LogoKode$word
Hoxhunt logo
Verified Tech Organization

Careers at Hoxhunt

Browse and filter through all verified positions currently open at Hoxhunt.

Total Company Roles6
Matching Filter6
hoxhunt.comHQ: Helsinki, Southern Finland, Finland
Sector:computercomputer and network securityinformation technologynetwork securitysecurity awareness training software

All Openings (6)

Ordered by most recently published

Our mission and why it matters We are on a mission to make humans the strongest security layer. Human risk remains one of the biggest vulnerabilities and traditional awareness training is not enough. We take a different approach by combining AI-driven personalization, real threat detection, and behavioral science to actively protect people and organizations. We don't just simulate risks. We build the tools that detect and stop them. Why this role matters We are growing by over 50% yearly, which means our tech is scaling rapidly, we are expanding into new regions, and we are seeing a massive increase in our global user base. As a Senior Software Engineer, you will be at the absolute heart of our multi-award-winning gamified cybersecurity awareness product. Your mission is to build the customized learning paths, smart automations, and mini-games that make our platform so engaging and effective, shaping the way we build and grow our product for our ~4 million users. What you’ll own and drive Build and deliver scalable, highly reliable features across the entire stack (front-end and back-end) for our learning platform. Bring our product vision to life by developing diverse content formats (quizzes, mini games, interactive layouts) and custom themes. Drive the next stage of our roadmap by taking active ownership of courses, user learning paths, and agentic workflows from concept to a finalized state. Drive performance improvements and make critical architectural decisions to ensure system reliability for our high-volume user base. Provide essential technical leadership and mentorship, uplifting the entire team. You will continuously develop our team practices and actively help upskill your peers. What success looks like In your first three months, you will become highly productive in our tech stack, shipping new features and actively contributing to the planning and execution of our core product roadmap. By month six, you will be confidently leading significant, end-to-end technical projects on your own, making a visible impact on the quality and scalability of our output. What makes you thrive here You probably have at least a decade of experience in software engineering and are already clearly established as a senior. But more than the years on your resume, we’d love to hear about what you’ve worked on, how it was built, and why it was a success. You have: Deep expertise in full-stack development using Node.js, React, and TypeScript. Bonus points if you also have hands-on experience with GraphQL and NoSQL databases like MongoDB. A strong product mindset with a passion for creating high-quality products that drive real value for users. Proven experience acting as an end-to-end project lead, breaking down execution plans, and effectively mentoring other developers (no lone wolves!). The ability to navigate a broad area of accountability, switch contexts easily, and solve complex scalability challenges for a massive global user base. AI-Native Mindset (Critical Requirement): You’re likely already using AI tools professionally in your current role, or have incorporated them in your hobby projects when your current organization has not been able keep up with your desire to learn. Who you’ll work with You will be joining our dedicated gamified learning product team where creativity, user-centered development and a strong product focus are part of our daily work. We care deeply about the user experience, positively surprising our users with small but important wow moments while building something that supports their personalized learning journey. In this team, we are dedicated to building world-class products by actively listening to our users and focusing on their needs. What you can expect from us Compensation: Monthly salary of €6000-€7500 depending on your experience. We work in a hybrid work setting (please note this is not a fully remote position). You are expected to visit the Helsinki office a minimum of 1-2 days per week. High performance meets high humanity: We bring an incredibly driven, high-impact energy to our work, but we leave our egos at the door. You will be surrounded by wildly talented, dedicated colleagues in an environment built on extreme kindness, support, and psychological safety. Authentic trust & autonomy: We hire great people and trust them to do great work. You will find a culture free of micromanagement, giving you the autonomy to take real ownership, drive impact, and shape things early on. A product you can be proud of: It is incredibly rare in cybersecurity to build a multi-award-winning product that end-users genuinely love. You will join a fast-paced, technically sophisticated team making a real, measurable impact against cybercrime, backed by strong financial stability and growth. The perks that matter: Alongside this amazing community, you will enjoy extensive healthcare and our beautiful office in Helsinki (complete with a gym and swimming pool!). Recruitment Process We want to get to know you and how you think! Our process includes: Interview with Talent Acquisition (30 min, remote). Hiring Manager Interview (60 min, remote). Take-home assignment Panel Interview (90 min, on-site). Meeting with VP of Engineering (60 min, remote). Reference checks and final offer. About Hoxhunt Hoxhunt was founded in 2016 by four visionaries. Today we are a global team of +270 amazing Hoxhunters advancing a truly AI-native category leader in human risk management, with key hubs in the United States, the United Kingdom, Singapore, and Finland. We are proud to be an award-winning, fast-growing software company, recognized by G2 and Gartner, named to TIME Magazine's list of the World's Top EdTech Companies, and featured for our innovation in major publications like Fast Company, TechCrunch, Forbes, and Inc. As a multi-product company, Hoxhunt goes beyond traditional security awareness. We don't just educate employees through frequent, personalized, and behavior-changing cybersecurity training - we also actively build real threat intelligence and response tools that protect organizations against malicious cyberattacks every single day. Be among the first to know about our open positions. Drop your details in our Talent Community, and we will reach out when there is a match!

View more...
Software EngineeringVia Ashby
Verified21 days ago

Our mission and why it matters We are on a mission to make humans the strongest security layer. Human risk remains one of the biggest vulnerabilities and traditional awareness training is not enough. We take a different approach by combining AI-driven personalization, real threat detection, and behavioral science to actively protect people and organizations. We don't just simulate risks. We build the tools that detect and stop them. Why this role matters We’re growing fast, over 50% year-over-year, and expanding our product offerings. Join us in building a new product that protects enterprise users from cyber attacks through real-time threat detection, while giving organizations continuous visibility into their risk surface and attack vectors. The product is already seeing strong market demand, and we're looking for you to help shape it and define how it scales as we grow. What you’ll own and drive Own delivery of key features end-to-end across the technology stack from building detection for emerging cyber attack patterns and large scale data processing to building intuitive, high quality user experiences. Contributing to team processes and practices to help us scale the team and product Improve our system reliability and overall architecture by coordinating execution plans and making key technical decisions. Drive and mentor the team through technical leadership, acting as a multiplier who unblocks peers and leads insightful code reviews to solve complex challenges. What makes you thrive here You’ll probably have at least five years’ experience working in the industry, but we care less about how long you’ve been active and more about what you’ve been doing. We’d love to hear about what you’ve worked on, how it was built, and why it was a success. You have a proven track record of leading complex technical projects from end to finish a strong product mindset, with the ability to turn ambiguous problems into user-focused requirements and value generation deep, hands-on experience with TypeScript and React, along with experience building backend services and APIs. We use Node.js and MongoDB. a solid understanding of the web platform Who you’ll work with You’ll be joining a team of ambitious product engineers who value high autonomy, low hierarchy and user-centered solutions. We are product-minded and work in agile, AI-native ways without compromising quality. Our goal is to build the best product in the market and win while enjoying the journey and creating the best working environment for each other. Join us in building a great product and having fun along the way! What you can expect from us Compensation: Monthly salary of €6000-€7500 depending on your experience. You may notice varying salary ranges for roles with similar titles across Hoxhunt; this is because each range is grounded in our role leveling and reflects the seniority, scope, and impact expectations required for that specific role and team, and we operate with a low hierarchy. Working ways: We work in a flexible, but hybrid work setting. You are expected to visit the Helsinki office weekly. High performance meets high humanity: We bring an incredibly driven, high-impact energy to our work, but we leave our egos at the door. You will be surrounded by wildly talented, dedicated colleagues in an environment built on extreme kindness, support, and psychological safety. Authentic trust & autonomy: We hire great people and trust them to do great work. You will find a culture free of micromanagement, giving you the autonomy to take real ownership, drive impact, and shape things early on. A product you can be proud of: It is incredibly rare in cybersecurity to build a multi-award-winning product that end-users genuinely love. You will join a fast-paced, technically sophisticated team making a real, measurable impact against cybercrime, backed by strong financial stability and growth. The perks that matter: Alongside this amazing community, you will enjoy extensive healthcare and our fresh new office in Helsinki (complete with a gym and swimming pool!). Recruitment Process We want to get to know you and how you think! Our process includes: Interview with Talent Acquisition (30 min, onsite). Hiring Manager Interview with Team Lead (45 min, remote). Technical Assignment (take-home task, max 6 hours) Panel Interview (60-90 min, onsite) Meeting with VP of Engineering (30 min, remote) Reference checks and final offer presentation. About Hoxhunt Hoxhunt was founded in 2016 by four visionaries. Today we are a global team of +270 amazing Hoxhunters advancing a truly AI-native category leader in human risk management, with key hubs in the United States, the United Kingdom, Singapore, and Finland. We are proud to be an award-winning, fast-growing software company, recognized by G2 and Gartner, named to TIME Magazine's list of the World's Top EdTech Companies, and featured for our innovation in major publications like Fast Company, TechCrunch, Forbes, and Inc. As a multi-product company, Hoxhunt goes beyond traditional security awareness. We don't just educate employees through frequent, personalized, and behavior-changing cybersecurity training - we also actively build real threat intelligence and response tools that protect organizations against malicious cyberattacks every single day. Be among the first to know about our open positions. Drop your details in our Talent Community, and we will reach out when there is a match!

View more...
Software EngineeringVia Ashby
Verified25 days ago

Our mission and why it matters We are on a mission to make humans the strongest security layer. Human risk remains one of the biggest vulnerabilities and traditional awareness training is not enough. We take a different approach by combining AI-driven personalization, real threat detection, and behavioral science to actively protect people and organizations. We don't just simulate risks. We build the tools that detect and stop them. Why this role matters We are growing by over 50% yearly, which means our tech is scaling rapidly, we are expanding into new regions, and our global user base continues to grow at pace. As a Senior Software Engineer, you will play a key role in shaping the future of our gamified phishing platform, our oldest and most well-known flagship product that helps 5+ million people build safer online behavior daily. It is incredibly rare in cybersecurity to build a product that end-users genuinely want to use, but our gamification is so engaging that users actively reach out to ask for more simulations when they finish their training paths! You’ll join the team responsible for this core product at a pivotal stage of growth, where scalability, product quality, and speed of execution matter more than ever. What you’ll own and drive Build and deliver scalable, highly reliable full-stack features for our gamification platform. Develop innovative new ways to train users on evolving cybersecurity threats. Contribute to the long-term evolution of our architecture by successfully scaling systems that were not originally designed for our current, massive scale. Collaborate closely with Product Management and your engineering peers to plan, scope, and execute projects together in a highly collaborative environment with strong ownership and accountability. These are some example projects that you may work on: Simulations that train against modern AI attacks; this year we have released deepfake simulations and simulations where the agent calls the user pretending to be their coworker Extend our simulation engine to recreate modern multi-channel attacks that target users across email, chat, and phone over weeks Design and ship gamification features (leaderboards, achievements, learning paths) that keep users engaged What success looks like In your first 90 days, you’ll become productive in our tech stack, start shipping new features and actively contributing to the planning and execution of our core product roadmap. By month six, you’ll be confidently driving significant end-to-end projects, contributing to architectural decisions, and operating as a trusted technical owner within the team. What makes you thrive here You’ll probably have at least five years’ experience working in the industry, but we care far more about your impact, ownership, and product thinking than the number of years on your CV. We’d especially love to hear about products you’ve helped build, how you approached technical and product decisions, and the role you played in making them successful. You have: Hands-on experience with TypeScript and React, along with experience building backend services and APIs. We use Node.js and MongoDB. Experience building and maintaining large-scale systems utilized by real end-users. A track record of reliably and consistently delivering results. We prioritize high-capacity execution and a strong builder mindset over hyper-specific niche skill gaps. A strong product mindset and the ability to balance technical quality with user value and business impact. An AI-native mindset, including curiosity and excitement around building software with AI-assisted workflows and teams of agents working in parallel. Bonus points if you also: Have a deep focus on system logic and architecture (deep UX expertise is completely not necessary for this specific role). Who you’ll work with You’ll join our dedicated attack capabilities product team in an actively growing, highly capable group focused on building engaging experiences that genuinely help users change their security behavior. The team combines strong product thinking, technical ownership, and a high-performance mindset with a supportive, low-ego culture. We care deeply about the user experience, positively surprising our users with small but important wow moments while building something that supports their personalized training journey. Our day-to-day work is highly collaborative: planning projects together, refining ideas as a team, and shipping impactful features quickly. While everyone has strong ownership over their own domain, success comes from working closely together and continuously improving how we build. What you can expect from us Compensation : Monthly salary of €6000–€7500 depending on your experience. Your placement within this band is grounded in our internal role leveling and depends on a combination of your technical expertise, scope of ownership, and overall capacity to deliver results. Working ways : We work in a hybrid work setting (please note this is not a fully remote position). You are expected to visit the Helsinki office a minimum of 1-2 days per week. High performance meets high humanity : We bring an incredibly driven, high-impact energy to our work, but we leave our egos at the door. You will be surrounded by wildly talented, dedicated colleagues in an environment built on extreme kindness, support, and psychological safety. Authentic trust & autonomy : We hire great people and trust them to do great work. You will find a culture free of micromanagement, giving you the autonomy to take real ownership, drive impact, and shape things early on. A product you can be proud of : It is incredibly rare in cybersecurity to build a multi-award-winning product that end-users genuinely love. You will join a fast-paced, technically sophisticated team making a real, measurable impact against cybercrime. The perks that matter : Alongside this amazing community, you will enjoy extensive healthcare with other benefits and our beautiful office in Helsinki (complete with a gym and swimming pool!). Recruitment Process We want to get to know you and how you think! Our process includes: Interview with Talent Acquisition (30 min, remote) Hiring Manager Interview with Team Lead (60 min, remote) Technical Assignment and Panel Interview (90 min, on-site) Meeting with VP of Engineering (60 min, remote). Reference checks and final offer. About Hoxhunt Hoxhunt was founded in 2016 by four visionaries. Today we are a global team of +270 amazing Hoxhunters advancing a truly AI-native category leader in human risk management, with key hubs in the United States, the United Kingdom, Singapore, and Finland. We are proud to be an award-winning, fast-growing software company, recognized by G2 and Gartner, named to TIME Magazine's list of the World's Top EdTech Companies, and featured for our innovation in major publications like Fast Company, TechCrunch, Forbes, and Inc. As a multi-product company, Hoxhunt goes beyond traditional security awareness. We don't just educate employees through frequent, personalized, and behavior-changing cybersecurity training - we also actively build real threat intelligence and response tools that protect organizations against malicious cyberattacks every single day. Be among the first to know about our open positions. Drop your details in our Talent Community, and we will reach out when there is a match!

View more...
Software EngineeringVia Ashby
Verified25 days ago

Software Engineer, Security

On-sitefull timeMid-LevelHelsinki, Finland
Apply Now

Our mission and why it matters We are on a mission to make humans the strongest security layer. Human risk remains one of the biggest vulnerabilities and traditional awareness training is not enough. We take a different approach by combining AI-driven personalization, real threat detection, and behavioral science to actively protect people and organizations. We don't just simulate risks. We build the tools that detect and stop them. Why this role matters We're growing fast, over 50% year over year, and our security has to scale with the product: through tooling and code, not headcount. There is no manned SOC here and no plans for one. You will build our security observability: the pipeline that collects, processes and routes security events and logs across our Google Cloud platform, and the detections, alerting and dashboards on top of it. You won't start from zero. Dashboards, audit logging, alerting and a SIEM build-out are underway, and you inherit working security automation: an automated vulnerability triager covering our npm, Maven, Go and Python ecosystems, remediation nudging with CI tests, and the scanning-stack integrations around them. Your job is to take all of it from working to excellent. What you'll own and drive Design and build our security event and log pipeline on GCP, and the detections, alerting and dashboards on top of it, engineered as code: reviewed, tested, deployed through CI/CD. Own and extend our security automation: the vulnerability triager, the remediation nudging automation, and our scanning-stack integrations (GitHub Advanced Security, dependency ownership, issue sync). Build and improve the tooling our GRC function relies on every day. Turn recurring manual security work into code, for example automating our churned-customer data-removal monitoring end to end. Harden our cloud security architecture together with SRE/Platform: trust boundaries, IAM and least privilege, network egress, secrets, infrastructure-as-code. Contribute to our agentic security tooling (AI-assisted PR review and security review) alongside the team. What makes you thrive here You'll probably have at least a few years of experience building production software, but we care less about how long you've been active and more about what you've built, how it was built, and why it worked. You have deep, hands-on experience with Google Cloud: IAM, networking, logging and eventing services, containers and Kubernetes. production experience in at least one of TypeScript, Python or Go, and no fear of the other two. We work in a large monorepo spanning all three. experience building data or event pipelines, observability systems, or detection tooling, and the instinct to treat all of it as software: version-controlled, reviewed, tested. a genuine pull toward security. A security title is not required; an engineer who wants their work to protect things is. AI agents in your daily workflow. We expect you to use modern AI tools everywhere to expand and scale your reach. Who you'll work with You'll join the Product Security team: a small, high-leverage group whose job is to address any security concern a product team or customer raises. You build the platforms; your teammates run the programs on top of them and cover application security and compliance. You'll work daily with SRE/Platform and the product engineering teams. What you can expect from us Compensation: monthly salary of €4,500–6,000 depending on your experience. You may notice varying salary ranges for roles with similar titles across Hoxhunt; this is because each range is grounded in our role leveling and reflects the seniority, scope, and impact expectations required for that specific role and team, and we operate with a low hierarchy. Working ways: flexible, hybrid. You are expected to visit the Helsinki office weekly. High performance meets high humanity: driven, high-impact work with egos left at the door, surrounded by wildly talented colleagues in an environment built on kindness, support, and psychological safety. Authentic trust and autonomy: we hire great people and trust them to do great work. Real ownership over how our security automation gets built, and the space to decide what's worth automating first. A product you can be proud of: Hoxhunt's own products are security products. Building security tooling at a company that ships security tooling means your internal work and the product sharpen each other. The perks that matter: extensive healthcare and our fresh office in Helsinki, complete with a gym and swimming pool. Recruitment process Interview with Talent Acquisition (30 min) Hiring Manager interview with the Director of Product Security (45–60 min) Technical assignment and panel interview (60–90 min) Meeting with the VP of Engineering (30 min) Reference checks and final offer About Hoxhunt Hoxhunt was founded in 2016 by four visionaries. Today we are a global team of +270 amazing Hoxhunters advancing a truly AI-native category leader in human risk management, with key hubs in the United States, the United Kingdom, Singapore, and Finland. We are proud to be an award-winning, fast-growing software company, recognized by G2 and Gartner, named to TIME Magazine's list of the World's Top EdTech Companies, and featured for our innovation in major publications like Fast Company, TechCrunch, Forbes, and Inc. As a multi-product company, Hoxhunt goes beyond traditional security awareness. We don't just educate employees through frequent, personalized, and behavior-changing cybersecurity training - we also actively build real threat intelligence and response tools that protect organizations against malicious cyberattacks every single day. Be among the first to know about our open positions. Drop your details in our Talent Community, and we will reach out when there is a match!

View more...
Software EngineeringVia Ashby
Verified27 days ago

Senior Software Engineer, Security

On-sitefull timeSeniorHelsinki, Finland
Apply Now

Our mission and why it matters We are on a mission to make humans the strongest security layer. Human risk remains one of the biggest vulnerabilities and traditional awareness training is not enough. We take a different approach by combining AI-driven personalization, real threat detection, and behavioral science to actively protect people and organizations. We don't just simulate risks. We build the tools that detect and stop them. Why this role matters We're growing fast, over 50% year over year, and our security has to scale with the product: through tooling and code, not headcount. There is no manned SOC here and no plans for one. You will build our security observability: the pipeline that collects, processes and routes security events and logs across our Google Cloud platform, and the detections, alerting and dashboards on top of it. You won't start from zero. Dashboards, audit logging, alerting and a SIEM build-out are underway, and you inherit working security automation: an automated vulnerability triager covering our npm, Maven, Go and Python ecosystems, remediation nudging with CI tests, and the scanning-stack integrations around them. Your job is to take all of it from working to excellent. What you'll own and drive Own the architecture and outcomes of our security event and log pipeline on GCP, and the detections, alerting and dashboards on top of it, engineered as code: reviewed, tested, deployed through CI/CD. Own and extend our security automation: the vulnerability triager, the remediation nudging automation, and our scanning-stack integrations (GitHub Advanced Security, dependency ownership, issue sync). Build and improve the tooling our GRC function relies on every day. Turn recurring manual security work into code, for example automating our churned-customer data-removal monitoring end to end. Harden our cloud security architecture together with SRE/Platform: trust boundaries, IAM and least privilege, network egress, secrets, infrastructure-as-code. Drive technical decisions and mentor through code review: act as a multiplier who raises the bar on how security software gets built here. Contribute to our agentic security tooling (AI-assisted PR review and security review) alongside the team. What makes you thrive here You'll probably have at least five years of experience building production software, but we care less about how long you've been active and more about what you've built, how it was built, and why it worked. You are comfortable owning outcomes at system scale, turning ambiguous problems into shipped systems, and influencing how adjacent teams build securely. You have deep, hands-on experience with Google Cloud: IAM, networking, logging and eventing services, containers and Kubernetes. production experience in at least one of TypeScript, Python or Go, and no fear of the other two. We work in a large monorepo spanning all three. experience building data or event pipelines, observability systems, or detection tooling, and the instinct to treat all of it as software: version-controlled, reviewed, tested. a genuine pull toward security. A security title is not required; an engineer who wants their work to protect things is. AI agents in your daily workflow. We expect you to use modern AI tools everywhere to expand and scale your reach. Who you'll work with You'll join the Product Security team: a small, high-leverage group whose job is to address any security concern a product team or customer raises. You build the platforms; your teammates run the programs on top of them and cover application security and compliance. You'll work daily with SRE/Platform and the product engineering teams. What you can expect from us Compensation: monthly salary of €6,000–7,500 depending on your experience. You may notice varying salary ranges for roles with similar titles across Hoxhunt; this is because each range is grounded in our role leveling and reflects the seniority, scope, and impact expectations required for that specific role and team, and we operate with a low hierarchy. Working ways: flexible, hybrid. You are expected to visit the Helsinki office weekly. High performance meets high humanity: driven, high-impact work with egos left at the door, surrounded by wildly talented colleagues in an environment built on kindness, support, and psychological safety. Authentic trust and autonomy: we hire great people and trust them to do great work. Real ownership over how our security automation gets built, and the space to decide what's worth automating first. A product you can be proud of: Hoxhunt's own products are security products. Building security tooling at a company that ships security tooling means your internal work and the product sharpen each other. The perks that matter: extensive healthcare and our fresh office in Helsinki, complete with a gym and swimming pool. Recruitment process Interview with Talent Acquisition (30 min) Hiring Manager interview with the Director of Product Security (45–60 min) Technical assignment and panel interview (60–90 min) Meeting with the VP of Engineering (30 min) Reference checks and final offer About Hoxhunt Hoxhunt was founded in 2016 by four visionaries. Today we are a global team of +270 amazing Hoxhunters advancing a truly AI-native category leader in human risk management, with key hubs in the United States, the United Kingdom, Singapore, and Finland. We are proud to be an award-winning, fast-growing software company, recognized by G2 and Gartner, named to TIME Magazine's list of the World's Top EdTech Companies, and featured for our innovation in major publications like Fast Company, TechCrunch, Forbes, and Inc. As a multi-product company, Hoxhunt goes beyond traditional security awareness. We don't just educate employees through frequent, personalized, and behavior-changing cybersecurity training - we also actively build real threat intelligence and response tools that protect organizations against malicious cyberattacks every single day. Be among the first to know about our open positions. Drop your details in our Talent Community, and we will reach out when there is a match!

View more...
Software EngineeringVia Ashby
Verified27 days ago

Junior Security Engineer, GRC

On-sitefull timeEntry / JuniorHelsinki, Finland
Apply Now

Our mission and why it matters We are on a mission to make humans the strongest security layer. Human risk remains one of the biggest vulnerabilities and traditional awareness training is not enough. We take a different approach by combining AI-driven personalization, real threat detection, and behavioral science to actively protect people and organizations. We don't just simulate risks. We build the tools that detect and stop them. Why this role matters We are looking for a Junior Security Engineer, GRC to join Hoxhunt's Product Security team. In this role, you will act as a quarterback to support customer trust by helping with the security questionnaires and RFPs that unblock sales deals, seeing each case through with guidance from senior teammates. You will also play a key role in our compliance footprint by helping collect and validate evidence across the frameworks we operate under (SOC 2 Type II, ISO 27001, ISO 42001, HIPAA), and you will learn to run the day-to-day coordination of our vulnerability management program and our recurring security activities. This is an excellent opportunity to build a career at the intersection of information security and business within a fast-growing SaaS company, with modern tooling and automation doing the heavy lifting. This is a growth role for someone with ambition. We hire juniors we expect to grow quickly, and we invest in making that happen by providing real ownership from week one and experienced mentors to support you. What you'll do Quarterback RFP and security questionnaire responses: See each case you take through, end-to-end, with guidance from senior teammates. Triage the request, draft high-quality responses using our answer library and tooling, coordinate input from technical experts when needed, and drive it through to submission. Support continuous compliance: Help manage the evidence flow across SOC 2 Type II, ISO 27001, ISO 42001 and HIPAA. Validate evidence collected continuously through Vanta, handle manual needs, and work with engineers to automate processes to stay continuously audit-ready. Learn to run the vulnerability management coordination cadence: Review dashboards and automated triage output weekly, route findings to the code owners, track remediation against our CVSS-based SLAs, escalate when needed, and report on status. Coordinate our recurring security activities: Help manage the regular calendar including coordinating penetration testing with external partners, access and policy review cycles, and subprocessor reviews. Maintain our security knowledge base and sales collateral: Keep the answer library comprehensive, accurate, and current, and maintain external-facing security documentation that supports the sales process. Close the loop: Track security-questionnaire outcomes, collect lessons learned from each RFP cycle, and feed recurring gaps back to Product, Sales, and the security team. Support compliance reporting and external audits: Help prepare quarterly compliance status reporting for the Senior Management Team, keep procedures and policies documented, organize evidence for external audits, and help maintain our AI Management System. Contribute to security improvements: Research, propose, and deliver improvements to security controls, and collaborate on security automation initiatives with our engineers. What success looks like In your first 3 months you'll: Get up to speed with our existing security answer library and compliance tooling, start helping with incoming security questionnaires and RFPs, and begin learning the vulnerability management cadences and recurring security activities. By month 6 you'll: Smoothly support continuous compliance and evidence validation, actively partner with engineers to automate manual compliance tasks, confidently see RFPs through to submission with guidance from your team, and contribute to improvements in our security controls and knowledge base. What makes you thrive here You have: A genuine desire to work in compliance and with customers. This role is customer-facing security work at its core and requires someone who truly wants to do this work. Excellent written English with rigorous attention to detail to ensure every customer-facing answer is clear, accurate, professional, and error-free. Organizational and project-management ability to coordinate RFP execution by identifying the right internal stakeholders, gathering their input, and keeping everyone on deadline. An understanding of compliance frameworks (SOC 2, ISO 27001, ISO 42001, HIPAA, NIST) or a strong willingness to learn them quickly. An understanding of security controls and best practices, or the drive to build it fast. A self-motivated, continuous learning mindset where you actively teach yourself new frameworks, tools, and techniques. Currently pursuing or completed a Bachelor's or Master's degree in Information Security, IT, Business, or a related field. A mindset to use modern AI tools everywhere to expand and scale your reach, acting as a force multiplier. You don't need to meet every qualification on day one. Three things are non-negotiable: you want to work in compliance and with customers, you use AI to accelerate everything you do, and you teach yourself what you don't know. If that's you, we'd like to hear from you even if the rest is still growing. Bonus points if you also: Bring experience with GRC or RFP automation tools like Vanta, Drata, Loopio, or Hyperproof. Have previous experience in compliance, audit, security, or technical-writing roles. Possess basic programming or scripting skills (Python, Shell) for automation tasks. Have exposure to vulnerability management concepts like CVSS, triage, and remediation tracking. Understand AI-native, cloud-native, and SaaS business models. Who you'll work with You will work daily with the Product Security team, whose shared job is to address any security concern a product team or customer raises. You will not start from scratch or work alone; the team behind you includes experienced colleagues who own the frameworks and engineers who build the automation you run. You will report to the Director of Product Security, collaborating closely with Sales, Product, and external partners in an environment where continuous learning and automation are the default. What you can expect from us Compensation: Monthly salary of €3,000 - €4,000 depending on your experience. You may notice varying salary ranges for roles with similar titles across Hoxhunt; this is because each range is grounded in our role leveling and reflects the seniority, scope, and impact expectations required for that specific role and team, and we operate with a low hierarchy. Working ways: We work in a flexible, but hybrid work setting. You are expected to visit the Helsinki office 2-3 days a week. High performance meets high humanity: We bring an incredibly driven, high-impact energy to our work, but we leave our egos at the door. You will be surrounded by wildly talented, dedicated colleagues in an environment built on extreme kindness, support, and psychological safety. Authentic trust & autonomy: We hire great people and trust them to do great work. You will find a culture free of micromanagement, giving you the autonomy to take real ownership, drive impact, and shape things early on. A product you can be proud of: It is incredibly rare in cybersecurity to build a product that end-users genuinely love. You will join a fast-paced, technically sophisticated team making a real, measurable impact against cybercrime. The perks that matter: Alongside this amazing community, you will enjoy extensive healthcare with other benefits and our beautiful office in Helsinki (complete with a gym and swimming pool!). Recruitment Process We want to get to know you and how you think! Our process includes: Screening call with Talent Acquisition (30 min, remote) Interview with the Director of Product Security (45–60 min, remote) Practical exercise and panel interview (60 min) Meeting with the VP of Engineering (30 min) Reference checks and final offer About Hoxhunt Hoxhunt was founded in 2016 by four visionaries. Today we are a global team of +270 amazing Hoxhunters advancing a truly AI-native category leader in human risk management, with key hubs in the United States, the United Kingdom, Singapore, and Finland. We are proud to be an award-winning, fast-growing software company, recognized by G2 and Gartner, named to TIME Magazine's list of the World's Top EdTech Companies, and featured for our innovation in major publications like Fast Company, TechCrunch, Forbes, and Inc. As a multi-product company, Hoxhunt goes beyond traditional security awareness. We don't just educate employees through frequent, personalized, and behavior-changing cybersecurity training - we also actively build real threat intelligence and response tools that protect organizations against malicious cyberattacks every single day. Be among the first to know about our open positions. Drop your details in our Talent Community, and we will reach out when there is a match!

View more...
CybersecurityVia Ashby
Verified27 days ago