ZeroNorth

Senior Security Engineer

ZeroNorth Copenhagen, Capital Region of Denmark, Denmark

Software Development · 501-1,000 employees

6 h ago
security Senior (5-10 yrs) Full-time Denmark
Log in to apply, save this posting, or score it against your profile with AI.

About the role

You will design and manage technical security controls across AWS, EKS, and IoT infrastructure while integrating automated security scanning into CI/CD pipelines. Additionally, you will lead GRC efforts, including audit preparation and policy maintenance, while securing the company's maritime AI platform.

What they look for

AWS Kubernetes EKS Terraform IaC CI/CD GitHub Actions IoT Security GRC SOC 2 ISO 27001 GDPR NIS2 AI Security Vulnerability Management Incident Response

Requirements

The role requires broad hands-on experience with cloud infrastructure, Kubernetes, and IaC, alongside a solid understanding of security frameworks like SOC 2 and ISO 27001. Candidates should possess strong communication skills and relevant certifications such as CISSP, CISM, or AWS Security Specialty.

Full description

At ZeroNorth, we are at the forefront of transforming the shipping industry through digital innovation. Our solutions go beyond optimising business operations, they are designed to lead the industry in sustainability by significantly reducing CO2 emissions.

Our core mission of making global trade greener drives everything we do. Your contributions will play a crucial role in reducing emissions, aligning commercial success with sustainability, and delivering benefits for both profitability and the environment.

ZeroNorth is powered by a diverse team of 550+ professionals with more than 38 nationalities, operating out of global hubs including Copenhagen (our headquarters), Athens, Chennai, Mumbai, Singapore, Sofia, and Tokyo.

We are leading the industry's green transition, enabling our partners to leverage data for actionable decarbonisation efforts.

Senior Security Engineer at ZeroNorth

This is a hands-on role where you get to touch every aspect of security and compliance in a modern SaaS company. You will build security controls directly in our AWS and IoT-based platforms (basically a distributed, ship-based, 1k+ machine datacenter) and use that same technical depth to strengthen our GRC work. We are looking for someone who is comfortable moving between a policy document, security controls and doing a technical deep dive in the same day. Expect the balance to lean hands-on technical work, with GRC concentrated around audit cycles.

As a software company operating in the maritime industry, our customers and legislation put strict requirements on us to operate in a secure environment. You will take a central role in ensuring our processes, operations and software development practices are up to par with the latest standards and pressures of the industry. You will work closely with engineering teams, Internal IT, Legal, external auditors, and leadership.

Additionally, AI is central to how we work: we build with it, we defend with it, and we are now building a maritime AI platform of our own that needs securing. This role sits at the front of all three and should be a comfortable user of AI.

Key responsibilities:

Secure the platform, hands-on: Design, implement, and manage technical security controls on our AWS, EKS, and IoT infrastructure. Integrate automated security scanning into our GitHub Actions CI/CD pipelines and interface with development teams to ensure findings are addressed. Monitor and remediate vulnerabilities across the platform, and act as the technical security expert for the team. When incidents happen, you help drive the response — from triage through remediation to post-incident review. We are using AI to facilitate this work and we want to build this out even more.

Secure our AI platform: We are building an AI platform, and protecting it is a core part of this role. You will help create the framework for ensuring the AI platform we ship to production is trustworthy and compliant by design.

Support security strategy and policy: Help maintain security policies and standards, and interpret relevant regulations (GDPR, NIS2, and others) to inform how we apply controls.

Treat compliance as an engineering problem: Help drive adherence to our compliance frameworks (SOC 2, NIS2, GDPR) by automating evidence collection through our GRC platform (Vanta), keeping controls mapped to how the platform actually works, and making external audits uneventful. You will be a key point of contact when auditors come knocking.

Your profile:

  • Broad knowledge and hands-on experience with software development, infrastructure, IoT, CI/CD, Kubernetes/EKS, and IaC/Terraform.
  • Strong AWS cloud experience - our main hosting platform and we want to keep it safe.
  • Experience or a strong interest in AI security, whether securing AI systems or using AI to strengthen security operations.
  • Experience in Information Security covering both GRC and hands-on technical implementation.
  • Solid understanding of security frameworks (SOC 2, ISO 27001) and regulations (GDPR, NIS2).
  • Relevant certifications (CISSP, CISM, AWS Security Specialty, or similar).
  • Excellent communication and collaboration skills; comfortable with both technical and non-technical stakeholders.
  • Ability to learn on the job in case you don't check all the boxes (who does?).

About ZeroNorth

At ZeroNorth, we aim to make global trade sustainable by steering the maritime industry toward zero emissions. Using advanced technology and trusted data, our platform delivers real-time insights to optimize operations and align commercial success with environmental impact.

We partner with customers on their journey toward sustainability, solving complex challenges and empowering informed decisions that benefit both the planet and their bottom line.

Our culture thrives on growth, inclusion, and collaboration. We value honesty, trust, and the unique contributions of every team member, driving meaningful change together.

Let's make global trade green.

Similar roles