Security Engineer (Fractional)
Arcanys Melbourne, Victoria, Australia
Outsourcing and Offshoring Consulting · 201-500 employees
About the role
The Security Engineer will design a 12-month security roadmap, establish risk registers, and mentor the IT team on security controls and secure coding practices. They will also ensure cross-border data compliance and provide security advisory services for the company's venture portfolio.
What they look for
Requirements
Candidates must have proven hands-on experience in security engineering, cloud platforms, and DevSecOps within software or technology environments. A strong technical foundation in SDLC, compliance frameworks, and relevant security certifications like CISSP or CISM is preferred.
Full description
Arcanys is a high-growth Swiss software development partner with a 300+ person operation in the Philippines. We are looking for a Security Engineer (Fractional) to transition our security posture to "enterprise-grade".
Who you are (Requirements):
1. Proven hands-on experience in security engineering, cloud security, application security, or DevSecOps, ideally in software, technology, or outsourcing environments.
2. Strong technical foundation across SDLC, CI/CD security, cloud platforms (AWS/GCP), identity and access management, vulnerability management, and endpoint security.
3. Able to independently assess and verify security controls, including reviewing AWS/GCP configurations, GitHub repositories, CI/CD pipelines, and security tools, and provide practical recommendations.
4. Experience with client security assessments, security questionnaires, audits, or vendor assessments. Governance, risk management, SOC 2, ISO 27001, GDPR, and other compliance experience is a plus.
5. Relevant security certifications such as AWS/GCP, CISSP, CISM, CISA, or equivalent are preferred.
6. Experience working with distributed teams (Europe/Asia/Australia) and with early-stage startups is a plus.
Key Responsibilities:
1. Security Strategy
- Design a 12-month security roadmap that balances "Swiss Quality" expectations with the agility of a software outsourcing firm.
- Establish a Risk Register and prioritize remediation based on business impact.
2. Mentorship & Team Elevation
- Act as the direct mentor to our IT Manager, transforming technical tasks into security controls.
- Establish "Security Office Hours" to train our lead developers on secure coding (OWASP) and DevSecOps.
3. Cross-Border Compliance
- Ensure all data handling meets the European GDPR, the Philippines Data Privacy Act and the Australian Privacy Act standards, among other regulations.
- Standardize our response to client security questionnaires to accelerate the sales cycle.
4. Incident & Policy Management
- Draft and implement core policies (Incident Response, Access Control, BCP/DR) that are practical, not just theoretical.
- Oversee the selection and implementation of essential security tools (EDR, SIEM, Vulnerability Scanners) without over-complicating the stack.
5. Venture Portfolio Security & Advisory
- Define a "Right-Sized" security framework for Arcanys Ventures’ portfolio companies, ensuring they have essential protections without stifling their growth or speed.
- Assist the leadership team during the investment process by evaluating the technical security and data privacy risks of potential new ventures.
- Act as a fractional advisor for our startups, helping their founders establish basic security policies, data privacy compliance (GDPR/DPA), and a "Security by Design" culture from day one.
Similar roles
-
Lead Cybersecurity & Application Security Engineer
Weekday AI Hyderabad, Telangana, India
-
Cyber Security Engineer
Zensar Pune, Maharashtra, India
-
Italian Speaking Cybersecurity Customer Experts - Work In Athens, Greece
Mercier Consultancy Group Belgium
-
Cybersecurity Incident Commander - CIRT
Thrive Mabalacat, Pampanga, Philippines
-
Cybersecurity Expert
Consort Group Porto, Porto, Portugal · €43K–€52K/yr
-
Senior Consultant - Cybersecurity
UL Solutions Bangalore, Karnataka, India