yandex
H
hoxhunt
+500% приглашений

Откликайтесь
на вакансии с ИИ

Ускорим процесс поиска работы
JuniorУдалённоПолная занятость

Junior Security Engineer, GRC

ИИОценка ИИ

Отличная позиция для старта карьеры в GRC с четким планом развития на первые 6 месяцев. Компания использует современные инструменты (Vanta) и работает с передовыми стандартами (ISO 42001), что дает ценный опыт.


Вакансия из Quick Offer Global, списка международных компаний
Пожаловаться

Сложность вакансии

ЛегкоСложно
ИИОценка ИИ

Роль начального уровня (Junior), но требует высокой ответственности и организованности. Основная сложность заключается в необходимости быстро освоить специфические стандарты (SOC 2, ISO) и работать на стыке техники и продаж.

Анализ зарплаты

Медиана3 500 €
Рынок2 800 € – 4 500 €
ИИОценка ИИ

Для позиции Junior GRC Engineer в европейском SaaS-секторе предлагаемые условия (исходя из рыночных данных) являются конкурентными. Зарплата соответствует начальному уровню специалиста по кибербезопасности в Финляндии или удаленно на европейский рынок.

Сопроводительное письмо

I am writing to express my strong interest in the Junior Security Engineer, GRC position at Hoxhunt. With a solid foundation in cybersecurity principles and a keen interest in the intersection of information security and business operations, I am eager to contribute to your Product Security team. I am particularly drawn to Hoxhunt’s innovative approach of using AI-driven personalization and behavioral science to mitigate human risk, and I am excited by the prospect of managing critical compliance frameworks like SOC 2 and ISO 27001.

In my previous experience and academic background, I have developed a meticulous approach to documentation and a proactive mindset toward vulnerability management. I am proficient in navigating complex technical requirements and translating them into clear, professional responses for RFPs and security questionnaires. I am eager to leverage tools like Vanta to automate compliance workflows and ensure that Hoxhunt remains audit-ready while supporting the sales team in closing high-value deals.

I am a fast learner with the ambition to grow within a high-performance environment. I look forward to the possibility of bringing my dedication to security excellence to your team and helping Hoxhunt scale its security operations. Thank you for your time and consideration.

+250% к просмотрам

Составьте идеальное письмо к вакансии с ИИ-агентом

Составьте идеальное письмо к вакансии с ИИ-агентом

Откликнитесь в hoxhunt уже сейчас

Присоединяйтесь к Hoxhunt и станьте ключевым звеном в обеспечении безопасности и доверия клиентов в быстрорастущем SaaS-стартапе!

Описание вакансии

OUR MISSION AND WHY IT MATTERS

We are on a mission to make humans the strongest security layer.

Human risk remains one of the biggest vulnerabilities and traditional awareness training is not enough. We take a different approach by combining AI-driven personalization, real threat detection, and behavioral science to actively protect people and organizations.

We don't just simulate risks. We build the tools that detect and stop them.

WHY THIS ROLE MATTERS

We are looking for a Junior Security Engineer, GRC to join Hoxhunt's Product Security team. In this role, you will act as a quarterback for customer trust by taking the lead on the security questionnaires and RFPs that unblock sales deals, owning each case end-to-end. You will play a key role in our compliance footprint by collecting and validating evidence across the frameworks we operate under (SOC 2 Type II, ISO 27001, ISO 42001, HIPAA). You will also run the day-to-day coordination of our vulnerability management program and our recurring security activities. This is an excellent opportunity to build a career at the intersection of information security and business within a fast-growing SaaS company, with modern tooling and automation doing the heavy lifting. This is a growth role for someone with ambition. We hire juniors we expect to grow quickly, providing real ownership from week one and experienced mentors to support you.

WHAT YOU'LL OWN AND DRIVE

\* Quarterback RFP and security questionnaire responses:

Triage requests, draft high-quality responses using our answer library and tooling (Vanta), coordinate input from technical experts, and drive it through to submission.

\* Drive continuous compliance:

Own the evidence flow across SOC 2 Type II, ISO 27001, ISO 42001 and HIPAA. Validate evidence collected through Vanta, handle manual needs, and work with engineers to automate processes to stay continuously audit-ready.

\* Run the vulnerability management coordination cadence:

Review dashboards and automated triage output weekly, route findings to the code owners, track remediation against CVSS-based SLAs, escalate when needed, and report on status.

\* Run our recurring security activities:

Own the regular calendar including coordinating penetration testing with external partners, quarterly access reviews, annual policy reviews and approvals, and annual subprocessor reviews.

\* Maintain our security knowledge base and sales collateral:

Keep the answer library comprehensive, accurate, and current, and maintain external-facing security documentation that supports the sales process.

\* Close the loop:

Track security-questionnaire outcomes, collect lessons learned from each RFP cycle, and feed recurring gaps back to Product, Sales, and the security team.

\* Support compliance reporting:

Help prepare quarterly compliance status reporting for the Senior Management Team and keep procedures and policies documented.

\* Assist in preparing for external audits, maintaining our AI Management System (AIMS, ISO 42001), and acting as a point of contact for external vulnerability reports. • Research, propose, and deliver improvements to security controls and contribute to security automation initiatives.

WHAT SUCCESS LOOKS LIKE

\* In your first 3 months you'll: Master our existing security answer library and compliance tooling, take ownership of incoming security questionnaires and RFPs, and begin coordinating vulnerability management cadences and recurring security activities.

\* By month 6 you'll: Smoothly drive continuous compliance and evidence validation, actively partner with engineers to automate manual compliance tasks, independently quarterback complex RFPs from triage to submission, and contribute to improvements in our security controls and knowledge base.

WHAT MAKES YOU THRIVE HERE

You have:

+400% к собеседованиям

Создайте идеальное резюме с помощью ИИ-агента

Создайте идеальное резюме с помощью ИИ-агента

Навыки

  • SOC 2
  • ISO 27001
  • HIPAA
  • Compliance
  • Vulnerability Management
  • RFP
  • GRC
  • SaaS Security
  • ISO 42001
  • Vanta

Возможные вопросы на собеседовании

Проверка понимания ключевых стандартов, упомянутых в вакансии.

Можете ли вы объяснить основные различия между SOC 2 Type II и ISO 27001?

Оценка навыков приоритизации и работы с уязвимостями.

Как бы вы приоритизировали исправление уязвимостей, если у вас есть несколько находок с разным уровнем CVSS?

Проверка способности работать с клиентами и отделом продаж.

Как вы будете действовать, если в опроснике безопасности от клиента встретится вопрос, на который у нас пока нет утвержденного ответа в базе?

Оценка потенциала к автоматизации процессов.

Какие рутинные задачи в области комплаенса, по вашему мнению, стоит автоматизировать в первую очередь и почему?

Проверка внимательности к деталям и процессам аудита.

Опишите ваш подход к сбору и проверке доказательств (evidence) для прохождения внешнего аудита.

Похожие вакансии

H
hoxhunt
более 1000 офферов получено
4.9

1000+ офферов получено

Устали искать работу? Мы найдём её за вас

Quick Offer улучшит ваше резюме, подберёт лучшие вакансии и откликнется за вас. Результат — в 3 раза больше приглашений на собеседования и никакой рутины!