evidence for external audits, and help maintain our AI Management System.

  • Contribute to security improvements: Research, propose, and deliver improvements to security controls, and collaborate on security automation initiatives with our engineers.

What success looks like

  • In your first 3 months you'll: Get up to speed with our existing security answer library and compliance tooling, start helping with incoming security questionnaires and RFPs, and begin learning the vulnerability management cadences and recurring security activities.

  • By month 6 you'll: Smoothly support continuous compliance and evidence validation, actively partner with engineers to automate manual compliance tasks, confidently see RFPs through to submission with guidance from your team, and contribute to improvements in our security controls and knowledge base.

What makes you thrive here

You have:

  • A genuine desire to work in compliance and with customers. This role is customer-facing security work at its core and requires someone who truly wants to do this work.

  • Excellent written English with rigorous attention to detail to ensure every customer-facing answer is clear, accurate, professional, and error-free.

  • Organizational and project-management ability to coordinate RFP execution by identifying the right internal stakeholders, gathering their input, and keeping everyone on deadline.

  • An understanding of compliance frameworks (SOC 2, ISO 27001, ISO 42001, HIPAA, NIST) or a strong willingness to learn them quickly.

  • An understanding of security controls and best practices, or the drive to build it fast.

  • A self-motivated, continuous learning mindset where you actively teach yourself new frameworks, tools, and techniques.

  • Currently pursuing or completed a Bachelor's or Master's degree in Information Security, IT, Business, or a related field.

  • A mindset to use modern AI tools everywhere to expand and scale your reach, acting as a force multiplier.

You don't need to meet every qualification on day one. Three things are non-negotiable: you want to work in compliance and with customers, you use AI to accelerate everything you do, and you teach yourself what you don't know. If that's you, we'd like to hear from you even if the rest is still growing.

Bonus points if you also:

  • Bring experience with GRC or RFP automation tools like Vanta, Drata, Loopio, or Hyperproof.

  • Have previous experience in compliance, audit, security, or technical-writing roles.

  • Possess basic programming or scripting skills (Python, Shell) for automation tasks.

  • Have exposure to vulnerability management concepts like CVSS, triage, and remediation tracking.

  • Understand AI-native, cloud-native, and SaaS business models.

Who you'll work with

You will work daily with the Product Security team, whose shared job is to address any security concern a product team or customer raises. You will not start from scratch or work alone; the team behind you includes experienced colleagues who own the frameworks and engineers who build the automation you run. You will report to the Director of Product Security, collaborating closely with Sales, Product, and external partners in an environment where continuous learning and automation are the default.

What you can expect from us

  • Compensation: Monthly salary of €3,000 - €4,000 depending on your experience. You may notice varying salary ranges for roles with similar titles across Hoxhunt; this is because each range is grounded in our role leveling and reflects the seniority, scope, and impact expectations required for that specific role and team, and we operate with a low hierarchy.

  • Working ways: We work in a flexible, but hybrid work setting. You are expected to visit the Helsinki office 2-3 days a week.

  • High performance meets high humanity: We bring an incredibly driven, high-impact energy to our work, but we leave our egos at the door. You will be surrounded by wildly talented, dedicated colleagues in an environment built on extreme kindness, support, and psychological safety.

  • Authentic trust & autonomy: We hire great people and trust them to do great work. You will find a culture free of micromanagement, giving you the autonomy to take real ownership, drive impact, and shape things early on.

  • A product you can be proud of: It is incredibly rare in cybersecurity to build a product that end-users genuinely love. You will join a fast-paced, technically sophisticated team making a real, measurable impact against cybercrime.

  • The perks that matter: Alongside this amazing community, you will enjoy extensive healthcare with other benefits and our beautiful office in Helsinki (complete with a gym and swimming pool!).

Recruitment Process

We want to get to know you and how you think! Our process includes:

  • Screening call with Talent Acquisition (30 min, remote)

  • Interview with the Director of Product Security (45-60 min, remote)

  • Practical exercise and panel interview (60 min)

  • Meeting with the VP of Engineering (30 min)

  • Reference checks and final offer

About Hoxhunt

Hoxhunt was founded in 2016 by four visionaries. Today we are a global team of +270 amazing Hoxhunters advancing a truly AI-native category leader in human risk management, with key hubs in the United States, the United Kingdom, Singapore, and Finland. We are proud to be an award-winning, fast-growing software company, recognized by G2 and Gartner, named to TIME Magazine's list of the World's Top EdTech Companies, and featured for our innovation in major publications like Fast Company, TechCrunch, Forbes, and Inc.

As a multi-product company, Hoxhunt goes beyond traditional security awareness. We don't just educate employees through frequent, personalized, and behavior-changing cybersecurity training - we also actively build real threat intelligence and response tools that protect organizations against malicious cyberattacks every single day.

Be among the first to know about our open positions. Drop your details in our Talent Community, and we will reach out when there is a match!

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
660,302 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Helsinki
$100k – $150k per year • Remote • 6+ years exp • PhD
Python
Databases
Oracle
DevOps
Terraform
IAM
Cybersecurity
ISO 27001
CIS Benchmarks
PCI DSS
SOC 2
HIPAA
FedRAMP
Zero Trust
Threat Modeling
Apply
$135k – $155k per year • Remote • 6+ years exp • PhD
Python
Go
Bash
DevOps
Terraform
Ansible
GCP
Red Hat
OpenShift
Helm
Istio
Linkerd
Azure
CI/CD
GitOps
ArgoCD
Jenkins
AWS
Kubernetes
Service Mesh
Tekton
Cybersecurity
PCI DSS
SOC 2
HIPAA
Apply
$100k – $150k per year • Remote • 6+ years exp • Bachelor's Degree
Python
PowerShell
Databases
Azure Cosmos DB
Azure SQL Database
DevOps
Terraform
Azure DevOps
GitHub Actions
Istio
Linkerd
Azure
CI/CD
Kubernetes
Service Mesh
Bicep
Azure AKS
FinOps
SLI/SLO/SLA
Cybersecurity
Microsoft Defender
PCI DSS
SOC 2
HIPAA
FedRAMP
Least Privilege
Microsoft Defender for Cloud
Analytics
Azure Data Factory
Apply
$100k – $120k per year • Remote • 6+ years exp • Bachelor's Degree
Python
PowerShell
DevOps
Terraform
Azure DevOps
GitHub Actions
Istio
Linkerd
Azure
CI/CD
Kubernetes
Service Mesh
Bicep
Azure AKS
FinOps
Cybersecurity
PCI DSS
SOC 2
HIPAA
FedRAMP
Apply
$100k – $150k per year • Remote • 6+ years exp • Bachelor's Degree
Python
PowerShell
Databases
DynamoDB
Amazon Redshift
Amazon Aurora
AI/ML
Ray
DevOps
Terraform
GitHub Actions
OpenTelemetry
AWS CDK
CloudFormation
Prometheus
GitLab CI
CI/CD
Jenkins
AWS
Kubernetes
Grafana
Amazon EKS
AWS Fargate
AWS Lambda
Amazon EC2
eBPF
FinOps
Amazon S3
IAM
Amazon ECS
Amazon CloudWatch
Amazon Kinesis
Cybersecurity
PCI DSS
SOC 2
HIPAA
FedRAMP
Zero Trust
Least Privilege
Apply
$83k – $104k per year • Remote/Hybrid • Full-Time • 10+ years exp • Helsinki
JavaScript
TypeScript
Node JS
AI/ML
Agentic Workflows
Frontend
GraphQL
React.js
Apply
$53k – $62k per year • Remote/Hybrid • Full-Time • 3+ years exp • Helsinki
Apply
$83k – $104k per year • Remote/Hybrid • Full-Time • 5+ years exp • Helsinki
JavaScript
TypeScript
Node JS
Frontend
React.js
Management
Agile
Apply
$83k – $104k per year • Remote/Hybrid • Full-Time • 5+ years exp • Helsinki
JavaScript
TypeScript
Node JS
Frontend
React.js
Apply
$62k – $83k per year • Remote/Hybrid • Full-Time • Helsinki
Python
JavaScript
TypeScript
AI/ML
AI Agents
Frontend
npm
DevOps
GCP
CI/CD
Kubernetes
GitHub
IAM
Cybersecurity
Least Privilege
Apply
$80k – $90k per year • Equity • Remote/Hybrid • Helsinki
SQL
Databases
Google BigQuery
BigQuery
AI/ML
AI Agents
Analytics
Looker
Management
Google Sheets
Apply
$48k – $107k per year (Estimated) • Remote/Hybrid • Helsinki
Marketing
LinkedIn
Apply
$47k – $111k per year (Estimated) • Remote • Contractor • 5+ years exp • Paris • Madrid • Warsaw • Lviv • Tallinn
Game Dev
Unity
Apply
$36k – $101k per year (Estimated) • In office • Full-Time • Helsinki
Apply
$36k – $101k per year (Estimated) • In office • Full-Time • Helsinki
Apply
See all jobs
This is one of many
660,302 more open roles from verified company boards, updated every day.