Match your resume skills with our AI powered skill match!
The role involves managing operational security, including access control reviews, security requests, and incident monitoring. Additionally, the engineer will drive ISO 27001 compliance, coordinate penetration tests, and support secure development practices.
ORdigiNAL is a technology company operating worldwide, with our strongest presence across Europe. We deliver technology through an established partner network alongside our own applications, sold into markets where security isn't a checkbox; it's a condition of sale. Our SecOps function sits at the heart of that, and this role sits at the heart of SecOps.
You'll join our SecOps function, reporting directly to the Global Technology & Services Director. The role is deliberately broad: at its day-to-day level you'll own operational security - handling security requests, access control reviews, and keeping our security posture tidy and evidenced. At its highest level you'll drive the certifications that let us sell our applications across Europe: ISO 27001 and the audits, evidence and assessments that surround it.
You'll have real ownership from day one, direct support from the director you report to, and the chance to shape our security programme as the business and product line grow.
Day to day
Own the security request queue: access requests, permission changes, joiner/mover/leaver reviews, security questions from around the business
Run periodic access control reviews across our systems and keep the evidence audit-ready
Monitor, triage and escalate security events and keep our incident readiness current
Carry out vendor risk assessments for new tools and suppliers
Compliance and certification
Drive ISO 27001 evidence collection and keep our ISMS living, not shelfware, including extending its scope to cover our software development
Support DPIAs and data protection reviews alongside the business
Coordinate CREST-accredited penetration tests (annually and per major release) and track remediation through to closure
Help us attain and maintain the market schemes our customers require — Cyber Essentials Plus, NHS DSPT and DTAC in the UK, NEN 7510 in the Netherlands, and equivalents as we grow
Product security
Work with our engineering function on secure development practices for our applications
Contribute to the security cases our customers ask for during procurement
2+ years in a security, infrastructure or IT role with meaningful security responsibility
Working knowledge of ISO 27001 (helping run an ISMS, gathering evidence, or being on the receiving end of an audit all count)
Comfortable owning a queue: organised, responsive, and able to keep many small things moving without dropping them
Clear writing: much of this role is producing evidence, assessments and documentation that auditors and customers will read
Pragmatism: security that is proportionate and enables the business, evidenced without becoming bureaucracy
Nice to have
Experience in a regulated sector (e.g. DSPT, DTAC, NEN 7510, HDS, BSI C5, SOC 2)
Exposure to DPIAs or GDPR work
Familiarity with cloud security (Microsoft 365 / Azure) and identity management
A security certification (Security+, ISO 27001 internal auditor, or similar) — or the appetite to work towards one
£33,000 salary (or local equivalent) plus employer pension
Remote working from the UK or mainland Europe, with occasional travel to our Netherlands office for team days and audits
Netherlands-based? Even better, you're welcome to work from our office
A genuinely broad role with direct access to senior leadership and a clear growth path as our security programme and product line grow
An annual training budget to support role-relevant development and certifications
A role where security visibly matters to the business and its route to market
Stop the endless job search. Our AI finds and applies to the best jobs for you.
Discover remote opportunities in Software Development
Answer easy questions
200,000+ jobs across 15+ categories
Get your best job matches
Only hand-screened, legit jobs
Find a remote job faster
No ads, scams, or junk
“I was the first applicant for a remote marketing position that got listed on the company website the same day I applied. Had an interview within 48 hours!”