Founding Security Engineer (Part-Time)
Job Title: Founding Security Engineer
Department: Technology
Reports To: CEO / CTO
Location: Remote
Employment Type: Part-time
About the Company
One of our Netherlands-based safety-technology company building an AI-powered personal safety guardian that gets help to people at the moment they can't act for themselves, running on mobile devices and on a dedicated card-thin hardware device that senses danger and can call for help autonomously.
Role Overview
This is a founding role responsible for building our entire security program from the ground up. Because our product's core promise is protecting people at their most vulnerable, security is not a supporting feature, it is the product. The Founding Security Engineer will own the security roadmap end-to-end: prioritizing what matters most at each stage, doing the highest-leverage work personally, and bringing in specialists, tooling, and automation as the company scales. This role has real authority over product and infrastructure architecture, reports directly to the CEO/CTO, and is responsible for protecting our users, our intellectual property (including our patented sensing and escalation architecture), and our ability to grow.
Key Responsibilities
Offensive Security
- Act as our in-house ethical hacker - continuously test and attempt to compromise our systems before anyone else can
- Conduct penetration testing and real-world attack simulation across web and mobile apps, APIs, authentication, cloud, networks, our hardware device, and our CI/CD pipelines
- Run periodic red-team exercises, including phishing, credential theft, privilege escalation, and cloud-compromise scenarios
Vulnerability Management
- Identify, prioritize, and remediate vulnerabilities across the OWASP Top 10 and API Top 10, authentication/authorization flaws, privilege escalation, business-logic attacks, injection, RCE, SSRF, XSS/CSRF, IDOR, insecure deserialization, and race conditions
- Address AI-specific risks including prompt injection, jailbreaks, model abuse, and supply-chain vulnerabilities
AI Security
- Assess and harden our AI system against prompt injection, leakage, model manipulation, data poisoning, and sensitive-information disclosure
- Write and maintain secure-deployment guidelines for shipping AI safely
Cloud & Infrastructure Security
- Secure our cloud estate (AWS/Azure/GCP): IAM, network architecture, VPCs, security groups, secrets management, Kubernetes/containers, storage, logging, monitoring, and disaster recovery
- Harden servers, networks, VPN, firewalls, DNS, identity, and remote access
Application Security & DevSecOps
- Embed security into the SDLC through secure code reviews, threat modeling, architecture reviews, dependency analysis, and SAST/DAST/SCA
- Automate security into CI/CD, including dependency/secret scanning, container and IaC scanning, and compliance checks
Hardware Security
- Review and harden firmware update processes, secure boot, secure-element integration, hardware encryption, BLE/Wi-Fi security, OTA updates, device identity, and manufacturing/supply-chain security
Compliance, Governance & Security Culture
- Drive us toward ISO/IEC 27001 and SOC 2 Type II certification, supporting GDPR and NIS2 compliance where applicable
- Stand up the ISMS, policies, risk register, asset inventory, and incident-response/business-continuity documentation
- Build security monitoring and detection capabilities, lead incident investigations and post-incident reviews, and raise security literacy across the team
Required Qualifications
- 5+ years of experience across penetration testing, application security, cloud security, or offensive security, with genuine depth in several areas rather than surface-level exposure
- Strong experience with at least one major cloud provider (AWS, Azure, or GCP), modern auth/authz standards, and securing SaaS, APIs, and AI-enabled applications
- Experience supporting security audits and compliance frameworks (ISO 27001/SOC 2), or a clear ability and appetite to lead the organization there
- Degree in cybersecurity, computer science, or a related field, or equivalent demonstrated ability
- Relevant certifications (OSCP, OSWE, OSEP, PNPT, CISSP, CCSP, ISO/IEC 27001 Lead Implementer/Auditor, or a cloud security specialty) are valued but not required
Technical Skills
- Threat modeling, IAM, cryptography, and network security
- Linux and scripting (Python, Bash, PowerShell)
- Docker/Kubernetes and CI/CD security
- Reverse-engineering and mobile/hardware security (a strong plus)
- Familiarity with OWASP ASVS, API Security Top 10, MITRE ATT&CK, NIST CSF/SSDF, CIS Controls, ISO/IEC 27001, and SOC 2 Trust Services Criteria
Core Competencies / Soft Skills
- A builder's temperament - comfortable establishing a practice from nothing rather than joining an existing one
- Ruthless prioritization and a focus on highest-leverage work over checklist completion
- Strong ownership mindset with the ability to operate with real autonomy and authority
- Ability to communicate security priorities clearly to non-technical stakeholders and founders
- Practical, non-preachy approach to raising security awareness across a team
Work Environment
This is a fully remote, part-time, founding-team position reporting directly to the CEO/CTO. The role carries broad technical scope spanning software, cloud, AI, and hardware security, along with direct influence over product and infrastructure architecture decisions from the earliest stage.
Compensation & Benefits
200,000 Naira per month (part-time).
Application Process